Edge Register

What each regime attaches to a site outside the data centre

Eight regimes, ticked on the register, plus the 27002 guidance beside every ISO 27001 row and the 800-207 design rules on the remote-access rows. Each page says which sites the regime reaches, how the rows attach by exposure, link, data and plant, and quotes the clauses.

ISO/IEC 27001:2022, with the 27002:2022 guidance beside it 16 clausesNIST SP 800-53 Rev 5 17 clausesNIST SP 800-171 Rev 3 7 clausesCIS Controls v8 6 clausesISO 22301:2019 3 clausesthe GDPR, Chapter V transfers and Article 32 4 clausesDORA, the Digital Operational Resilience Act 2 clausesNIST SP 800-82 Rev 3, the OT overlay 6 clauses

Named references the register links and never quotes: IEC 62443, industrial automation and control systems security (named on the plant classes; its text is not quoted); ISO/IEC 27002:2022, the guidance beside every ISO/IEC 27001 control quoted here; NIST SP 800-207, the remote-access design rules behind the plant remote-access finding.