[FEAT] Modello Organizzativo SGSI (ISO 27001/27017/27018) + SoA pre-popolato da NIS2

Nuovo modulo guidato in 6 step (cl. 4-10 + Statement of Applicability):
- migration 037 (isms_models/roles/soa/documents) + 038 (dataset 111 controlli:
  93 Annex A:2022 + 7 CLD/27017 + 11 PII/27018) + runner scripts/migrate-isms.php
- IsmsModelController (16 endpoint) registrato in index.php
- SoA pre-popolato dalle risposte Gap Analysis NIS2 (mapping iso27001_control)
- estensioni cloud condizionali 27017/27018 via flag uses_public_cloud/
  is_cloud_provider/processes_pii_in_cloud
- AIService::generateIsmsDocument + fonti ISO in nis2_sources.php
- frontend isms.html/isms.js + api client + sidebar + help + i18n IT/EN
- ingest KB ISO (scope SYSTEM, solo titoli/sintesi: no testo coperto da copyright)
- version.json 1.14.0; doc studio + deploy handoff

Strumento di supporto/pre-audit (non certificazione). Migration DA APPLICARE su host.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
DevEnv nis2-agile
2026-06-11 11:32:42 +02:00
parent 66d50cd2cf
commit 3f74165531
17 changed files with 2166 additions and 1 deletions
+21
View File
@@ -88,6 +88,7 @@ $controllerMap = [
'organizations' => 'OrganizationController',
'assessments' => 'AssessmentController',
'acn-gap' => 'AcnAssessmentController', // Gap Analysis ACN (Det. 164179/2025, misure/requisiti)
'isms' => 'IsmsModelController', // Modello Organizzativo SGSI (ISO 27001/27017/27018 + SoA)
'dashboard' => 'DashboardController',
'risks' => 'RiskController',
'incidents' => 'IncidentController',
@@ -217,6 +218,26 @@ $actionMap = [
'POST:{id}/aiAnalyze' => 'aiAnalyze',
],
// ── IsmsModelController — Modello Organizzativo SGSI (ISO 27001/27017/27018) ──
'isms' => [
'GET:model' => 'getModel',
'POST:model' => 'saveModel',
'PUT:model' => 'saveModel',
'GET:annexControls' => 'annexControls',
'GET:soa' => 'getSoa',
'POST:soa/derive' => 'deriveSoa',
'PUT:soa' => 'updateSoaControl',
'GET:roles' => 'listRoles',
'POST:roles' => 'saveRole',
'DELETE:roles/{subId}' => 'deleteRole',
'GET:documents' => 'listDocuments',
'POST:documents' => 'createDocument',
'POST:documents/aiGenerate' => 'aiGenerateDocument',
'PUT:documents/{subId}' => 'updateDocument',
'GET:readiness' => 'readiness',
'GET:export' => 'export',
],
// ── DashboardController ─────────────────────────
'dashboard' => [
'GET:overview' => 'overview',