[FEAT] Modello Organizzativo SGSI (ISO 27001/27017/27018) + SoA pre-popolato da NIS2

Nuovo modulo guidato in 6 step (cl. 4-10 + Statement of Applicability):
- migration 037 (isms_models/roles/soa/documents) + 038 (dataset 111 controlli:
  93 Annex A:2022 + 7 CLD/27017 + 11 PII/27018) + runner scripts/migrate-isms.php
- IsmsModelController (16 endpoint) registrato in index.php
- SoA pre-popolato dalle risposte Gap Analysis NIS2 (mapping iso27001_control)
- estensioni cloud condizionali 27017/27018 via flag uses_public_cloud/
  is_cloud_provider/processes_pii_in_cloud
- AIService::generateIsmsDocument + fonti ISO in nis2_sources.php
- frontend isms.html/isms.js + api client + sidebar + help + i18n IT/EN
- ingest KB ISO (scope SYSTEM, solo titoli/sintesi: no testo coperto da copyright)
- version.json 1.14.0; doc studio + deploy handoff

Strumento di supporto/pre-audit (non certificazione). Migration DA APPLICARE su host.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
DevEnv nis2-agile
2026-06-11 11:32:42 +02:00
parent 66d50cd2cf
commit 3f74165531
17 changed files with 2166 additions and 1 deletions
+70
View File
@@ -0,0 +1,70 @@
<?php
/**
* NIS2 Agile - Runner migrazioni SGSI (ISO 27001) — 037 + 038
* ----------------------------------------------------------------------------
* Applica le migrazioni del Modello Organizzativo SGSI usando la STESSA
* connessione PDO dell'app (config/database.php), cosi da colpire il DB
* realmente servito (host MySQL via socket), NON il DB secondario del container.
*
* USO (sull'host, con la connessione dell'app):
* docker exec nis2-app php /var/www/nis2-agile/scripts/migrate-isms.php
*
* Idempotente: le migrazioni usano CREATE TABLE IF NOT EXISTS + INSERT IGNORE.
* Sola lettura su tabelle esistenti: NON modifica nessuna tabella preesistente.
*/
require_once __DIR__ . '/../application/config/config.php';
require_once __DIR__ . '/../application/config/database.php';
$files = [
__DIR__ . '/../docs/sql/037_isms_model.sql',
__DIR__ . '/../docs/sql/038_iso27001_annex_controls.sql',
];
$pdo = Database::getInstance();
$totalStmts = 0;
foreach ($files as $file) {
if (!is_readable($file)) {
fwrite(STDERR, "[migrate-isms] File non leggibile: $file\n");
exit(1);
}
$sql = (string) file_get_contents($file);
// Rimuove le righe di commento "--" (le migrazioni non usano stringhe con '--').
$lines = preg_split('/\r?\n/', $sql);
$clean = [];
foreach ($lines as $l) {
if (preg_match('/^\s*--/', $l)) {
continue;
}
$clean[] = $l;
}
$sql = implode("\n", $clean);
// Split semplice su ';' (nessun DELIMITER / stored procedure in questi file).
$statements = array_filter(array_map('trim', explode(';', $sql)), fn($s) => $s !== '');
echo "== " . basename($file) . " (" . count($statements) . " statement) ==\n";
foreach ($statements as $stmt) {
try {
$pdo->exec($stmt);
$totalStmts++;
} catch (PDOException $e) {
$head = substr(preg_replace('/\s+/', ' ', $stmt), 0, 80);
fwrite(STDERR, "[ERRORE] su \"$head...\": " . $e->getMessage() . "\n");
exit(1);
}
}
}
// Verifica rapida del seed.
$count = (int) ($pdo->query('SELECT COUNT(*) AS n FROM iso27001_annex_controls')->fetch()['n'] ?? 0);
$byStd = $pdo->query('SELECT standard, COUNT(*) AS n FROM iso27001_annex_controls GROUP BY standard')->fetchAll();
echo "\n[OK] Eseguiti $totalStmts statement.\n";
echo "[OK] iso27001_annex_controls: $count controlli totali.\n";
foreach ($byStd as $r) {
echo " - {$r['standard']}: {$r['n']}\n";
}
echo "[OK] Tabelle SGSI pronte (isms_models, isms_roles, isms_soa, isms_documents).\n";