[FEAT] Integrazione analisi docs/nis2 v1.7.0 — scoring asset, tassonomia incidenti, PIR, NIST CSF, fonti certe
Fase 1 - Asset Relevance Scoring NIS2 (GV.OC-04): metodologia 0-100 a 6 criteri, AssetScoringService + endpoint scoringGrid/score/relevantSystems + UI assets.html + registro stampabile. Fase 2 - Tassonomia incidenti Determina ACN 164179/2025: IS-1..4 + regime essenziale/importante (Allegati 3/4). Fase 3 - Post-Incident Review (5-Whys) + metriche TTD/TTC/TTR + timestamp di fase. Fase 4 - Mapping NIST CSF 2.0 (43 controlli) reference-only. Fonti certe: registry config/nis2_sources.php + grounding AI (vieta riferimenti inventati) + citazioni help.js + ingest PDF normativi nella KB RAG (scripts/ingest-nis2-sources.php). Migrazioni 020/021/022 (additive idempotenti). Fix VectorService IP Qdrant (drift .5->.3). Analisi concorrenza Evix (docs/EVIX_ANALISI_CONCORRENZA.html, gap-driven). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
a7a21faa82
commit
5c545ea3d0
@@ -195,6 +195,83 @@ class AuditController extends BaseController
|
||||
$this->jsonSuccess($mapping);
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /api/audit/nistCsfMapping
|
||||
* Layer di mapping NIST CSF 2.0 (43 controlli) -> NIS2 Art.21 / D.Lgs.138/2024 -> modulo piattaforma.
|
||||
* Reference-only (nessuna persistenza): arricchisce l'assessment Art.21 con i codici controllo
|
||||
* NIST CSF 2.0 usati come standard de-facto. Fonte mapping: NIST CSF 2.0 + Direttiva (UE) 2022/2555.
|
||||
*/
|
||||
public function getNistCsfMapping(): void
|
||||
{
|
||||
$this->requireOrgAccess();
|
||||
|
||||
// [code, function, nis2, module]
|
||||
$rows = [
|
||||
// GOVERN
|
||||
['GV.OC-04', 'Govern', '21.1', 'Asset - Sistemi rilevanti (GV.OC-04)'],
|
||||
['GV.RM-03', 'Govern', '21.2.a', 'Risk Management'],
|
||||
['GV.RR-02', 'Govern', '20', 'Organizzazione - Ruoli e responsabilita'],
|
||||
['GV.RR-04', 'Govern', '20', 'Organizzazione - Risorse cybersecurity'],
|
||||
['GV.PO-01', 'Govern', '21.2.a', 'Policy - Politica di sicurezza'],
|
||||
['GV.PO-02', 'Govern', '21.2.a', 'Policy - Revisione politiche'],
|
||||
['GV.SC-01', 'Govern', '21.2.d', 'Supply Chain - Strategia'],
|
||||
['GV.SC-02', 'Govern', '21.2.d', 'Supply Chain - Ruoli fornitori'],
|
||||
['GV.SC-04', 'Govern', '21.2.d', 'Supply Chain - Valutazione fornitori'],
|
||||
['GV.SC-05', 'Govern', '21.2.d', 'Supply Chain - Requisiti contrattuali'],
|
||||
['GV.SC-07', 'Govern', '21.2.d', 'Supply Chain - Monitoraggio rischio fornitori'],
|
||||
// IDENTIFY
|
||||
['ID.AM-01', 'Identify', '21.2.i', 'Asset - Inventario hardware'],
|
||||
['ID.AM-02', 'Identify', '21.2.i', 'Asset - Inventario software'],
|
||||
['ID.AM-03', 'Identify', '21.2.i', 'Asset - Diagrammi flussi/rete (essenziali)'],
|
||||
['ID.AM-04', 'Identify', '21.2.i', 'Asset - Catalogo servizi'],
|
||||
['ID.RA-01', 'Identify', '21.2.a', 'Risk Management - Vulnerabilita'],
|
||||
['ID.RA-05', 'Identify', '21.2.a', 'Risk Management - Valutazione rischio'],
|
||||
['ID.RA-06', 'Identify', '21.2.a', 'Risk Management - Trattamento rischio'],
|
||||
['ID.RA-08', 'Identify', '21.2.e', 'Risk Management - Gestione vulnerabilita/disclosure'],
|
||||
['ID.IM-01', 'Identify', '21.2.f', 'Audit - Miglioramento da valutazioni'],
|
||||
['ID.IM-04', 'Identify', '21.2.c', 'Incidenti - Piani BC/DR e test'],
|
||||
// PROTECT
|
||||
['PR.AA-01', 'Protect', '21.2.i', 'Asset/Access - Gestione identita'],
|
||||
['PR.AA-03', 'Protect', '21.2.i', 'Access - Autenticazione'],
|
||||
['PR.AA-05', 'Protect', '21.2.i', 'Access - Privilegi e accessi'],
|
||||
['PR.AA-06', 'Protect', '21.2.i', 'Access - Accesso fisico'],
|
||||
['PR.AT-01', 'Protect', '21.2.g', 'Training - Awareness'],
|
||||
['PR.AT-02', 'Protect', '21.2.g', 'Training - Ruoli privilegiati'],
|
||||
['PR.DS-01', 'Protect', '21.2.h', 'Policy - Protezione dati a riposo'],
|
||||
['PR.DS-02', 'Protect', '21.2.h', 'Policy - Protezione dati in transito'],
|
||||
['PR.DS-11', 'Protect', '21.2.c', 'Incidenti - Backup'],
|
||||
['PR.PS-01', 'Protect', '21.2.e', 'Policy - Configurazione sicura'],
|
||||
['PR.PS-02', 'Protect', '21.2.e', 'Asset - Gestione software'],
|
||||
['PR.PS-03', 'Protect', '21.2.e', 'Asset - Gestione hardware'],
|
||||
['PR.PS-04', 'Protect', '21.2.b', 'Audit - Log generation'],
|
||||
['PR.PS-06', 'Protect', '21.2.e', 'Policy - Secure development lifecycle'],
|
||||
['PR.IR-01', 'Protect', '21.2.i', 'Asset - Protezione reti'],
|
||||
['PR.IR-03', 'Protect', '21.2.c', 'Incidenti - Resilienza/ridondanza'],
|
||||
// DETECT
|
||||
['DE.CM-01', 'Detect', '21.2.b', 'Incidenti - Monitoraggio reti'],
|
||||
['DE.CM-09', 'Detect', '21.2.b', 'Incidenti - Monitoraggio asset/sistemi'],
|
||||
// RESPOND / RECOVER
|
||||
['RS.MA-01', 'Respond', '21.2.b / 23', 'Incidenti - Gestione incidenti'],
|
||||
['RS.CO-02', 'Respond', '23', 'Incidenti - Notifica CSIRT'],
|
||||
['RC.RP-01', 'Recover', '21.2.c', 'Incidenti - Piano di ripristino'],
|
||||
['RC.CO-03', 'Recover', '21.2.c', 'Incidenti - Post-Incident Review'],
|
||||
];
|
||||
|
||||
$mapping = array_map(fn($r) => [
|
||||
'csf_code' => $r[0],
|
||||
'function' => $r[1],
|
||||
'nis2_art' => $r[2],
|
||||
'module' => $r[3],
|
||||
], $rows);
|
||||
|
||||
$this->jsonSuccess([
|
||||
'mapping' => $mapping,
|
||||
'count' => count($mapping),
|
||||
'functions' => ['Govern', 'Identify', 'Protect', 'Detect', 'Respond', 'Recover'],
|
||||
'source' => 'NIST Cybersecurity Framework 2.0 + Direttiva (UE) 2022/2555 (NIS2) Art.20-21-23 / D.Lgs. 138/2024',
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /api/audit/executive-report
|
||||
* Genera report esecutivo HTML (stampabile come PDF)
|
||||
@@ -211,6 +288,22 @@ class AuditController extends BaseController
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /api/audit/relevantSystemsRegister
|
||||
* Registro formale "Sistemi Rilevanti NIS2" (GV.OC-04), HTML stampabile.
|
||||
*/
|
||||
public function relevantSystemsRegister(): void
|
||||
{
|
||||
$this->requireOrgRole(['org_admin', 'compliance_manager', 'board_member', 'auditor']);
|
||||
|
||||
$reportService = new ReportService();
|
||||
$html = $reportService->generateRelevantSystemsRegister($this->getCurrentOrgId());
|
||||
|
||||
header('Content-Type: text/html; charset=utf-8');
|
||||
echo $html;
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /api/audit/export/{type}
|
||||
* Esporta dati in CSV
|
||||
|
||||
Reference in New Issue
Block a user