Skip to content

feat(prowler): chunk15 add the NIS2/ISO27001 compliance contract (#422) - #445

Draft
Christophe Melchior (Kakudou) wants to merge 4 commits into
feat/422-prowler-injector-chk14-compliance-cisfrom
feat/422-prowler-injector-chk15-compliance-nis
Draft

feat(prowler): chunk15 add the NIS2/ISO27001 compliance contract (#422)#445
Christophe Melchior (Kakudou) wants to merge 4 commits into
feat/422-prowler-injector-chk14-compliance-cisfrom
feat/422-prowler-injector-chk15-compliance-nis

Conversation

@Kakudou

@Kakudou Christophe Melchior (Kakudou) commented Aug 28, 2026

Copy link
Copy Markdown
Member

Part of #422.

Chunk 15 of the Prowler injector stack: add the NIS2 / ISO 27001 compliance contract — the CHK.015 NIS2 and ISO 27001 assessments: the BDD suite (behaviour, lifecycle / verbose diagnostics recorded through the conftest recording logger, OCSF record fixtures), the new contracts/nis2_iso27001.py defining the seven canonical routes nis2/aws, nis2/azure, nis2/gcp, iso27001/aws, iso27001/azure, iso27001/gcp, iso27001/kubernetes against the Prowler 5.36 NIS2 / ISO 27001:2022 frameworks (nis2_aws, nis2_azure, nis2_gcp, iso27001_2022_aws, iso27001_2022_azure, iso27001_2022_gcp, iso27001_2022_kubernetes), the seven selectors added to the ComplianceSelector type and the client's compliance → provider-type mapping, unsupported and cross-provider compliance selectors rejected before the adapter / engine, their registration in the registry / __init__ (15 → 22 canonical contracts), and the cross-chunk registry-alignment BDD updates (chk001, chk007, chk008, chk009, chk010, chk011, chk012, chk013, chk014) plus the chk006 unit registry expectations. Existing check and service selection channels are untouched, and framework routing is not exposed as form input.

Re-landed from feat/422-prowler-chk015-compliance-nis2-iso27001 (c75f7a9..89bcb8e): 10 source commits folded into 4 (Q1: 227551c; Q2: 96ee856 + 0df461c + 859639f + caa65bf + 89bcb8e; Q3: 0007bf8 + 92e5f69 + 5f93042; Q4: f7d4102). Q2 landed at the source-final post-images of the CHK.015 BDD suite (including the source's own missing __init__.py fix from 859639f) and the chk006 registry unit test, so the four later suite commits fold in as content with zero conflicts; Q3 carries the five implementation files (the new contract at its 5f93042 post-image, unchanged through the tip) and the nine prior-chunk BDDs at their final post-images, with the CHK.014 BDD at its 0007bf8 post-image; Q4 is the re-flow of that CHK.014 BDD (1+/3−). Gate V (whole-branch tree vs source tip 89bcb8e): byte-identical except (a) the 14 pyproject.toml version differences of the other injectors (source base 3.260805.0 vs re-land base 3.260821.0; prowler/ subtree otherwise untouched), (b) the 12 trap-analysis.md files (chk004–chk015) excluded by standing call, and (c) one approved deviation — the pinned pyoaev version assert removed from prowler/tests/unit/chk006_executable_base/test_outputs_registry_runtime.py.

@Filigran-Automation Filigran Automation (Filigran-Automation) added the filigran team Item from the Filigran team. label Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

filigran team Item from the Filigran team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants