Control Mapping
What is Control Mapping?
The process of identifying relationships between controls in different frameworks. For example, mapping ISO 27001 Annex A controls to NIST 800-53 controls to identify overlap and gaps.
Related terms
Frameworks that govern control mapping
What the standards actually require on control mapping
Requirements naming control mapping across 3 standards, quoted from the control text.
The assessment covers the full set of applicable CCM control domains, with any not-applicable controls justified, so the assurance reflects the complete CCM control set rather than a subset.
STAR-CCM-01 · CCM control mapping completeness →34 CFR 99.31(a)(6)(iii)(D) safeguards requirement + the PTAC Best Practices Guidance + SPPO Guidance. The 2011 final rule explicitly requires APPROPRIATE METHODS to PROTECT PII when disclosed under the studies + audit + evaluation exceptions.
FERPA-Safeguards-PTAC · Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) →Florida FDBR crosswalk to comprehensive security + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (FDBR controller responsibilities + DPAs + privacy notice) + IDENTIFY (sensitive data inventory + minors data + voice/facial recognition data) + PROTECT (opt-in...
FDBR-Compliance-Crosswalk-NIST-ISO-SOC · FDBR Crosswalk to NIST CSF, ISO 27001, SOC 2 and Federal/Sectoral Frameworks →Questions people ask about control mapping
What is Control Mapping?
Why is Control Mapping important for compliance?
What concepts are related to Control Mapping?
Which compliance frameworks address Control Mapping?
Where can I learn more about Control Mapping?
See how Control Mapping applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.