Module 14 · Intermediate · ⏱ 55 min · 🏆 +300 XP

Control Frameworks & Mapping

One organization, three regulators, five frameworks. The secret to not duplicating effort is mastering control mapping — showing how one well-designed control satisfies requirements across multiple frameworks simultaneously.

NIST CSF ISO 27001 COBIT Control Mapping Gap Analysis Crosswalks

Learning Objectives

  • Describe the structure and five functions of the NIST Cybersecurity Framework (CSF) 2.0.
  • Map NIST CSF categories to ISO 27001 Annex A controls.
  • Explain COBIT 2019's governance and management objectives relevant to security.
  • Perform a control gap analysis against a chosen framework.
  • Build a control crosswalk showing one control satisfying multiple framework requirements.
  • Explain why organizations use frameworks rather than building controls from scratch.

Lecture

1 · Why Use Frameworks?

Frameworks accelerate control program design by providing a proven, peer-reviewed baseline. Building a control program from scratch invites omissions. Frameworks represent decades of collective practitioner experience, regulatory input, and incident lessons. They also provide a common language — your auditor, your customer, and your board all understand what 'ISO 27001 certified' means.

2 · The Major Frameworks Compared

FrameworkPurposeMandatory?Best For
NIST CSF 2.0Risk-based cybersecurity governanceNo (US federal agencies yes)All organizations; strategic baseline
ISO 27001ISMS certification standardNo (certification optional)Organizations seeking external certification
COBIT 2019IT governance and managementNoLarge enterprises; IT audit focus
NIST 800-53Security and privacy controls catalogYes (US federal)Federal agencies and contractors
PCI-DSSPayment card securityYes (card processors)Any org processing payment cards
SOC 2Trust Services assuranceNo (customer-driven)SaaS/cloud service providers

3 · The Efficiency of Control Mapping

A single encryption control (AES-256 for data at rest) satisfies: NIST CSF PR.DS-1, ISO 27001 A.8.24, PCI-DSS Requirement 3.5, HIPAA Technical Safeguard §164.312(a)(2)(iv), and SOC 2 CC6.1. Control mapping captures this overlap — preventing duplicate testing, documentation, and cost.
Golden rule of control mapping: Design controls to the most stringent requirement. A control meeting ISO 27001 standards will typically satisfy most other frameworks' equivalent requirement.

Theory Deep Dive

📐 NIST CSF 2.0 — Structure and Functions

NIST CSF 2.0 (released 2024) reorganized the framework into 6 core functions, adding GOVERN to the original 5:

GV
GOVERN (New in 2.0)

Establishes and monitors the organization's cybersecurity risk management strategy, expectations, and policy. Covers governance, risk management strategy, roles and responsibilities, policies, and supply chain risk. Reflects the recognition that governance is the foundation of all other functions.

ID
IDENTIFY

Develop an understanding of the organization's risk environment. Asset management, business environment, governance, risk assessment, risk management strategy, supply chain. You cannot protect what you do not know you have.

PR
PROTECT

Develop and implement appropriate safeguards to limit impact. Identity management, access control, awareness training, data security, process/procedure protection, maintenance, protective technology.

DE
DETECT

Develop and implement activities to identify cybersecurity events. Anomalies and events, security continuous monitoring, detection processes. Identifies when a security event occurs.

RS
RESPOND

Take action regarding a detected cybersecurity incident. Response planning, communications, analysis, mitigation, improvements. Limits impact of security events.

RC
RECOVER

Maintain plans for resilience and restore impaired capabilities. Recovery planning, improvements, communications. Restores normal operations after an incident.

🌍 ISO 27001:2022 — ISMS Standard Structure

ISO 27001:2022 is the only internationally recognized certification standard for information security management. Its structure:

Clauses 4–10 (Mandatory)

The ISMS framework requirements: Context, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement. All mandatory for certification — no exclusions permitted.

Annex A (Controls Reference)

93 controls across 4 themes (People, Organisational, Physical, Technological). Organizations select applicable controls based on risk assessment. Non-applicable controls must be justified in the Statement of Applicability (SoA).

Statement of Applicability (SoA)

The SoA is the critical document that maps each Annex A control to the organization, stating: applicable or not, justification, implementation status, and evidence reference. The SoA is the core deliverable for ISO 27001 certification.

Risk Assessment Linkage

ISO 27001 requires control selection to be driven by the risk assessment. Controls chosen arbitrarily (not risk-justified) will not satisfy an ISO 27001 auditor. Every selected control must trace back to a risk in the register.

🗺️ Control Crosswalk — One Control, Many Frameworks

A control crosswalk maps each control to every framework requirement it satisfies. Example crosswalk for Multi-Factor Authentication:

ControlNIST CSF 2.0ISO 27001NIST 800-53PCI-DSSSOC 2
MFA for privileged accessPR.AA-01, PR.AA-03A.8.5, A.8.2IA-2(1), IA-2(2)Req 8.4CC6.1, CC6.3
Access review (quarterly)PR.AA-05A.5.18, A.8.2AC-2Req 7.2, 8.2CC6.2, CC6.3
Encryption at rest (AES-256)PR.DS-01A.8.24SC-28Req 3.5CC6.1
Security awareness training (annual)PR.AT-01A.6.3AT-2Req 12.6CC1.4, CC2.2

A mature organization implements controls once, maps them to all applicable frameworks, and tests them once — satisfying multiple compliance requirements with a single evidence collection exercise.

🔍 Framework Gap Analysis Methodology

A gap analysis compares your current control implementation against a framework's requirements, identifying deficiencies and prioritizing remediation:

1
Select Framework and Scope

Choose the target framework and scope (e.g., NIST CSF for enterprise security program, or ISO 27001 Annex A for ISMS certification). Scoping determines which controls apply.

2
Inventory Existing Controls

Document all currently implemented controls with implementation status (fully implemented, partially implemented, not implemented) and evidence availability.

3
Map Controls to Framework Requirements

For each framework requirement, identify which existing control(s) address it. Gaps are requirements with no existing control or only partial coverage.

4
Score and Prioritize Gaps

Score gaps by risk exposure. High-risk gaps (directly related to top risk register items) are highest priority. Low-risk gaps in non-critical areas can be deferred.

5
Build Remediation Roadmap

Assign owners, budgets, and timelines to each gap. Prioritize by risk score. Report progress to governance quarterly. Use gap closure metrics as a program maturity indicator.

🧪 Lab — Framework Crosswalk Builder

You are a GRC analyst at a company subject to NIST CSF 2.0, ISO 27001, and GDPR. Complete each crosswalk task to build the core technique that cuts integrated compliance effort by 40–60%.

Real-World Scenario

Mission Quiz

Mission Complete

← Module 13 Next: Module 15 →