CISOs and their groups are anticipated to display compliance with a spread of laws, frameworks and requirements. With an alphabet soup of frameworks — NIST, ISO, PCI DSS, HIPAA, GDPR and lots of different country- or sector-specific mandates — there’s a rising threat of duplicating effort, management gaps and audit fatigue.
CISOs can simplify governance by mapping safety controls to the varied home and worldwide requirements and laws addressing cybersecurity via a unified management structure.
Why management mapping issues
Enterprises which might be required to display regulatory compliance should show how they comply. Along with a wide range of audit exams, a map of the controls getting used and the corresponding requirements is a vital piece of audit proof.
With out a management map, CISOs and their groups can face redundant efforts when connecting controls to particular necessities, an absence of constant software of controls throughout the enterprise and extra work gathering proof for an audit.
Safety groups can save effort and time by constructing a structured map of controls and necessities, consolidating all mapping right into a single evaluation. This helps strengthen cyber resilience by establishing a holistic baseline.
Easy methods to construct a control-mapping technique
Previous to making ready a management/customary map, outline the general technique. This helps CISOs, auditors and regulators assess and confirm compliance, minimizes duplication and enhances governance. The hot button is to outline scope, set up a baseline management language and create a versatile and reusable mapping mannequin. Including AI to the method helps speed up map preparation and assists with ongoing upkeep.
Get hold of probably the most related and authoritative sources. Among the many most vital are:
- NIST CSF (Cyber Safety Framework). This framework gives steerage throughout a broad vary of cybersecurity points; implementation is voluntary.
- NIST SP 800-53. Designed for presidency use, these cybersecurity controls can be utilized by the personal sector. Implementation is voluntary however thought-about important for demonstrating compliance.
- ISO/IEC 27001. That is the worldwide cybersecurity customary; compliance should be formally demonstrated.
- CIS Controls. Developed by the U.S. Middle for Web Safety, there are 18 particular controls to handle; implementation is voluntary.
- SOC 2 Safety Controls. Developed to adjust to the AICPA’s Belief Companies Standards, these are auditable controls.
- HIPAA. The HIPAA safety controls, that are obligatory in healthcare, will be utilized in lots of industries; compliance should be formally demonstrated.
- PCI DSS. The Cost Card Trade Information Safety Commonplace is a compulsory requirement for organizations within the fee business; it has six management goals that delineate 12 particular necessities.
- FedRAMP. Based mostly on NIST SP 800-53, these obligatory controls have been designed for cloud service suppliers that deal with federal information.
- CMMC. The Cybersecurity Maturity Mannequin Certification was developed by the U.S. Protection Division to guard important authorities information utilized by contractors.
- GPPR. The EU Normal Information Safety Regulation specifies how information generated and utilized by EU member nations and different nations that work with EU member states is protected against unauthorized use; compliance should be formally demonstrated.
As soon as the related necessities have been recognized, develop an ordinary management language and taxonomy. Subsequent, create a crosswalk or different strategy the place related information will be recognized and used to assist audits, put together regulatory reporting and facilitate inner governance. You’ll want to embody info within the map that particulars proof sources, e.g., origin and rationale.
Step-by-step strategy
Comply with these steps to determine your management mapping.
- Outline scope. Start by figuring out the requirements, laws, frameworks and inner insurance policies to be mapped.
- Construct a catalog of cybersecurity controls. Whereas there may be dozens of particular person controls, attempt to group them in particular classes, similar to entry management and incident response.
- Choose your mapping strategy. This will embody 1:1 (one management to at least one customary), partial mapping (one customary to many controls) or thematic mapping (grouping controls into classes, similar to entry management).
- Outline mapping standards. Set guidelines for the way to develop mapping. Embrace components similar to intent, outcomes, safeguards or necessities for proof.
- Full and doc the mapping. Given the time it takes to finish a map, think about using inner consultants devoted to the challenge, exterior consultants or AI automation instruments.
- Provoke stakeholder validation. Invite representatives from the authorized, audit, compliance and engineering teams to overview the map’s accuracy.
- Launch the map. As soon as accepted, combine the map into governance, threat and compliance (GRC) workflows; threat assessments; reporting; and audits.
- Use change management to keep up maps. Noting that requirements and laws periodically change, use the change-control course of to maintain maps updated.
Overcoming management mapping challenges
When planning and creating a management map, there can be difficulties to beat. To mitigate them, attempt to standardize the language and map construction to reduce confusion.
Consistency counts for requirements, as effectively. Relying on the usual, the content material may be extra normal and broad-based, whereas others may very well be detailed, so be certain that the language is as constant as doable. Some requirements and laws, similar to HIPAA and GDPR, describe outcomes, whereas others, similar to NIST, CIS and SOC 2, present particular controls. Be able to replace maps with the most recent variations as requirements, laws and frameworks change.
Within the broader group, concentrate on the impression on different capabilities. Inner departments, similar to safety, threat administration, compliance and engineering, might need differing views of controls and the way controls are utilized.
Additionally you should definitely examine proof necessities. As soon as controls have been mapped, see if there are any variances in proof necessities.
Instruments and applied sciences
Automated instruments can help with management map improvement. To streamline the event and upkeep processes, think about instruments with AI capabilities.
Some obtainable merchandise embody:
- Archer Evolv, a management and regulatory mapping engine.
- CIS Controls Mapping, an Excel-based management mapping crosswalk to NIST, PCI DSS, ISO, HIPAA and SOC 2.
- Drata, an AI-based management mapping and monitoring instrument.
- Hyperproof, an AI-based management mapping instrument.
- LogicGate Danger Cloud, a instrument to develop maps utilizing workflows and mapping templates.
- NIST OSCAL (Open Safety Controls Evaluation Language), a set of NIST-developed hierarchical, formatted, XML- JSON- and YAML-based codecs used for improvement and evaluation of safety controls.
- OneTrust, a instrument that helps safety map improvement utilizing GDPR, DORA, ISO, NIST, HIPAA and others.
- Secureframe, an automatic management mapping instrument for SOC 2, ISO, HIPAA and different requirements.
- ServiceNow GRC, a instrument that features crosswalk templates and evidence-collection options.
- Tugboat Logic, which is a part of OneTrust, providing crosswalks for requirements similar to SOC 2, ISO and HIPAA.
Editor’s be aware: The creator selected to spotlight these instruments based mostly on unbiased analysis, prioritizing anecdotally distinguished and well-established choices with important person bases. This checklist is organized alphabetically.
Execs and cons of mapping with automation and AI
Management mapping advantages from automation, and, extra particularly, AI-assisted automation. Duties required for mapping will be streamlined and accomplished extra shortly with AI than via guide approaches and present mapping functions.
Among the many benefits are sooner management and customary matching. AI algorithms can analyze management intent throughout requirements and frameworks. Automation additionally allows a group to make use of constant language throughout totally different requirements. AI can monitor attributes constantly and alerts when requirements and laws are up to date.
Different advantages of automated mapping embody streamlined map creation; speedy assortment of related proof from varied sources and event-ticketing techniques; streamlined workflows for the control-testing course of; real-time model management for management maps and inner controls; and assortment of related proof for audit preparation and reporting.
If utilizing automation, be aware that whereas AI can collect related regulatory and requirements paperwork, it can not interpret the usual’s intent with out human overview. Additionally, AI-generated maps may comprise errors that will have an effect on compliance. It is as much as folks to substantiate the work produced is correct and comprehensible to auditors and regulators.
Paul Kirvan, FBCI, CISA, is an unbiased advisor and technical author with greater than 35 years of expertise in enterprise continuity, catastrophe restoration, resilience, cybersecurity, GRC, telecom and technical writing.









