CISOs and their groups are anticipated to display compliance with a spread of laws, frameworks and requirements. With an alphabet soup of frameworks — NIST, ISO, PCI DSS, HIPAA, GDPR and lots of different country- or sector-specific mandates — there’s a rising danger of duplicating effort, management gaps and audit fatigue.
CISOs can simplify governance by mapping safety controls to the varied home and worldwide requirements and laws addressing cybersecurity via a unified management structure.
Why management mapping issues
Enterprises which are required to display regulatory compliance should show how they comply. Along with quite a lot of audit exams, a map of the controls getting used and the corresponding requirements is a crucial piece of audit proof.
With no management map, CISOs and their groups can face redundant efforts when connecting controls to particular necessities, an absence of constant software of controls inside the enterprise and extra work gathering proof for an audit.
Safety groups can save effort and time by constructing a structured map of controls and necessities, consolidating all mapping right into a single evaluation. This helps strengthen cyber resilience by establishing a holistic baseline.
Learn how to construct a control-mapping technique
Previous to getting ready a management/commonplace map, outline the general technique. This helps CISOs, auditors and regulators assess and confirm compliance, minimizes duplication and enhances governance. The hot button is to outline scope, set up a baseline management language and create a versatile and reusable mapping mannequin. Including AI to the method helps speed up map preparation and assists with ongoing upkeep.
Receive probably the most related and authoritative sources. Among the many most essential are:
- NIST CSF (Cyber Safety Framework). This framework gives steering throughout a broad vary of cybersecurity points; implementation is voluntary.
- NIST SP 800-53. Designed for presidency use, these cybersecurity controls can be utilized by the non-public sector. Implementation is voluntary however thought of important for demonstrating compliance.
- ISO/IEC 27001. That is the worldwide cybersecurity commonplace; compliance should be formally demonstrated.
- CIS Controls. Developed by the U.S. Heart for Web Safety, there are 18 particular controls to deal with; implementation is voluntary.
- SOC 2 Safety Controls. Developed to adjust to the AICPA’s Belief Providers Standards, these are auditable controls.
- HIPAA. The HIPAA safety controls, that are obligatory in healthcare, may be utilized in lots of industries; compliance should be formally demonstrated.
- PCI DSS. The Fee Card Business Information Safety Commonplace is a compulsory requirement for organizations within the cost business; it has six management goals that delineate 12 particular necessities.
- FedRAMP. Based mostly on NIST SP 800-53, these obligatory controls had been designed for cloud service suppliers that deal with federal knowledge.
- CMMC. The Cybersecurity Maturity Mannequin Certification was developed by the U.S. Protection Division to guard crucial authorities knowledge utilized by contractors.
- GPPR. The EU Basic Information Safety Regulation specifies how knowledge generated and utilized by EU member nations and different nations that work with EU member states is protected against unauthorized use; compliance should be formally demonstrated.
As soon as the related necessities have been recognized, develop an ordinary management language and taxonomy. Subsequent, create a crosswalk or different strategy the place related knowledge may be recognized and used to assist audits, put together regulatory reporting and facilitate inner governance. You should definitely embody info within the map that particulars proof sources, e.g., origin and rationale.
Step-by-step strategy
Comply with these steps to ascertain your management mapping.
- Outline scope. Start by figuring out the requirements, laws, frameworks and inner insurance policies to be mapped.
- Construct a catalog of cybersecurity controls. Whereas there is perhaps dozens of particular person controls, attempt to group them in particular classes, similar to entry management and incident response.
- Choose your mapping strategy. This may embody 1:1 (one management to 1 commonplace), partial mapping (one commonplace to many controls) or thematic mapping (grouping controls into classes, similar to entry management).
- Outline mapping standards. Set guidelines for develop mapping. Embody elements similar to intent, outcomes, safeguards or necessities for proof.
- Full and doc the mapping. Given the time it takes to finish a map, think about using inner consultants devoted to the mission, exterior consultants or AI automation instruments.
- Provoke stakeholder validation. Invite representatives from the authorized, audit, compliance and engineering teams to evaluation the map’s accuracy.
- Launch the map. As soon as permitted, combine the map into governance, danger and compliance (GRC) workflows; danger assessments; reporting; and audits.
- Use change management to keep up maps. Noting that requirements and laws periodically change, use the change-control course of to maintain maps updated.
Overcoming management mapping challenges
When planning and creating a management map, there can be difficulties to beat. To mitigate them, attempt to standardize the language and map construction to attenuate confusion.
Consistency counts for requirements, as properly. Relying on the usual, the content material is perhaps extra basic and broad-based, whereas others could possibly be detailed, so be certain that the language is as constant as doable. Some requirements and laws, similar to HIPAA and GDPR, describe outcomes, whereas others, similar to NIST, CIS and SOC 2, present particular controls. Be able to replace maps with the newest variations as requirements, laws and frameworks change.
Within the broader group, concentrate on the impression on different capabilities. Inside departments, similar to safety, danger administration, compliance and engineering, might need differing views of controls and the way controls are utilized.
Additionally make sure you verify proof necessities. As soon as controls have been mapped, see if there are any variances in proof necessities.
Instruments and applied sciences
Automated instruments can help with management map improvement. To streamline the event and upkeep processes, contemplate instruments with AI capabilities.
Some accessible merchandise embody:
- Archer Evolv, a management and regulatory mapping engine.
- CIS Controls Mapping, an Excel-based management mapping crosswalk to NIST, PCI DSS, ISO, HIPAA and SOC 2.
- Drata, an AI-based management mapping and monitoring device.
- Hyperproof, an AI-based management mapping device.
- LogicGate Danger Cloud, a device to develop maps utilizing workflows and mapping templates.
- NIST OSCAL (Open Safety Controls Evaluation Language), a set of NIST-developed hierarchical, formatted, XML- JSON- and YAML-based codecs used for improvement and evaluation of safety controls.
- OneTrust, a device that helps safety map improvement utilizing GDPR, DORA, ISO, NIST, HIPAA and others.
- Secureframe, an automatic management mapping device for SOC 2, ISO, HIPAA and different requirements.
- ServiceNow GRC, a device that features crosswalk templates and evidence-collection options.
- Tugboat Logic, which is a part of OneTrust, providing crosswalks for requirements similar to SOC 2, ISO and HIPAA.
Editor’s be aware: The creator selected to spotlight these instruments primarily based on impartial analysis, prioritizing anecdotally outstanding and well-established choices with vital consumer bases. This listing is organized alphabetically.
Execs and cons of mapping with automation and AI
Management mapping advantages from automation, and, extra particularly, AI-assisted automation. Duties required for mapping may be streamlined and accomplished extra shortly with AI than via guide approaches and present mapping functions.
Among the many benefits are sooner management and commonplace matching. AI algorithms can analyze management intent throughout requirements and frameworks. Automation additionally permits a staff to make use of constant language throughout totally different requirements. AI can monitor attributes repeatedly and alerts when requirements and laws are up to date.
Different advantages of automated mapping embody streamlined map creation; speedy assortment of related proof from varied sources and event-ticketing methods; streamlined workflows for the control-testing course of; real-time model management for management maps and inner controls; and assortment of related proof for audit preparation and reporting.
If utilizing automation, be aware that whereas AI can collect related regulatory and requirements paperwork, it can not interpret the usual’s intent with out human evaluation. Additionally, AI-generated maps might include errors that might have an effect on compliance. It is as much as individuals to substantiate the work produced is correct and comprehensible to auditors and regulators.
Paul Kirvan, FBCI, CISA, is an impartial guide and technical author with greater than 35 years of expertise in enterprise continuity, catastrophe restoration, resilience, cybersecurity, GRC, telecom and technical writing.






