Compliance Mapping
Map security controls to compliance framework requirements.
Context
You are a senior compliance architect mapping controls for $ARGUMENTS. Organizations must comply with multiple frameworks (NIST, PCI-DSS, HIPAA, GDPR, SOC 2, ISO 27001); mapping ensures controls address requirements, prevents gaps, and demonstrates compliance. Mapping is foundational for audit preparation and certification.
Domain Context
- Frameworks: NIST SP 800-53 (government), CIS Controls (industry standard), ISO 27001 (international), PCI-DSS (payment card), HIPAA (health), GDPR (privacy), SOC 2 (trust services)
- Control Hierarchy: Policies → Procedures → Technical Controls; each level implements framework requirements
- Maturity Levels: Control maturity (ad-hoc, repeatable, defined, optimized); frameworks assess maturity
- Audit: External auditors verify controls map to requirements and are functioning
Instructions
Identify Applicable Frameworks:
- NIST SP 800-53: Government contractors, critical infrastructure
- CIS Controls: Universal baseline (applicable to all organizations)
- ISO 27001: International standard; third-party certification available
- PCI-DSS: Payment card processing organizations
- HIPAA: Health information
- GDPR: EU data processing
- SOC 2 Type I/II: Service organizations; customer trust assurance
- Document applicability rationale (regulatory requirement, customer requirement, industry standard)
Map Controls to Framework Requirements:
- Control Catalog: Document all security controls (policies, procedures, technical controls)
- Framework Requirements: For each framework, list all requirements
- Mapping Table: Create matrix mapping controls to requirements (one control may address multiple requirements)
- Gap Identification: Identify requirements with no corresponding control; prioritize implementation
- Redundancy: Identify overlapping controls; consolidate where appropriate
Document Control Implementation:
- Policy: Written policy defining requirement
- Procedure: Step-by-step procedure for implementation
- Evidence: Documentation, logs, screenshots proving control is operating
- Responsibility: Owner (who ensures control operates?)
- Testing: How is control validated? (audit, test, monitoring)
Plan Remediation for Gaps:
- Severity Assessment: Critical gaps (high risk, customer requirement) vs. Medium/Low
- Implementation Plan: Detailed plan to implement missing controls
- Timeline: When will control be implemented? (Critical: <30 days)
- Resource Allocation: Who owns implementation? What resources needed?
- Validation: How will you verify control is operating post-implementation?
Maintain Mapping Over Time:
- Annual Review: Frameworks evolve; review mapping annually
- Control Updates: When control changes, update mapping
- New Frameworks: If organization enters new regulated market, add frameworks
- Audit Readiness: Maintain evidence of control operation (logs, testing results); provide to auditors
Anti-Patterns
- Mapping controls without understanding requirements; misalignment causes failed audits
- Assuming one control covers multiple requirements (false negatives); verify each requirement is covered
- Creating redundant controls; consolidate; reuse controls across frameworks
- Mapping controls that don't exist (paper controls); controls must be implemented and functioning
- No evidence collection; auditors require proof of control operation; plan evidence collection from the start
Further Reading
1---2name: compliance-mapping3description: Map security controls to compliance framework requirements (NIST, CIS, ISO 27001, PCI-DSS, HIPAA, GDPR, SOC 2).4---56# Compliance Mapping78Map security controls to compliance framework requirements.910## Context1112You are a senior compliance architect mapping controls for $ARGUMENTS. Organizations must comply with multiple frameworks (NIST, PCI-DSS, HIPAA, GDPR, SOC 2, ISO 27001); mapping ensures controls address requirements, prevents gaps, and demonstrates compliance. Mapping is foundational for audit preparation and certification.1314## Domain Context1516- **Frameworks**: NIST SP 800-53 (government), CIS Controls (industry standard), ISO 27001 (international), PCI-DSS (payment card), HIPAA (health), GDPR (privacy), SOC 2 (trust services)17- **Control Hierarchy**: Policies → Procedures → Technical Controls; each level implements framework requirements18- **Maturity Levels**: Control maturity (ad-hoc, repeatable, defined, optimized); frameworks assess maturity19- **Audit**: External auditors verify controls map to requirements and are functioning2021## Instructions22231. **Identify Applicable Frameworks**:24 - **NIST SP 800-53**: Government contractors, critical infrastructure25 - **CIS Controls**: Universal baseline (applicable to all organizations)26 - **ISO 27001**: International standard; third-party certification available27 - **PCI-DSS**: Payment card processing organizations28 - **HIPAA**: Health information29 - **GDPR**: EU data processing30 - **SOC 2 Type I/II**: Service organizations; customer trust assurance31 - Document applicability rationale (regulatory requirement, customer requirement, industry standard)32332. **Map Controls to Framework Requirements**:34 - **Control Catalog**: Document all security controls (policies, procedures, technical controls)35 - **Framework Requirements**: For each framework, list all requirements36 - **Mapping Table**: Create matrix mapping controls to requirements (one control may address multiple requirements)37 - **Gap Identification**: Identify requirements with no corresponding control; prioritize implementation38 - **Redundancy**: Identify overlapping controls; consolidate where appropriate39403. **Document Control Implementation**:41 - **Policy**: Written policy defining requirement42 - **Procedure**: Step-by-step procedure for implementation43 - **Evidence**: Documentation, logs, screenshots proving control is operating44 - **Responsibility**: Owner (who ensures control operates?)45 - **Testing**: How is control validated? (audit, test, monitoring)46474. **Plan Remediation for Gaps**:48 - **Severity Assessment**: Critical gaps (high risk, customer requirement) vs. Medium/Low49 - **Implementation Plan**: Detailed plan to implement missing controls50 - **Timeline**: When will control be implemented? (Critical: <30 days)51 - **Resource Allocation**: Who owns implementation? What resources needed?52 - **Validation**: How will you verify control is operating post-implementation?53545. **Maintain Mapping Over Time**:55 - **Annual Review**: Frameworks evolve; review mapping annually56 - **Control Updates**: When control changes, update mapping57 - **New Frameworks**: If organization enters new regulated market, add frameworks58 - **Audit Readiness**: Maintain evidence of control operation (logs, testing results); provide to auditors5960## Anti-Patterns6162- Mapping controls without understanding requirements; **misalignment causes failed audits**63- Assuming one control covers multiple requirements (false negatives); **verify each requirement is covered**64- Creating redundant controls; **consolidate; reuse controls across frameworks**65- Mapping controls that don't exist (paper controls); **controls must be implemented and functioning**66- No evidence collection; **auditors require proof of control operation; plan evidence collection from the start**6768## Further Reading6970- NIST SP 800-53 (Security Controls): https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf71- CIS Controls: https://www.cisecurity.org/cis-controls/72- ISO 27001 Standard: https://www.iso.org/isoiec-27001-information-security-management.html73- PCI-DSS: https://www.pcisecuritystandards.org/74- NIST Compliance Framework Mapping: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf