modern auditing

Glossary

Control crosswalk

Also known as: control mapping, framework mapping

A mapping between the requirements of different frameworks, showing where one control satisfies obligations under several at once.

A crosswalk answers “if we do this, what does it cover?”. It is the working document behind any multi-framework compliance programme, and its quality determines whether “test once, satisfy many” is real or aspirational.

Crosswalks fail in a specific way: mappings are asserted at the level of topic rather than requirement. ISO 27001 A.9 and a NIST 800-53 AC family control are both “about access”, but the specific obligations differ in scope, evidence and frequency. A mapping that treats them as equivalent will produce a test that satisfies neither properly, and nobody discovers this until an assessor asks.

The useful test of a crosswalk is directional. For every mapped pair, ask: does satisfying control A fully satisfy requirement B, partially satisfy it, or merely relate to it? A crosswalk that records only “related” is a topic index. One that records the strength and direction of coverage is a control programme.

The compliance map publishes a worked crosswalk across 22 frameworks — useful as a starting point, and more useful as a demonstration of the level of specificity the exercise requires.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.