workflow

Framework Adoption & Cross-Mapping

Adopt or refresh a security/compliance framework (for example NIST CSF 2.0, ISO/IEC 27001:2022, or SOC 2) by scoping the target framework, rating the current profile, defining the target profile, crosswalking requirements to existing controls and adjacent frameworks, prioritizing gaps, and maintaining a live mapping table. The workflow instance runs on an Audit item created at the start of each adoption cycle (audit_type: readiness, or compliance) — its scope/period fields carry the assessment boundary and cycle window, and every step document versions against it. No upstream workflow feeds this one; it consumes the organization's own existing inventory: the risk register (Risk items), the control library / RCM (Control items and their Risk links), the in-scope Process inventory, and any prior Audit items for this or adjacent frameworks. Named deliverables: the framework mapping table (the crosswalk), the risk-ranked prioritized gap list, the coverage/gap dashboard, and the versioned adoption package. In scope: profile construction, crosswalk mapping, gap prioritization, and the closure disposition. Out of scope: authoring the policies and designing the new controls the gaps demand — those are handed off downstream to TWO workflows, Policy Lifecycle Management (policy-driven gaps) and Control Design (control-build gaps).

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
compliance-legal
lineOfDefense
monitor

Details

teams
  • compliance-legal
  • risk-management
domains
  • grc
standards
  • nist-csf-2
  • iso-27001
  • soc2
sourceTemplateId
workflow-library:grc-framework-adoption-cross-mapping
releaseId
sha256:1a62dedf9c3fd637b88064ca3f0909b6746b8c23914c060731d9c9c4acef0250
canonicalUrl
https://workflow-library.com/all/?w=grc-framework-adoption-cross-mapping
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-GOV-16
    • UC-RISK-14
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:1a62dedf9c3fd637b88064ca3f0909b6746b8c23914c060731d9c9c4acef0250

            Connections