workflow
Framework Adoption & Cross-Mapping
Adopt or refresh a security/compliance framework (for example NIST CSF 2.0, ISO/IEC 27001:2022, or SOC 2) by scoping the target framework, rating the current profile, defining the target profile, crosswalking requirements to existing controls and adjacent frameworks, prioritizing gaps, and maintaining a live mapping table. The workflow instance runs on an Audit item created at the start of each adoption cycle (audit_type: readiness, or compliance) — its scope/period fields carry the assessment boundary and cycle window, and every step document versions against it. No upstream workflow feeds this one; it consumes the organization's own existing inventory: the risk register (Risk items), the control library / RCM (Control items and their Risk links), the in-scope Process inventory, and any prior Audit items for this or adjacent frameworks. Named deliverables: the framework mapping table (the crosswalk), the risk-ranked prioritized gap list, the coverage/gap dashboard, and the versioned adoption package. In scope: profile construction, crosswalk mapping, gap prioritization, and the closure disposition. Out of scope: authoring the policies and designing the new controls the gaps demand — those are handed off downstream to TWO workflows, Policy Lifecycle Management (policy-driven gaps) and Control Design (control-build gaps).
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- compliance-legal
- lineOfDefense
- monitor
Details
- teams
- compliance-legal
- risk-management
- domains
- grc
- standards
- nist-csf-2
- iso-27001
- soc2
- sourceTemplateId
- workflow-library:grc-framework-adoption-cross-mapping
- releaseId
- sha256:1a62dedf9c3fd637b88064ca3f0909b6746b8c23914c060731d9c9c4acef0250
- canonicalUrl
- https://workflow-library.com/all/?w=grc-framework-adoption-cross-mapping
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-GOV-16
- UC-RISK-14
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:1a62dedf9c3fd637b88064ca3f0909b6746b8c23914c060731d9c9c4acef0250