{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:1a62dedf9c3fd637b88064ca3f0909b6746b8c23914c060731d9c9c4acef0250","slug":"grc-framework-adoption-cross-mapping","url":"/assets/agent_workflow-grc-framework-adoption-cross-mapping-1d384ecc.0b1d28d777073a49.json"},"kind":"record","record":{"attributes":{"department":"compliance-legal","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-framework-adoption-cross-mapping","description":"Adopt or refresh a security/compliance framework (for example NIST CSF 2.0, ISO/IEC 27001:2022, or SOC 2) by scoping the target framework, rating the current profile, defining the target profile, crosswalking requirements to existing controls and adjacent frameworks, prioritizing gaps, and maintaining a live mapping table. The workflow instance runs on an Audit item created at the start of each adoption cycle (audit_type: readiness, or compliance) — its scope/period fields carry the assessment boundary and cycle window, and every step document versions against it. No upstream workflow feeds this one; it consumes the organization's own existing inventory: the risk register (Risk items), the control library / RCM (Control items and their Risk links), the in-scope Process inventory, and any prior Audit items for this or adjacent frameworks. Named deliverables: the framework mapping table (the crosswalk), the risk-ranked prioritized gap list, the coverage/gap dashboard, and the versioned adoption package. In scope: profile construction, crosswalk mapping, gap prioritization, and the closure disposition. Out of scope: authoring the policies and designing the new controls the gaps demand — those are handed off downstream to TWO workflows, Policy Lifecycle Management (policy-driven gaps) and Control Design (control-build gaps).","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-framework-adoption-cross-mapping","capabilities":[],"controls":["UC-GOV-16","UC-RISK-14"],"domains":["grc"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:1a62dedf9c3fd637b88064ca3f0909b6746b8c23914c060731d9c9c4acef0250","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-framework-adoption-cross-mapping","standards":["nist-csf-2","iso-27001","soc2"],"teams":["compliance-legal","risk-management"]},"id":"wf:G6","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG6","slug":"grc-framework-adoption-cross-mapping","sourceIds":["nist-800-53","soc2"],"sourceUrl":null,"title":"Framework Adoption & Cross-Mapping","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:100fe01610faae2684f5795798b84e7f9a0ca6283f57cf35610d13f5c34931c5","properties":{},"sourceDetailPath":"/data/v1/records/wf-g6-86d7ed66.json","sourceId":"wf:G6","targetDetailPath":"/data/v1/records/uc-uc-gov-16-694834ac.json","targetId":"uc:UC-GOV-16","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:252c84fd319ea6cb0455c7eb6fc88af12c07dccc1781fb8b5da2d0799803d1f1","properties":{},"sourceDetailPath":"/data/v1/records/wf-g6-86d7ed66.json","sourceId":"wf:G6","targetDetailPath":"/data/v1/records/uc-uc-risk-14-a5d6281b.json","targetId":"uc:UC-RISK-14","type":"oversees"}],"schemaVersion":1}
