← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

gdpr_security · art32 — Security of processing (Art. 32)

nist_csf_2_0

  • PR.DS-01 — The confidentiality, integrity, and availability of data-at-rest are protected. (strong, editorial): Confidentiality of data at rest.
  • PR.DS-02 — The confidentiality, integrity, and availability of data-in-transit are protected. (strong, editorial): Confidentiality of data in transit.
  • PR.AA-05 — Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and they incorporate the principles of least privilege and separation of duties. (strong, editorial): Access control.
  • PR.IR-03 — Mechanisms are implemented to achieve resilience requirements in normal and adverse situations. (strong, editorial): Resilience.

iso_27001_2022

  • A.5.32 — Intellectual property rights (partial, editorial): IP rights tangential — but Art 32 is broader.
  • A.8.24 — Use of cryptography (strong, editorial): Encryption.
  • A.8.13 — Information backup (strong, editorial): Backup as resilience.
  • A.5.34 — Privacy and protection of PII (exact, editorial): PII protection.

dora_level1

  • art9 — Protection and prevention (strong, editorial): Both require risk-appropriate technical measures.

nist_800_53_r5_moderate

  • SC-13 — Cryptographic Protection (strong, editorial): Encryption as named GDPR technical measure.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.