← GRC Hub
Cross-framework Control Crosswalk
Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.
Dataset v1.0.0 · reviewed 2026-06-10 ·
methodology & method hierarchy →
nis2_art21 · 21_2_i — Human-resources security, access control policies and asset management
iso_27001_2022
- A.6.1 — Screening (exact, enisa-guidance): Screening.
- A.6.2 — Terms and conditions of employment (strong, enisa-guidance): Terms and conditions of employment.
- A.6.5 — Responsibilities after termination or change of employment (strong, enisa-guidance): Post-termination responsibilities.
- A.5.9 — Inventory of information and other associated assets (strong, enisa-guidance): Asset inventory.
- A.5.15 — Access control (exact, enisa-guidance): Access control.
- A.5.16 — Identity management (strong, enisa-guidance): Identity management.
- A.5.18 — Access rights (strong, enisa-guidance): Access rights.
- A.8.2 — Privileged access rights (strong, enisa-guidance): Privileged access rights.
nist_csf_2_0
- PR.AA-01 — Identities and credentials for authorized users, services, and hardware are managed by the organization. (exact, editorial): Identities and credentials management.
- PR.AA-05 — Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and they incorporate the principles of least privilege and separation of duties. (strong, editorial): Access permissions and least privilege.
- ID.AM-01 — Inventories of hardware managed by the organization are maintained. (strong, editorial): Hardware inventory.
- ID.AM-02 — Inventories of software, services, and systems managed by the organization are maintained. (strong, editorial): Software inventory.
- GV.RR-04 — Cybersecurity is included in human resources practices. (strong, editorial): Cybersecurity in HR practices.
dora_rts_riskmgmt
- rts_art5 — ICT asset management policy (exact, dora-l2): ICT asset management policy.
- rts_art12 — Logical access control (exact, dora-l2): Logical access control.
nist_800_53_r5_moderate
- AC-2 — Account Management (strong, editorial): Account management.
- AC-3 — Access Enforcement (strong, editorial): Access enforcement.
- CM-8 — System Component Inventory (strong, editorial): Asset inventory.
- PS-3 — Personnel Screening (strong, editorial): Screening.
Pivot: corresponding controls per target framework
Framework pair: full mapping
Coverage: if I implement X, how much of Y do I cover?
Tick the controls you have implemented in your source framework. The page computes coverage against each target framework using the formula exact = 1.0, strong = 0.75, partial = 0.4, related = 0, capped at 1.0 per target control.
Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its
method tag — filter or sort by it on the methodology page.