← GRC Hub
Cross-framework Control Crosswalk
Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.
Dataset v1.0.0 · reviewed 2026-06-10 ·
methodology & method hierarchy →
nis2_art21 · ir_2024_2690_log — Logging, monitoring and detection (IR 2024/2690)
iso_27001_2022
- A.8.15 — Logging (exact, editorial): Logging.
- A.8.16 — Monitoring activities (exact, editorial): Monitoring activities.
nist_csf_2_0
- DE.CM-01 — Networks and network services are monitored to find potentially adverse events. (strong, editorial): Network monitoring.
- DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events. (strong, editorial): Endpoint monitoring.
- PR.PS-04 — Log records are generated and made available for continuous monitoring. (exact, editorial): Log generation and availability.
dora_rts_riskmgmt
- rts_art14 — Logging and monitoring (exact, dora-l2): Logging and monitoring.
- rts_art15 — ICT-related incident detection (strong, dora-l2): ICT-related incident detection.
Pivot: corresponding controls per target framework
Framework pair: full mapping
Coverage: if I implement X, how much of Y do I cover?
Tick the controls you have implemented in your source framework. The page computes coverage against each target framework using the formula exact = 1.0, strong = 0.75, partial = 0.4, related = 0, capped at 1.0 per target control.
Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its
method tag — filter or sort by it on the methodology page.