← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

nis2_art21 · 21_2_b — Incident handling

iso_27001_2022

  • A.5.24 — Information security incident management planning and preparation (exact, enisa-guidance): Incident management planning maps directly to incident handling.
  • A.5.25 — Assessment and decision on information security events (strong, enisa-guidance): Event assessment and decision is part of the incident handling lifecycle.
  • A.5.26 — Response to information security incidents (strong, enisa-guidance): Response to information security incidents.
  • A.5.27 — Learning from information security incidents (strong, enisa-guidance): Learning from incidents is part of the cycle.
  • A.5.28 — Collection of evidence (partial, editorial): Evidence collection during incident handling.
  • A.6.8 — Information security event reporting (partial, editorial): Personnel reporting feeds detection input to the incident process.

nist_csf_2_0

  • RS.MA-01 — The incident response plan is executed in coordination with relevant third parties once an incident is declared. (exact, editorial): Incident response plan execution.
  • RS.MA-02 — Incident reports are triaged and validated. (strong, editorial): Triage and validation.
  • RS.MA-03 — Incidents are categorized and prioritized. (strong, editorial): Categorisation and prioritisation.
  • RS.AN-03 — Analysis is performed to establish what has taken place during an incident and the root cause of the incident. (strong, editorial): Root-cause analysis.
  • DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria. (strong, editorial): Incident declaration.
  • DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities. (strong, editorial): Adverse event analysis.
  • DE.AE-04 — The estimated impact and scope of adverse events are understood. (strong, editorial): Impact and scope.
  • DE.AE-07 — Cyber threat intelligence and other contextual information are integrated into the analysis. (strong, editorial): Threat intel integration in analysis.
  • RS.MI-01 — Incidents are contained. (strong, editorial): Containment.
  • RS.MI-02 — Incidents are eradicated. (strong, editorial): Eradication.

dora_level1

  • art17 — ICT-related incident management process (exact, editorial): DORA Art 17 incident management process is the financial-sector parallel.
  • art18 — Classification of ICT-related incidents and cyber threats (strong, editorial): Classification of incidents.
  • art19 — Reporting of major ICT-related incidents and voluntary notification of significant cyber threats (strong, editorial): Major-incident reporting.

gdpr_security

  • art33 — Notification of a personal data breach to the supervisory authority (Art. 33) (partial, editorial): Breach notification overlaps where the incident involves personal data.

cra_essential

  • annex1_p2_05 — Coordinated vulnerability disclosure policy (partial, editorial): Coordinated vulnerability disclosure intersects incident communications.

nist_800_53_r5_moderate

  • IR-4 — Incident Handling (exact, editorial): Incident handling.
  • IR-6 — Incident Reporting (strong, editorial): Incident reporting.
  • IR-8 — Incident Response Plan (strong, editorial): IR plan.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.