← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

nis2_art21 · 21_2_g — Basic cyber hygiene practices and cybersecurity training

iso_27001_2022

  • A.6.3 — Information security awareness, education and training (exact, enisa-guidance): Awareness, education and training.
  • A.6.8 — Information security event reporting (strong, enisa-guidance): Reporting events forms part of cyber hygiene.
  • A.8.7 — Protection against malware (strong, enisa-guidance): Malware protection.
  • A.8.8 — Management of technical vulnerabilities (strong, enisa-guidance): Technical vulnerability management as hygiene baseline.

nist_csf_2_0

  • PR.AT-01 — Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind. (exact, editorial): General awareness/training.
  • PR.AT-02 — Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind. (strong, editorial): Specialised role training.
  • PR.PS-05 — Installation and execution of unauthorized software are prevented. (strong, editorial): Prevent installation/execution of unauthorised software.

dora_rts_riskmgmt

  • rts_art21 — Human resources policy (strong, dora-l2): Human resources policy.
  • rts_art22 — Awareness programmes and training (exact, dora-l2): Awareness programmes and training.

nist_800_53_r5_moderate

  • AT-2 — Literacy Training and Awareness (strong, editorial): Awareness training.
  • AT-3 — Role-based Training (strong, editorial): Role-based training.
  • SI-3 — Malicious Code Protection (strong, editorial): Malware protection.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.