Control Catalogue
Definition
A structured list of security controls, each with an identifier, a statement of intent, and (in detailed catalogues) implementation guidance. Examples include NIST SP 800-53 (which lists hundreds of controls across 20 families) and ISO 27002 (93 controls across four themes). A catalogue is the source document from which a mapping is built.
- Example
- NIST SP 800-53
- SP 800-53 scope
- Hundreds of controls across 20 families
- Other example
- ISO 27002, 93 controls, 4 themes
Common questions
How is a control catalogue used when building a framework mapping?+
It serves as the source list from which each control is individually cross-referenced against equivalent or overlapping controls in a different catalogue, item by item.
Is a control catalogue the same thing as a compliance framework?+
No, a catalogue lists available controls, while a framework such as ISO 27001 specifies which of those controls an organisation must implement and how conformance will be assessed.
Related terms
- Control Family
- A grouping of related controls within a catalogue. NIST SP 800-53 uses 20 families identified by two-letter codes: AC (Access Control), AU...
- Crosswalk
- A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST,...
- Gap Analysis
- The process of comparing what a framework requires against what an organisation has actually implemented, to identify controls that are absent, partial,...
- Implementation Group (IG)
- A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers...
- Unified Control Mapping
- An organisation-specific artefact that consolidates multiple crosswalks into a single table, adds columns for the organisation's own control implementations and evidence artefacts,...