Crosswalk
Definition
A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST, CIS, and ISO all publish official crosswalks. A crosswalk is a starting point; it typically notes approximate equivalences and flags where one framework is more or less detailed than the other.
- Purpose
- Aligns controls from two frameworks that address the same objective
- Publishers
- NIST, CIS, ISO all publish official crosswalks
- Nature
- Approximate equivalence, not a guaranteed one-to-one map
- Use case
- Compliance teams reporting against multiple frameworks at once
Common questions
Why can a crosswalk mapping between two frameworks be only approximate?+
Frameworks differ in scope, granularity, and intent, so a control that satisfies one framework's requirement in full may only partially satisfy the corresponding control in another framework, or a single control in one framework might map to several in the other, which a crosswalk usually flags rather than glosses over.
How do organisations use a crosswalk in a compliance audit?+
A team subject to two overlapping frameworks, for example a company needing both ISO 27001 certification and NIST CSF alignment, uses a crosswalk to identify which evidence already gathered for one framework can support the other, avoiding duplicated audit work.
What is the risk of relying on a crosswalk without independent review?+
Treating an approximate mapping as exact can leave a genuine gap unaddressed, since a control marked equivalent on the crosswalk may still fall short of the second framework's specific evidentiary or implementation requirements, so mapped controls still need direct verification.
Related terms
- Implementation Group (IG)
- A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers...
- CIS Benchmark
- A technology-specific configuration hardening guide published by CIS for operating systems, cloud services, databases, and applications. Each Benchmark provides Level 1 (broadly...
- CIS Controls Self-Assessment Tool (CSAT)
- A free web-based tool provided by CIS that allows organisations to score their current implementation status for each Safeguard and generate a...
- CIS Controls V8
- The eighth version of the CIS Critical Security Controls, released in May 2021. It consolidates 18 Controls and 153 Safeguards, reorganised from...
- Control Catalogue
- A structured list of security controls, each with an identifier, a statement of intent, and (in detailed catalogues) implementation guidance. Examples include...
- Control Family
- A grouping of related controls within a catalogue. NIST SP 800-53 uses 20 families identified by two-letter codes: AC (Access Control), AU...
- Gap Analysis
- The process of comparing what a framework requires against what an organisation has actually implemented, to identify controls that are absent, partial,...
- Safeguard
- The individual action item within a CIS Control. Each Safeguard specifies a concrete activity (for example, 'establish and maintain an accurate inventory...
- Unified Control Mapping
- An organisation-specific artefact that consolidates multiple crosswalks into a single table, adds columns for the organisation's own control implementations and evidence artefacts,...
Explained in these topics
- CIS Controls and Implementation GroupsA published mapping document that shows the correspondence between CIS Safeguards and the controls or subcategories of another framework such as NIST CSF, ISO...
- Mapping Controls Across Frameworks