Skip to content

Crosswalk

Definition

A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST, CIS, and ISO all publish official crosswalks. A crosswalk is a starting point; it typically notes approximate equivalences and flags where one framework is more or less detailed than the other.

Purpose
Aligns controls from two frameworks that address the same objective
Publishers
NIST, CIS, ISO all publish official crosswalks
Nature
Approximate equivalence, not a guaranteed one-to-one map
Use case
Compliance teams reporting against multiple frameworks at once

Common questions

Why can a crosswalk mapping between two frameworks be only approximate?+

Frameworks differ in scope, granularity, and intent, so a control that satisfies one framework's requirement in full may only partially satisfy the corresponding control in another framework, or a single control in one framework might map to several in the other, which a crosswalk usually flags rather than glosses over.

How do organisations use a crosswalk in a compliance audit?+

A team subject to two overlapping frameworks, for example a company needing both ISO 27001 certification and NIST CSF alignment, uses a crosswalk to identify which evidence already gathered for one framework can support the other, avoiding duplicated audit work.

What is the risk of relying on a crosswalk without independent review?+

Treating an approximate mapping as exact can leave a genuine gap unaddressed, since a control marked equivalent on the crosswalk may still fall short of the second framework's specific evidentiary or implementation requirements, so mapped controls still need direct verification.

Related terms

Implementation Group (IG)
A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers...
CIS Benchmark
A technology-specific configuration hardening guide published by CIS for operating systems, cloud services, databases, and applications. Each Benchmark provides Level 1 (broadly...
CIS Controls Self-Assessment Tool (CSAT)
A free web-based tool provided by CIS that allows organisations to score their current implementation status for each Safeguard and generate a...
CIS Controls V8
The eighth version of the CIS Critical Security Controls, released in May 2021. It consolidates 18 Controls and 153 Safeguards, reorganised from...
Control Catalogue
A structured list of security controls, each with an identifier, a statement of intent, and (in detailed catalogues) implementation guidance. Examples include...
Control Family
A grouping of related controls within a catalogue. NIST SP 800-53 uses 20 families identified by two-letter codes: AC (Access Control), AU...
Gap Analysis
The process of comparing what a framework requires against what an organisation has actually implemented, to identify controls that are absent, partial,...
Safeguard
The individual action item within a CIS Control. Each Safeguard specifies a concrete activity (for example, 'establish and maintain an accurate inventory...
Unified Control Mapping
An organisation-specific artefact that consolidates multiple crosswalks into a single table, adds columns for the organisation's own control implementations and evidence artefacts,...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.