07 Build an Enterprise Compliance Control Matrix
Welcome to the seventh project in:
Module 11 — Enterprise GRC Transformation Project
In the previous projects, you completed:
Enterprise Risk Assessment ↓Build an ISMS ↓ISO 27001 Gap Assessment ↓SOC 2 Readiness Review ↓PCI DSS Assessment ↓Cloud Compliance ReviewYou now have multiple frameworks, requirements, controls, evidence sources, owners, and assessments.
A new enterprise problem appears:
Too ManyFrameworksCloudNova currently manages compliance separately:
ISO 27001 Controls +SOC 2 Controls +PCI DSS Controls +ISO 27017 Controls +ISO 27018 ControlsThis creates:
Duplicate Controls
Duplicate Evidence
Duplicate Testing
Duplicate Interviews
Duplicate Remediation
Compliance FatigueYour assignment is to transform this fragmented approach into:
One EnterpriseComplianceControl MatrixProject Objective
Section titled “Project Objective”Your objective is to move CloudNova from:
Framework ↓Separate Controls ↓Separate Evidence ↓Separate Testingto:
Enterprise Risk ↓Common Control ↓Control Owner ↓Implementation ↓Evidence ↓Testing ↓Framework Mapping ↓Multiple ComplianceRequirementsThe central principle is:
Implement Once
Test Once
Collect Evidence Once
Map Many TimesMission Information
Section titled “Mission Information”Project Type: Enterprise Common Control Framework & Compliance Mapping
Difficulty: Advanced
Estimated Time: 6–8 Hours
Primary Role: GRC Analyst / Compliance Architect
Supporting Roles: Security / Internal Audit / IAM / Cloud / Privacy / IT / Risk / Legal / Control Owners
Frameworks: ISO 27001, SOC 2, PCI DSS, ISO 27017, ISO 27018, NIST CSF
Environment: Spreadsheet / GRC Platform / Documentation Platform
Deliverable: Enterprise Compliance Control Matrix & Common Control Framework
Important: Framework requirements and mappings change as standards evolve. Real-world mappings should always be validated against the organization’s licensed/current versions of the applicable standards.
Learning Objectives
Section titled “Learning Objectives”By completing this project, you will learn how to:
-
understand enterprise control frameworks.
-
distinguish requirements from controls.
-
distinguish controls from evidence.
-
create common enterprise controls.
-
normalize controls across frameworks.
-
map multiple frameworks.
-
establish control objectives.
-
create control IDs.
-
assign control owners.
-
identify control operators.
-
define control frequency.
-
classify preventive, detective, and corrective controls.
-
distinguish manual and automated controls.
-
map risks to controls.
-
map policies to controls.
-
map controls to frameworks.
-
establish evidence requirements.
-
eliminate duplicate evidence collection.
-
create testing procedures.
-
identify control dependencies.
-
manage compensating controls.
-
identify control gaps.
-
manage framework changes.
-
build compliance dashboards.
-
support continuous compliance.
-
create a scalable Common Control Framework.
Scenario
Section titled “Scenario”CloudNova’s GRC team maintains separate spreadsheets for:
ISO 27001
SOC 2
PCI DSS
Cloud Compliance
Privacy ComplianceThe IAM team receives multiple requests:
ISO Auditor:"Show MFA Evidence."
SOC 2 Auditor:"Show MFA Evidence."
PCI Assessor:"Show MFA Evidence."
Cloud Compliance:"Show MFA Evidence."The IAM manager asks:
Why Are WeProviding theSame EvidenceFour Times?The CISO asks:
Why Do We HaveFour DifferentMFA Controls?Your answer should be:
We Shouldn't.Instead, CloudNova needs:
One MFA Control ↓One Owner ↓One Implementation ↓One Evidence Process ↓Multiple FrameworkMappingsYour Mission
Section titled “Your Mission”Build CloudNova’s:
EnterpriseCommon ControlFrameworkand create a master:
ComplianceControl Matrixthat connects:
Risk
Policy
Control
Owner
Implementation
Evidence
Testing
Framework
Requirement
Gap
RemediationRequired Deliverables
Section titled “Required Deliverables”Create:
01 Framework Inventory
02 Requirement Inventory
03 Enterprise Control Taxonomy
04 Common Control Library
05 Risk-to-Control Matrix
06 Policy-to-Control Matrix
07 Framework-to-Control Matrix
08 Control Ownership Register
09 Evidence Mapping Matrix
10 Control Testing Matrix
11 Control Dependency Register
12 Gap & Exception Register
13 Compliance Coverage Matrix
14 Enterprise Compliance Dashboard
15 Control Framework Governance Standard
16 Continuous Compliance PlanPart 1 — Understand the Problem
Section titled “Part 1 — Understand the Problem”Without a Common Control Framework:
Framework A ↓Control A1
Framework B ↓Control B1
Framework C ↓Control C1Even though all three controls may address:
Multi-FactorAuthenticationThis produces unnecessary duplication.
Part 2 — Build a Common Control Framework
Section titled “Part 2 — Build a Common Control Framework”Instead:
Enterprise ControlIAM-003 ↓Privileged MFA ↓ISO 27001 +SOC 2 +PCI DSS +ISO 27017 +NIST CSFOne control can support multiple requirements.
Part 3 — Understand Requirements vs Controls
Section titled “Part 3 — Understand Requirements vs Controls”A:
Requirementdescribes what must be achieved.
A:
Controldescribes what the organization implements to achieve it.
For example:
Requirement ↓Restrict Accessto Authorized UsersCloudNova may implement:
IAM-001Role-Based Access
IAM-002Access Approval
IAM-003MFA
IAM-004Quarterly Access ReviewPart 4 — Understand Controls vs Evidence
Section titled “Part 4 — Understand Controls vs Evidence”A control is not evidence.
Example:
Control:Privileged MFAEvidence might include:
MFA Configuration
Identity Report
User Population
Authentication Logs
Exception ReportThink:
Control ↓Operates ↓Produces EvidencePart 5 — Start With Framework Inventory
Section titled “Part 5 — Start With Framework Inventory”Create an inventory of applicable frameworks.
Example:
| Framework | Purpose | Scope | Owner |
|---|---|---|---|
| ISO 27001 | ISMS | Enterprise | GRC |
| SOC 2 | Assurance | SaaS Platform | Compliance |
| PCI DSS | Payment Security | CDE | Compliance |
| ISO 27017 | Cloud Security | Cloud Services | Cloud GRC |
| ISO 27018 | Cloud Privacy | Public Cloud PII | Privacy |
| NIST CSF | Cyber Risk | Enterprise | Security |
Part 6 — Add Framework Metadata
Section titled “Part 6 — Add Framework Metadata”Record:
Framework
Version / Edition
Regulatory / Contractual Driver
Scope
Business Unit
System
Data
Owner
Assessment Type
Assessment FrequencyPart 7 — Maintain Version Awareness
Section titled “Part 7 — Maintain Version Awareness”Do not record only:
ISO 27001Record the applicable:
Framework+Edition+Scope+Assessment PeriodFramework changes can affect mappings.
Part 8 — Build Requirement Inventory
Section titled “Part 8 — Build Requirement Inventory”Create a normalized inventory containing:
Requirement ID
Framework
Requirement Reference
Requirement Summary
Domain
Applicability
Scope
Mapped Controls
Owner
StatusPart 9 — Do Not Copy Standards Unnecessarily
Section titled “Part 9 — Do Not Copy Standards Unnecessarily”The purpose of your matrix is not to reproduce copyrighted standards.
Instead maintain:
Requirement Reference +Internal Summary +Control Mappingwhile using licensed official standards as the authoritative source.
Part 10 — Create Enterprise Control Domains
Section titled “Part 10 — Create Enterprise Control Domains”Organize controls into logical domains.
For CloudNova:
GOV — Governance
RISK — Risk Management
IAM — Identity & Access
HR — Human Resources Security
AST — Asset Management
DATA — Data Protection
CRY — Cryptography
NET — Network Security
CFG — Configuration Management
VUL — Vulnerability Management
APP — Application Security
CLD — Cloud Security
LOG — Logging & Monitoring
IR — Incident Response
BCM — Business Continuity
TPRM — Third-Party Risk
PHY — Physical Security
PRV — Privacy
AUD — Audit & Assurance
CMP — Compliance ManagementPart 11 — Create Control IDs
Section titled “Part 11 — Create Control IDs”Use predictable identifiers.
Example:
IAM-001
IAM-002
IAM-003
NET-001
LOG-001
IR-001Avoid:
Control 17
Security Control New
SOC-MFA-Control
PCI-MFA-ControlPart 12 — Create Control Naming Standard
Section titled “Part 12 — Create Control Naming Standard”Use:
Domain+Control ObjectiveExamples:
IAM-001 — User Access Provisioning
IAM-002 — Privileged Access Management
IAM-003 — Multi-Factor Authentication
IAM-004 — Periodic Access Review
LOG-001 — Security Event Logging
VUL-001 — Vulnerability ScanningPart 13 — Define Control Objective
Section titled “Part 13 — Define Control Objective”Every control should explain:
What RiskDoes ThisControl Address?Example:
Control:IAM-003
Objective:Reduce the risk ofunauthorized accountaccess through strongauthentication.Part 14 — Define Control Description
Section titled “Part 14 — Define Control Description”Example:
CloudNova requiresmulti-factor authenticationfor applicable privileged,remote, and sensitivesystem access.The description should explain:
Who
What
Where
When
HowPart 15 — Create Control Record
Section titled “Part 15 — Create Control Record”Each control should contain:
Control ID
Control Name
Domain
Control Objective
Description
Risk
Policy
Owner
Operator
Scope
Frequency
Control Type
Automation
Evidence
Testing Procedure
Framework Mapping
StatusPart 16 — Example Control Record
Section titled “Part 16 — Example Control Record”Control ID:IAM-003
Control:Multi-Factor Authentication
Domain:Identity & Access
Owner:IAM Manager
Operator:Identity Operations
Type:Preventive
Frequency:Continuous
Automation:Automated
Evidence:MFA ConfigurationMFA Coverage ReportException RegisterAuthentication LogsPart 17 — Classify Control Types
Section titled “Part 17 — Classify Control Types”Controls may be:
Preventive
Detective
CorrectiveExample:
MFA→ Preventive
Security Alert→ Detective
Account Disablement→ CorrectivePart 18 — Manual vs Automated
Section titled “Part 18 — Manual vs Automated”Classify controls as:
Manual
Semi-Automated
AutomatedExample:
QuarterlyAccess Review→ Manual / Semi-Automated
MFA Enforcement→ Automated
SIEM Alert→ AutomatedPart 19 — Frequency
Section titled “Part 19 — Frequency”Define frequencies such as:
Continuous
Event-Driven
Daily
Weekly
Monthly
Quarterly
Semi-Annual
AnnualFrequency should reflect the control’s purpose and applicable requirements.
Part 20 — Assign Control Owners
Section titled “Part 20 — Assign Control Owners”The control owner is accountable for:
Control Design
Implementation
Operation
Evidence
RemediationDo not assign every control to:
Security TeamPart 21 — Example Ownership
Section titled “Part 21 — Example Ownership”IAM Controls→ IAM Manager
Network Controls→ Network Manager
Cloud Controls→ Cloud Platform Manager
HR Controls→ HR
Vendor Controls→ Procurement / TPRM
Privacy Controls→ Privacy
Incident Controls→ SOC / SecurityPart 22 — Owner vs Operator
Section titled “Part 22 — Owner vs Operator”These may differ.
Example:
Control Owner:CISO
Control Operator:SOC Teamor:
Control Owner:IAM Manager
Control Operator:Identity OperationsPart 23 — Map Risks to Controls
Section titled “Part 23 — Map Risks to Controls”Connect the Enterprise Risk Register to the control library.
Example:
| Risk | Control | Relationship |
|---|---|---|
| Unauthorized Access | IAM-003 MFA | Mitigates |
| Excessive Privilege | IAM-002 PAM | Mitigates |
| Data Leakage | DATA-002 DLP | Mitigates |
| Malware | END-001 Endpoint Protection | Mitigates |
Part 24 — One Risk Can Have Multiple Controls
Section titled “Part 24 — One Risk Can Have Multiple Controls”Example:
Risk:Account CompromiseControls:
MFA
Password Policy
Conditional Access
PAM
Authentication Monitoring
User AwarenessThink:
Risk ↓Multiple Layersof ControlsPart 25 — One Control Can Address Multiple Risks
Section titled “Part 25 — One Control Can Address Multiple Risks”Example:
MFAcan help reduce:
Credential Theft
Remote Access Abuse
Privileged Account Compromise
Cloud Account TakeoverPart 26 — Build Risk-to-Control Matrix
Section titled “Part 26 — Build Risk-to-Control Matrix”Use:
| Risk ID | Risk | Control ID | Control | Coverage |
|---|---|---|---|---|
| R-001 | Account Compromise | IAM-003 | MFA | Primary |
| R-001 | Account Compromise | LOG-002 | Auth Monitoring | Secondary |
| R-002 | Data Exposure | DATA-001 | Classification | Supporting |
Part 27 — Map Policies to Controls
Section titled “Part 27 — Map Policies to Controls”Policies establish expectations.
Controls implement them.
Example:
Access Control Policy ↓IAM-001Provisioning
IAM-002Privileged Access
IAM-003MFA
IAM-004Access ReviewPart 28 — Build Policy-to-Control Matrix
Section titled “Part 28 — Build Policy-to-Control Matrix”Record:
Policy
Policy Section
Control ID
Control Owner
Implementation
EvidencePart 29 — Begin Framework Mapping
Section titled “Part 29 — Begin Framework Mapping”Now connect enterprise controls to:
ISO 27001
SOC 2
PCI DSS
ISO 27017
ISO 27018
NIST CSFPart 30 — Example Mapping
Section titled “Part 30 — Example Mapping”IAM-003Multi-Factor Authentication ↓ISO 27001 ↓SOC 2 ↓PCI DSS ↓ISO 27017 ↓NIST CSFThe exact mapping must be validated against applicable framework versions.
Part 31 — Mapping Does Not Mean Equivalence
Section titled “Part 31 — Mapping Does Not Mean Equivalence”This is critical.
If:
Control Amaps to requirements in:
Framework X+Framework Yit does not automatically mean those requirements are identical.
Mapping means:
Control SupportsRequirementnot necessarily:
RequirementsAre EquivalentPart 32 — Add Mapping Strength
Section titled “Part 32 — Add Mapping Strength”Use:
Primary
Supporting
Partial
Not ApplicableExample:
| Control | ISO | SOC 2 | PCI DSS | NIST |
|---|---|---|---|---|
| IAM-003 | Primary | Supporting | Primary | Supporting |
| LOG-001 | Primary | Primary | Primary | Primary |
Part 33 — Identify Partial Coverage
Section titled “Part 33 — Identify Partial Coverage”Suppose a framework requires:
Access Approval+MFA+Access ReviewMapping only:
IAM-003 MFAdoes not provide complete coverage.
Mark:
PartialPart 34 — Many-to-Many Mapping
Section titled “Part 34 — Many-to-Many Mapping”Real compliance mapping looks like:
Requirement 1 ├── Control A ├── Control B └── Control C
Control A ├── Requirement 1 ├── Requirement 7 └── Requirement 14This is:
Many-to-ManyMappingPart 35 — Build Framework-to-Control Matrix
Section titled “Part 35 — Build Framework-to-Control Matrix”Example:
| Control | ISO 27001 | SOC 2 | PCI DSS | ISO 27017 | ISO 27018 | NIST CSF |
|---|---|---|---|---|---|---|
| IAM-001 | ✓ | ✓ | ✓ | ✓ | ✓ | |
| IAM-003 | ✓ | ✓ | ✓ | ✓ | ✓ | |
| LOG-001 | ✓ | ✓ | ✓ | ✓ | ✓ | |
| PRV-001 | ✓ | ✓ | ✓ | ✓ |
Part 36 — Identify Control Coverage
Section titled “Part 36 — Identify Control Coverage”For each framework calculate:
Applicable Requirements
Mapped Requirements
Fully Covered
Partially Covered
UnmappedPart 37 — Coverage Is Not Compliance
Section titled “Part 37 — Coverage Is Not Compliance”Do not say:
100%Requirements Mapped
Therefore100% CompliantMapping only shows:
ControlCoverageCompliance also requires:
Implementation
Operating Effectiveness
Evidence
Scope
ApplicabilityPart 38 — Build Common Control Library
Section titled “Part 38 — Build Common Control Library”Create one authoritative:
EnterpriseControl LibraryDo not maintain separate master controls for every framework.
Part 39 — Example IAM Control Family
Section titled “Part 39 — Example IAM Control Family”IAM-001Identity Lifecycle
IAM-002Access Approval
IAM-003Multi-Factor Authentication
IAM-004Privileged Access Management
IAM-005Access Review
IAM-006Service Account Management
IAM-007Emergency Access
IAM-008Authentication MonitoringPart 40 — Network Control Family
Section titled “Part 40 — Network Control Family”NET-001Network Segmentation
NET-002Firewall Management
NET-003Internet Exposure Management
NET-004Remote Access Security
NET-005Network Monitoring
NET-006Network Configuration ReviewPart 41 — Data Protection Control Family
Section titled “Part 41 — Data Protection Control Family”DATA-001Data Classification
DATA-002Data Handling
DATA-003Data Retention
DATA-004Secure Deletion
DATA-005Data Loss Prevention
DATA-006Sensitive Data AccessPart 42 — Logging Control Family
Section titled “Part 42 — Logging Control Family”LOG-001Security Event Logging
LOG-002Central Log Collection
LOG-003Log Protection
LOG-004Security Monitoring
LOG-005Alert Investigation
LOG-006Log RetentionPart 43 — Vulnerability Control Family
Section titled “Part 43 — Vulnerability Control Family”VUL-001Vulnerability Scanning
VUL-002Patch Management
VUL-003Vulnerability Remediation
VUL-004Penetration Testing
VUL-005Dependency Scanning
VUL-006Container ScanningPart 44 — Cloud Control Family
Section titled “Part 44 — Cloud Control Family”CLD-001Cloud Service Onboarding
CLD-002Cloud Security Baseline
CLD-003Cloud IAM
CLD-004Cloud Logging
CLD-005Cloud Configuration Monitoring
CLD-006Cloud Data Protection
CLD-007Cloud Backup
CLD-008Cloud Exit ManagementPart 45 — Privacy Control Family
Section titled “Part 45 — Privacy Control Family”PRV-001PII Inventory
PRV-002Processing Purpose
PRV-003Data Minimization
PRV-004PII Access
PRV-005PII Retention
PRV-006PII Deletion
PRV-007Privacy Incident Response
PRV-008Subprocessor ManagementPart 46 — Evidence Mapping
Section titled “Part 46 — Evidence Mapping”Now ask:
What EvidenceProves EachControl?Part 47 — Evidence Catalog
Section titled “Part 47 — Evidence Catalog”Create evidence IDs:
E-IAM-001
E-IAM-002
E-NET-001
E-LOG-001Part 48 — Example Evidence Mapping
Section titled “Part 48 — Example Evidence Mapping”IAM-003Multi-Factor Authentication ↓E-IAM-003AMFA Configuration
E-IAM-003BMFA Coverage Report
E-IAM-003CException Register
E-IAM-003DAuthentication LogsPart 49 — Reuse Evidence
Section titled “Part 49 — Reuse Evidence”The same evidence may support:
ISO 27001
SOC 2
PCI DSS
Cloud ComplianceAvoid collecting identical evidence separately.
Part 50 — Evidence Metadata
Section titled “Part 50 — Evidence Metadata”Record:
Evidence ID
Control ID
Artifact
System
Owner
Frequency
Period
Location
Retention
Automation
Frameworks SupportedPart 51 — Build Evidence Matrix
Section titled “Part 51 — Build Evidence Matrix”Example:
| Evidence | Control | ISO | SOC 2 | PCI | Cloud |
|---|---|---|---|---|---|
| MFA Report | IAM-003 | ✓ | ✓ | ✓ | ✓ |
| Firewall Review | NET-002 | ✓ | ✓ | ✓ | ✓ |
| Incident Test | IR-004 | ✓ | ✓ | ✓ | ✓ |
Part 52 — Evidence Once, Use Many
Section titled “Part 52 — Evidence Once, Use Many”The future state should be:
Control Operates ↓Evidence Generated ↓Evidence Repository ↓Mapped Automatically ↓ISOSOC 2PCICloudPart 53 — Establish Evidence Repository
Section titled “Part 53 — Establish Evidence Repository”Evidence should not live only in:
Auditor Email
Desktop Folder
Random SharePoint Folder
Individual LaptopCreate an authoritative repository.
Part 54 — Evidence Naming Standard
Section titled “Part 54 — Evidence Naming Standard”Example:
2026-Q3_IAM-003_MFA-Coverage
2026-Q3_NET-002_Firewall-Review
2026-08_LOG-001_Log-ConfigurationPart 55 — Evidence Quality
Section titled “Part 55 — Evidence Quality”Assess:
Completeness
Accuracy
Period
Population
Traceability
Integrity
Approver
SourcePart 56 — Build Control Testing Procedures
Section titled “Part 56 — Build Control Testing Procedures”Each control should have a reusable:
Test ProcedureExample:
Control:IAM-003
Test:
1. Obtain user population.2. Identify applicable accounts.3. Obtain MFA configuration.4. Compare population to enrollment.5. Identify exceptions.6. Validate approved exceptions.7. Sample authentication events.8. Document conclusion.Part 57 — Test Once, Map Many
Section titled “Part 57 — Test Once, Map Many”Instead of:
ISO MFA Test
SOC MFA Test
PCI MFA Testperform:
EnterpriseIAM-003 TestThen map the result to relevant requirements.
Part 58 — Control Test Record
Section titled “Part 58 — Control Test Record”Maintain:
Test ID
Control ID
Tester
Period
Population
Sample
Procedure
Evidence
Exceptions
Conclusion
Framework ImpactPart 59 — Design Effectiveness
Section titled “Part 59 — Design Effectiveness”Ask:
If the ControlOperates as Designed,
Will It AchieveIts Objective?Part 60 — Operating Effectiveness
Section titled “Part 60 — Operating Effectiveness”Ask:
Did the ControlActually Operateas DesignedDuring the Period?Part 61 — Example
Section titled “Part 61 — Example”Control:
QuarterlyAccess ReviewDesign:
Quarterly ReviewDefinedOperation:
Q1 ✓Q2 ✓Q3 MissingQ4 ✓Conclusion:
Design Effective
OperatingEffectivenessExceptionPart 62 — Build Control Dependency Register
Section titled “Part 62 — Build Control Dependency Register”Controls frequently depend on other controls.
Example:
LOG-004Security Monitoring ↓Depends On ↓LOG-001Event LoggingIf logging fails:
MonitoringMay Also FailPart 63 — Another Dependency
Section titled “Part 63 — Another Dependency”IAM-005Access Review ↓Depends On ↓Accurate IdentityInventoryBad inventory produces:
Bad ReviewPart 64 — Identify Key Controls
Section titled “Part 64 — Identify Key Controls”Not every control has equal importance.
Identify:
Key Controls
Supporting Controls
Compensating ControlsPart 65 — Key Control
Section titled “Part 65 — Key Control”A key control is one whose failure could materially affect:
Risk
Compliance
Security
AssurancePart 66 — Compensating Controls
Section titled “Part 66 — Compensating Controls”When a required or expected control cannot be implemented as designed, an alternative may sometimes mitigate the risk.
But:
AlternativeControlmust not automatically be assumed to satisfy:
FrameworkRequirementValidate applicable framework rules.
Part 67 — Exception Management
Section titled “Part 67 — Exception Management”Create:
Exception ID
Control
Reason
Risk
Compensating Control
Owner
Approval
Expiry
Review Date
StatusPart 68 — Exceptions Need Expiry Dates
Section titled “Part 68 — Exceptions Need Expiry Dates”Avoid:
TemporaryException
Created:2022
Status:Still OpenRequire:
Expiry
Review
Renewal
ClosurePart 69 — Build Compliance Gap Register
Section titled “Part 69 — Build Compliance Gap Register”A gap may occur because:
RequirementNot Mapped
Control Missing
Control Poorly Designed
Control Not Implemented
Control Failed
Evidence Missing
Scope IncorrectPart 70 — Classify Gap Types
Section titled “Part 70 — Classify Gap Types”Use:
Mapping Gap
Design Gap
Implementation Gap
Operating Gap
Evidence Gap
Ownership Gap
Scope GapPart 71 — Example Gap
Section titled “Part 71 — Example Gap”Gap:CMP-014
Requirement:Periodic access review
Mapped Control:IAM-005
Condition:Control exists butQ2 review was notperformed.
Gap Type:Operating GapPart 72 — Avoid Duplicate Findings
Section titled “Part 72 — Avoid Duplicate Findings”If one failed control affects:
ISO
SOC 2
PCI DSSdo not automatically create three separate remediation projects.
Create:
OneControl Deficiencywith:
MultipleCompliance ImpactsPart 73 — Example
Section titled “Part 73 — Example”Deficiency:IAM-003MFA CoverageIncomplete ↓Impacts ↓ISO 27001
SOC 2
PCI DSS
Cloud CompliancePart 74 — Prioritize by Enterprise Risk
Section titled “Part 74 — Prioritize by Enterprise Risk”Do not prioritize only because:
AuditorAsked FirstUse:
Risk Severity
Control Criticality
Framework Impact
Business Impact
Exploitability
Regulatory ExposurePart 75 — Build Remediation Record
Section titled “Part 75 — Build Remediation Record”Record:
Gap ID
Control
Risk
Affected Frameworks
Action
Owner
Target Date
Evidence
Retest
StatusPart 76 — Framework Coverage Analysis
Section titled “Part 76 — Framework Coverage Analysis”Calculate:
Total ApplicableRequirements
Fully Covered
Partially Covered
Unmapped
Control Effective
Control DeficientPart 77 — Example Coverage Dashboard
Section titled “Part 77 — Example Coverage Dashboard”ISO 27001
Applicable Requirements 100%
Mapped 96%
Fully Covered 91%
Partially Covered 5%
Unmapped 4%
Effective Controls 87%Values are illustrative.
Part 78 — Enterprise Dashboard
Section titled “Part 78 — Enterprise Dashboard”Example:
COMMON CONTROL FRAMEWORK
Enterprise Controls 142
Key Controls 47
Frameworks 6
Requirements Mapped 94%
Controls Effective 88%
Control Deficiencies 14
Critical Deficiencies 2
Evidence Ready 91%
Open Exceptions 11
Overdue Remediation 4Part 79 — Dashboard by Domain
Section titled “Part 79 — Dashboard by Domain”| Domain | Controls | Effective | Gaps |
|---|---|---|---|
| IAM | 12 | 92% | 2 |
| Network | 10 | 90% | 2 |
| Cloud | 15 | 80% | 5 |
| Logging | 8 | 88% | 2 |
| Privacy | 10 | 70% | 6 |
Part 80 — Dashboard by Framework
Section titled “Part 80 — Dashboard by Framework”ISO 27001Coverage: 96%
SOC 2Coverage: 94%
PCI DSSCoverage: 91%
ISO 27017Coverage: 89%
ISO 27018Coverage: 84%
NIST CSFCoverage: 95%These percentages should represent clearly defined metrics rather than generic “compliance scores.”
Part 81 — Identify Concentration Risk
Section titled “Part 81 — Identify Concentration Risk”Suppose:
IAM-003supports:
5 FrameworksFailure of this control has:
HighComplianceImpactThis is:
ControlConcentrationRiskPart 82 — Identify High-Impact Controls
Section titled “Part 82 — Identify High-Impact Controls”Rank controls by:
Risk Criticality
Framework Coverage
System Coverage
Business Criticality
Dependency CountPart 83 — Common Controls Become Strategic
Section titled “Part 83 — Common Controls Become Strategic”A strong control such as:
Centralized IAMmay support dozens of requirements.
Therefore:
ImprovingOne Controlcan improve:
MultipleCompliance ProgramsPart 84 — Map Controls to Assets
Section titled “Part 84 — Map Controls to Assets”Extend the matrix:
Control ↓System ↓Asset ↓Business ServiceExample:
IAM-003 ↓AWS
Azure
Microsoft 365
GitHub
ServiceNowPart 85 — Scope Matters
Section titled “Part 85 — Scope Matters”A control can be effective for:
AWSbut ineffective for:
GitHubTherefore do not record only:
IAM-003EffectiveConsider:
Control+ScopePart 86 — Control Implementation Instances
Section titled “Part 86 — Control Implementation Instances”One enterprise control may have multiple implementations.
Example:
IAM-003MFA │ ├── Microsoft Entra ID ├── AWS IAM Identity Center ├── GitHub └── ServiceNowPart 87 — Implementation Register
Section titled “Part 87 — Implementation Register”Record:
Control
System
Implementation
Owner
Configuration
Evidence
StatusPart 88 — Common Control vs Local Control
Section titled “Part 88 — Common Control vs Local Control”Some controls are:
EnterpriseCommon ControlsOthers may be:
System-SpecificControlsExample:
Enterprise:Security Awareness
System-Specific:PCI Payment ApplicationInput ValidationPart 89 — Inherited Controls
Section titled “Part 89 — Inherited Controls”Systems may inherit controls from shared services.
Example:
Application ↓Uses EnterpriseIdentity Provider ↓InheritsAuthenticationControlsPart 90 — Build Inheritance Model
Section titled “Part 90 — Build Inheritance Model”Record:
System
Inherited Control
Provider
Implementation
Evidence
ResponsibilityPart 91 — Internal Shared Services
Section titled “Part 91 — Internal Shared Services”Common control providers may include:
Enterprise IAM
SOC
Network Security
Cloud Platform
HR
Security Awareness
Backup Platform
GRCPart 92 — External Control Inheritance
Section titled “Part 92 — External Control Inheritance”Some controls may be provided by:
Cloud Provider
SaaS Provider
Data Center
Managed Security ProviderBut responsibility must still be understood.
Part 93 — Integrate Third-Party Controls
Section titled “Part 93 — Integrate Third-Party Controls”Example:
Cloud ProviderPhysical Security ↓Provider Assurance ↓CloudNovaControl MappingPart 94 — Evidence for Inherited Controls
Section titled “Part 94 — Evidence for Inherited Controls”Potential evidence:
SOC Report
ISO Certificate
Provider Documentation
Contract
Shared Responsibility Matrix
Internal ReviewPart 95 — Map Controls to Policies
Section titled “Part 95 — Map Controls to Policies”The mature model becomes:
Risk ↓Policy ↓Standard ↓Control ↓Procedure ↓Technology ↓Evidence ↓TestingPart 96 — Example
Section titled “Part 96 — Example”Risk:Unauthorized Access
Policy:Access Control Policy
Standard:Authentication Standard
Control:IAM-003 MFA
Technology:Identity Platform
Evidence:MFA Coverage Report
Testing:Quarterly Control TestPart 97 — Map Controls to Processes
Section titled “Part 97 — Map Controls to Processes”Controls should connect to business processes such as:
Joiner
Mover
Leaver
Change Management
Incident Response
Vendor Onboarding
Cloud Onboarding
Vulnerability ManagementPart 98 — Map Controls to Metrics
Section titled “Part 98 — Map Controls to Metrics”Every important control should have measurable indicators where useful.
Example:
IAM-003MFA
KPI:MFA Coverage
Target:100%
KRI:Privileged AccountsWithout MFA
Tolerance:0Part 99 — Control Health
Section titled “Part 99 — Control Health”Create:
GreenEffective
AmberPartial / Exception
RedIneffective
GreyNot AssessedPart 100 — Avoid Manual Status Guessing
Section titled “Part 100 — Avoid Manual Status Guessing”Where possible:
Control ↓System Data ↓Metric ↓HealthExample:
MFA ↓Identity API ↓Coverage ↓Control StatusPart 101 — Continuous Control Monitoring
Section titled “Part 101 — Continuous Control Monitoring”Move from:
AnnualControl Testtoward:
ContinuousControlMonitoringwhere technically and operationally appropriate.
Part 102 — Example Continuous Control
Section titled “Part 102 — Example Continuous Control”Identity Platform ↓Daily User Export ↓MFA Coverage Check ↓Exception Detected ↓Ticket Created ↓Remediation ↓Evidence StoredPart 103 — Evidence Automation
Section titled “Part 103 — Evidence Automation”Potential sources:
Identity APIs
Cloud APIs
SIEM
Vulnerability Scanner
Ticketing
Configuration Platforms
Endpoint Management
CI/CD
HR SystemsPart 104 — GRC Platform Integration
Section titled “Part 104 — GRC Platform Integration”Future-state architecture:
Enterprise Systems ↓Automated Evidence ↓GRC Platform ↓Common Controls ↓Framework Mapping ↓Dashboards ↓AssurancePart 105 — Framework Change Management
Section titled “Part 105 — Framework Change Management”Frameworks evolve.
Therefore mappings must be:
VersionedWhen a framework changes:
New Requirement ↓Impact Analysis ↓Existing Control? ↓Yes → Map
No → Gap ↓New / Modified ControlPart 106 — Maintain Mapping History
Section titled “Part 106 — Maintain Mapping History”Record:
Framework Version
Mapping Version
Change Date
Change
Reviewer
ApprovalPart 107 — New Framework Onboarding
Section titled “Part 107 — New Framework Onboarding”Suppose CloudNova later adopts:
HIPAA
DORA
NIS2
FedRAMP
CIS ControlsDo not rebuild the control environment.
Instead:
New Framework ↓Requirement Inventory ↓Map Existing Controls ↓Identify Gaps ↓Add OnlyNecessary ControlsPart 108 — This Is the Scaling Benefit
Section titled “Part 108 — This Is the Scaling Benefit”Without common controls:
New Framework ↓New ComplianceProgramWith common controls:
New Framework ↓Mapping Exercise +Gap AnalysisPart 109 — Common Mistake: Framework-Centric Controls
Section titled “Part 109 — Common Mistake: Framework-Centric Controls”Avoid:
ISO Control
SOC Control
PCI ControlPrefer:
EnterpriseSecurity Controlwith framework mappings.
Part 110 — Common Mistake: Mapping by Similar Words
Section titled “Part 110 — Common Mistake: Mapping by Similar Words”Two requirements containing:
Access Controlare not automatically equivalent.
Understand:
Intent
Scope
Frequency
Evidence
Implementation
Specific ConditionsPart 111 — Common Mistake: Mapping Everything to Everything
Section titled “Part 111 — Common Mistake: Mapping Everything to Everything”Weak mapping:
IAM Policy ↓20 Requirementswithout validating actual coverage.
Mapping must be defensible.
Part 112 — Common Mistake: Control Exists Therefore Requirement Met
Section titled “Part 112 — Common Mistake: Control Exists Therefore Requirement Met”A mapped control can still be:
Not Implemented
Partially Implemented
Ineffective
Out of Scope
Missing EvidencePart 113 — Common Mistake: Duplicate Evidence
Section titled “Part 113 — Common Mistake: Duplicate Evidence”Avoid:
ISO Evidence Folder
SOC Evidence Folder
PCI Evidence Foldercontaining copies of the same artifact.
Prefer:
AuthoritativeEvidence Repository ↓FrameworkReferencesPart 114 — Common Mistake: No Ownership
Section titled “Part 114 — Common Mistake: No Ownership”A control without an owner becomes:
Everyone'sResponsibilitywhich often means:
Nobody'sResponsibilityPart 115 — Common Mistake: No Control Testing
Section titled “Part 115 — Common Mistake: No Control Testing”Documentation alone does not demonstrate effectiveness.
Move through:
Control Defined ↓Implemented ↓Operating ↓Tested ↓EffectivePart 116 — Common Mistake: Compliance Percentage Without Context
Section titled “Part 116 — Common Mistake: Compliance Percentage Without Context”Avoid:
94%Compliantwithout explaining what the number represents.
Instead report:
Requirement Coverage
Control Effectiveness
Evidence Readiness
Open Deficiencies
Critical Risks
Remediation StatusPart 117 — Common Control Framework Maturity
Section titled “Part 117 — Common Control Framework Maturity”Level 1 — Fragmented
Section titled “Level 1 — Fragmented”Framework-SpecificControlsLevel 2 — Mapped
Section titled “Level 2 — Mapped”Cross-FrameworkMappingLevel 3 — Common Controls
Section titled “Level 3 — Common Controls”EnterpriseControl LibraryLevel 4 — Integrated Assurance
Section titled “Level 4 — Integrated Assurance”Common Evidence
Common Testing
Unified ReportingLevel 5 — Continuous Assurance
Section titled “Level 5 — Continuous Assurance”Automated Evidence ↓Continuous Testing ↓Control Health ↓Framework Mapping ↓Real-TimeCompliance InsightPart 118 — Future-State CloudNova
Section titled “Part 118 — Future-State CloudNova”Move from:
ISO Spreadsheet
SOC Spreadsheet
PCI Spreadsheet
Cloud Spreadsheet
Privacy Spreadsheetto:
EnterpriseRisk Register ↓Common ControlFramework ↓Control Owners ↓Evidence Repository ↓Control Testing ↓Framework Mapping ↓Compliance DashboardPractical Assignment
Section titled “Practical Assignment”Build CloudNova’s Enterprise Compliance Control Matrix.
Task 1 — Create Framework Inventory
Section titled “Task 1 — Create Framework Inventory”Include at least:
ISO 27001
SOC 2
PCI DSS
ISO 27017
ISO 27018
NIST CSFTask 2 — Build Requirement Inventory
Section titled “Task 2 — Build Requirement Inventory”Create normalized records containing:
Framework
Requirement
Domain
Scope
ApplicabilityTask 3 — Create Control Taxonomy
Section titled “Task 3 — Create Control Taxonomy”Create at least:
15 ControlDomainsTask 4 — Build Common Control Library
Section titled “Task 4 — Build Common Control Library”Create at least:
75 EnterpriseControlsacross:
Governance
Risk
IAM
Data
Network
Cloud
Applications
Vulnerability
Logging
Incident Response
BCM
Third Parties
Privacy
Audit
ComplianceTask 5 — Define Control Metadata
Section titled “Task 5 — Define Control Metadata”For every control document:
ID
Name
Objective
Description
Owner
Operator
Scope
Frequency
Type
Automation
EvidenceTask 6 — Map Risks to Controls
Section titled “Task 6 — Map Risks to Controls”Map at least:
20 EnterpriseRisksto applicable controls.
Task 7 — Map Policies to Controls
Section titled “Task 7 — Map Policies to Controls”Connect controls to:
Policies
Standards
ProceduresTask 8 — Build Framework Mapping
Section titled “Task 8 — Build Framework Mapping”Map the common controls to:
ISO 27001
SOC 2
PCI DSS
ISO 27017
ISO 27018
NIST CSFusing applicable official requirements.
Task 9 — Identify Mapping Strength
Section titled “Task 9 — Identify Mapping Strength”Classify mappings as:
Primary
Supporting
PartialTask 10 — Build Evidence Matrix
Section titled “Task 10 — Build Evidence Matrix”Identify at least:
50 EvidenceArtifactsand map them to enterprise controls.
Task 11 — Build Testing Procedures
Section titled “Task 11 — Build Testing Procedures”Create reusable testing procedures for at least:
20 KeyControlsTask 12 — Identify Dependencies
Section titled “Task 12 — Identify Dependencies”Identify at least:
15 ControlDependenciesTask 13 — Identify Key Controls
Section titled “Task 13 — Identify Key Controls”Determine which controls have the greatest:
Risk Impact
Framework Impact
Business ImpactTask 14 — Identify Gaps
Section titled “Task 14 — Identify Gaps”Identify:
Unmapped Requirements
Missing Controls
Weak Controls
Missing Evidence
Failed ControlsTask 15 — Create Dashboard
Section titled “Task 15 — Create Dashboard”Report:
Framework Coverage
Control Effectiveness
Evidence Readiness
Control Deficiencies
Exceptions
RemediationFinal Validation Checklist
Section titled “Final Validation Checklist”Frameworks
Section titled “Frameworks”-
applicable frameworks identified.
-
framework versions recorded.
-
scopes defined.
-
owners assigned.
-
assessment requirements identified.
Requirements
Section titled “Requirements”-
requirements inventoried.
-
applicability determined.
-
internal summaries created.
-
mappings established.
-
unmapped requirements identified.
Controls
Section titled “Controls”-
control taxonomy established.
-
control IDs standardized.
-
objectives defined.
-
descriptions defined.
-
owners assigned.
-
operators identified.
-
frequencies defined.
-
control types classified.
-
automation status recorded.
Risk Integration
Section titled “Risk Integration”-
risks mapped to controls.
-
key controls identified.
-
control dependencies identified.
-
concentration risks identified.
Framework Mapping
Section titled “Framework Mapping”-
ISO 27001 mapped.
-
SOC 2 mapped.
-
PCI DSS mapped.
-
ISO 27017 mapped.
-
ISO 27018 mapped.
-
NIST CSF mapped.
-
mapping strengths identified.
-
partial coverage identified.
Evidence
Section titled “Evidence”-
evidence requirements identified.
-
evidence IDs assigned.
-
evidence owners assigned.
-
frequencies established.
-
authoritative sources identified.
-
duplicate evidence reduced.
-
evidence quality assessed.
Testing
Section titled “Testing”-
testing procedures defined.
-
design effectiveness assessed.
-
operating effectiveness assessed.
-
exceptions recorded.
-
framework impacts identified.
Governance
Section titled “Governance”-
framework change process defined.
-
control change process defined.
-
mapping reviews established.
-
exception management established.
-
remediation process established.
Continuous Compliance
Section titled “Continuous Compliance”-
control metrics defined.
-
control health model established.
-
automation opportunities identified.
-
continuous monitoring designed.
-
dashboard established.
Expected Project Folder
Section titled “Expected Project Folder”07 Build an Enterprise Compliance Control Matrix│├── 01 Framework Inventory├── 02 Requirement Inventory├── 03 Enterprise Control Taxonomy├── 04 Common Control Library├── 05 Risk-to-Control Matrix├── 06 Policy-to-Control Matrix├── 07 Framework-to-Control Matrix├── 08 Control Ownership Register├── 09 Evidence Mapping Matrix├── 10 Control Testing Matrix├── 11 Control Dependency Register├── 12 Gap & Exception Register├── 13 Compliance Coverage Matrix├── 14 Enterprise Compliance Dashboard├── 15 Control Framework Governance Standard└── 16 Continuous Compliance PlanSuccess Criteria
Section titled “Success Criteria”You successfully complete this project when you can move from:
Enterprise Risk ↓Policy ↓Common Control ↓Implementation ↓Evidence ↓Testing ↓Framework Mapping ↓ISO 27001SOC 2PCI DSSISO 27017ISO 27018NIST CSF ↓Gap ↓Remediation ↓ContinuousAssuranceand confidently answer:
Which FrameworksApply?
Which RequirementsApply?
Which EnterpriseControls Address Them?
Which RisksDo Those ControlsMitigate?
Who OwnsEach Control?
Where Isthe ControlImplemented?
What EvidenceProves It?
How Isthe Control Tested?
Which FrameworksDepend on It?
Where Arethe Coverage Gaps?
Which ControlsAre Ineffective?
What MustBe Remediated?
Can One EvidenceArtifact SupportMultiple Frameworks?Career Connection
Section titled “Career Connection”This project reflects work performed by:
GRC Analysts
Compliance Analysts
GRC Architects
Compliance Architects
Internal Auditors
Security AssuranceProfessionals
Risk Managers
Control Owners
GRC ConsultantsA beginner often sees compliance as:
Framework ↓Requirements ↓ChecklistA professional sees:
Enterprise Risk ↓Common Controls ↓Evidence ↓Testing ↓Multiple FrameworksAnd a mature organization moves toward:
One Risk Model
One Control Library
One Evidence Model
One Testing Model
Many FrameworksThe key principle is:
Do Not BuildComplianceFramework by Framework.
Build StrongEnterprise Controls
Then MapFrameworksto Them.What’s Next?
Section titled “What’s Next?”➡️ Next: 08 — Build an Enterprise GRC Dashboard
You now have:
Enterprise Risks ↓ISMS ↓Framework Assessments ↓Common Controls ↓Evidence ↓Testing ↓Compliance MappingThe next challenge is:
How Do WeTurn All ThisGRC DataInto Decisions?In the next project, you will bring together:
Enterprise Risk
Compliance
Controls
Audit Findings
Exceptions
Third-Party Risk
Remediation
KRIs
KPIsinto a unified:
EnterpriseGRC DashboardYou will learn how to transform hundreds of GRC records into:
ExecutiveRisk Visibility ↓Control Health ↓Compliance Posture ↓Remediation Status ↓Management Decisions➡️ Next: 08 — Build an Enterprise GRC Dashboard