workflow
Framework Adoption & Cross-Mapping
Adopt or refresh a security/compliance framework (for example NIST CSF 2.0, ISO/IEC 27001:2022, or SOC 2) by scoping the target framework, rating the current profile, defining the target profile, crosswalking requirements to existing controls and adjacent frameworks, prioritizing gaps, and maintaining a live mapping table. The workflow instance runs on an Audit item created at the start of each adoption cycle (audit_type: readiness, or compliance) — its scope/period fields carry the assessment boundary and cycle window, and every step document versions against it. No upstream workflow feeds this one; it consumes the organization's own existing inventory: the risk register (Risk items), the control library / RCM (Control items and their Risk links), the in-scope Process inventory, and any prior Audit items for this or adjacent frameworks. Named deliverables: the framework mapping table (the crosswalk), the risk-ranked prioritized gap list, the coverage/gap dashboard, and the versioned adoption package. In scope: profile construction, crosswalk mapping, gap prioritization, and the closure disposition. Out of scope: authoring the policies and designing the new controls the gaps demand — those are handed off downstream to TWO workflows, Policy Lifecycle Management (policy-driven gaps) and Control Design (control-build gaps).
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- compliance-legal
- lineOfDefense
- monitor
Details
- teams
- compliance-legal
- risk-management
- domains
- grc
- standards
- nist-csf-2
- iso-27001
- soc2
- sourceTemplateId
- workflow-library:grc-framework-adoption-cross-mapping
- releaseId
- sha256:a95fb76b46ad21568980b05348c461f854e084a67d9c6a782d73b353291cc888
- canonicalUrl
- https://evidenceflows.com/workflows/all/?w=grc-framework-adoption-cross-mapping
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-GOV-16
- UC-RISK-14
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:a95fb76b46ad21568980b05348c461f854e084a67d9c6a782d73b353291cc888