One control. Every framework it satisfies.
Most governance tooling treats every framework as its own control set: NIS2 in one module, ISO 27001 in another, SOC 2 in a spreadsheet. The same safeguard gets implemented once and then documented three, four, six times — and the documents drift apart.
TruSecure models controls independently of frameworks. A framework is a citation list pointing at controls, not a separate control set. One control — "multi-factor authentication enforced for all privileged access" — carries citations to NIS2 Art. 21(2)(j), DORA's ICT risk chapter, ISO 27001 Annex A, NIST CSF 2.0's Protect function, NIST SP 800-53 IA-2, and SOC 2's security criteria simultaneously — and to every other framework that asks the same question. One piece of evidence satisfies them all.
How it works
- Model the control once
Each control has one operational definition — what it means in a running system, not what an annex paragraph says about it.
- Attach the citations
Every framework clause the control satisfies is attached as a citation. The mapping is curated by TruSecure and versioned when frameworks change.
- Let evidence fan out
Evidence collected against the control automatically counts toward every citation on it. Assess once; comply many.
- Absorb new frameworks
When a new regime lands — or a transposition changes — the work is a new citation set on existing controls, not a new control program.
What a crosswalk looks like
One control card, every framework it satisfies hanging off it — this is the architecture drawn, not asserted:
One control. One piece of evidence. Every framework citation it satisfies — that's the architecture, not a slogan.
And the same structure in register form — the view an auditor works from:
| Control | NIS2 | ISO 27001 | DORA |
|---|---|---|---|
| MFA enforced for all privileged access | Art. 21(2)(j) | A.8.5 | Art. 9 |
| Access rights provisioned, reviewed, revoked | Art. 21(2)(i) | A.5.18 | Art. 9 |
| Incident detection and handling | Art. 21(2)(b) | A.5.24 | Art. 17 |
| Supply-chain security policy | Art. 21(2)(d) | A.5.19 | Art. 28 |
Where the citations come from
TruSecure maintains the crosswalk as versioned content: when ISO revises an annex or a member state transposes NIS2 with a national twist, the citation set is updated centrally and the change lands in your control model as a reviewable proposal — not as a gap-analysis project you commission separately.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.