One control. Every framework it satisfies.
Most governance tooling treats every framework as its own control set: NIS2 in one module, ISO 27001 in another, SOC 2 in a spreadsheet. The same safeguard gets implemented once and then documented three, four, six times — and the documents drift apart.
TruSecure models controls independently of frameworks. A framework is a citation list pointing at controls, not a separate control set. One control — "multi-factor authentication enforced for all privileged access" — carries citations to NIS2 Art. 21(2)(j), DORA's ICT risk chapter, ISO 27001 Annex A, NIST CSF 2.0's Protect function, NIST SP 800-53 IA-2, and SOC 2's security criteria simultaneously. One piece of evidence satisfies all six.
How it works
- Model the control once
Each control has one operational definition — what it means in a running system, not what an annex paragraph says about it.
- Attach the citations
Every framework clause the control satisfies is attached as a citation. The mapping is curated by TruSecure and versioned when frameworks change.
- Let evidence fan out
Evidence collected against the control automatically counts toward every citation on it. Assess once; comply many.
- Absorb new frameworks
When a new regime lands — or a transposition changes — the work is a new citation set on existing controls, not a new control programme.
What a crosswalk looks like
One control card, every framework it satisfies hanging off it — this is the architecture drawn, not asserted:
Six citations. One control. One piece of evidence. That's the architecture, not a slogan.
And the same structure in register form — the view an auditor works from:
| Control | NIS2 | ISO 27001 | DORA |
|---|---|---|---|
| MFA enforced for all privileged access | Art. 21(2)(j) | A.8.5 | Art. 9 |
| Access rights provisioned, reviewed, revoked | Art. 21(2)(i) | A.5.18 | Art. 9 |
| Incident detection and handling | Art. 21(2)(b) | A.5.24 | Art. 17 |
| Supply-chain security policy | Art. 21(2)(d) | A.5.19 | Art. 28 |
Where the citations come from
TruSecure maintains the crosswalk as versioned content: when ISO revises an annex or a member state transposes NIS2 with a national twist, the citation set is updated centrally and the change lands in your control model as a reviewable proposal — not as a gap-analysis project you commission separately.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
