Skip to content
Reference

Control Library and Framework Mapping (Crosswalks), Explained

The short version

A control library is an organization's single, maintained catalogue of its internal controls, each with a description, owner, frequency and evidence, mapped to the risks and requirements it addresses. Framework mapping, often called a crosswalk, records how the requirements of one framework relate to those of another, or to the controls in the library. Mapping lets one tested control provide evidence for several frameworks, such as SOC 2, NIST CSF 2.0 and PCI DSS v4.0.1, but only to the extent the requirements actually match. NIST's mapping guidance distinguishes relationships such as equal, subset, superset and intersecting, and requirements that map to nothing are kept visible as gaps.

A control library is a maintained catalogue of an organization's internal controls, in which each control is recorded once with its objective, description, owner, frequency, type and the evidence it produces, and is linked to the risks it mitigates and the requirements it helps satisfy. Framework mapping is the practice of recording how requirements in one control framework, standard or regulation relate to requirements in another, or to the controls in the library. A document that records these relationships is commonly called a crosswalk.

The two work together. Organizations are often subject to several overlapping frameworks at once, for example a SOC 2 examination for customers, PCI DSS for card data and a regulator's cybersecurity rule. Without a library and mappings, each framework tends to acquire its own list of controls, and the same underlying activity is documented and tested several times.

What a control record contains

FieldContent
Identifier and objectiveA unique ID and the risk or requirement the control exists to address.
DescriptionWhat is done, by whom, how often and with what system, specific enough that a tester can check it.
OwnerThe person accountable for operating the control, usually a first-line role.
Type and naturePreventive or detective; manual, automated or IT-dependent manual.
FrequencyPer event, daily, weekly, monthly, quarterly or annually.
EvidenceThe record the control leaves behind: a log, approval, ticket, reconciliation or report.
MappingsLinks to the risks in the risk register, to the requirements in the regulatory inventory, and to each framework requirement it supports.
Test historyDesign and operating-effectiveness test results, exceptions and related issues.

Common controls

A common control is a control that serves many systems, business units or frameworks at once and is operated centrally. NIST Special Publication 800-37 Revision 2 (the Risk Management Framework) defines a common control as a security or privacy control that is inherited by multiple information systems or programs, and includes a task (P-5) for identifying and documenting them. Typical examples are the policy framework, security awareness training, identity and access management, and incident response. Identifying common controls is usually an early step in building a library, because these controls appear in almost every framework and are frequently documented more than once.

Frameworks commonly mapped

How a crosswalk is built

A crosswalk is built by comparing each requirement in a source document with each potentially related requirement in a target document and recording the relationship. NIST Interagency Report 8477 (February 2024), Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines, describes three styles of mapping that NIST accepts for the OLIR program:

The set theory types make the reliability of a mapping explicit. If a library control is equal to, or a superset of, a framework requirement, testing the control can provide evidence for that requirement. If the control merely intersects with the requirement, part of the requirement is not covered, and the uncovered part needs another control or a documented gap.

Testing once for several frameworks

The practical purpose of a mapped library is that a single test of a control can be cited as evidence for every requirement it maps to. A quarterly access review, for example, may support a SOC 2 criterion on logical access, a CSF 2.0 subcategory on access permissions, and a PCI DSS requirement on reviewing user accounts. Testing it once, with a sample and method that satisfy the strictest of those requirements, avoids three separate tests.

The approach has limits:

Keeping unmapped requirements visible

A crosswalk records coverage, and it also records the absence of coverage. Requirements that map to no control, and requirements whose only mapping is an intersecting one, are the gaps a readiness assessment or gap analysis exists to find. Good practice keeps them as explicit entries, each with an owner and a remediation decision, rather than omitting them from the crosswalk. A crosswalk that shows only the requirements that were matched can make coverage look more complete than it is.

Where control libraries are kept

Small programs keep a control library and crosswalks in spreadsheets. Larger programs typically keep them in GRC software, which links each control to risks, requirements, tests, evidence and issues, and can import published mappings such as NIST's informative references or the AICPA's mapping documents. The quality of the library depends on the precision of the control descriptions and on the maintenance of the mappings, not on the tool.

Primary sources

Common questions

What is a control library?
A control library is an organization's maintained catalogue of its internal controls, each recorded once with its objective, description, owner, frequency, type, evidence and test history, and mapped to the risks it mitigates and the requirements it helps satisfy.
What is a compliance crosswalk?
A crosswalk is a document that records how the requirements of one framework, standard or regulation relate to those of another, or to an organization's controls. NIST IR 8477 (2024) describes concept crosswalks, supportive relationship mappings and set theory relationship mappings.
Can one control satisfy several frameworks?
It can provide evidence for several frameworks when it fully covers each mapped requirement, is tested across the scope each framework requires, and meets the most specific requirement among them. Where a control only partly covers a requirement, the remainder needs another control or is recorded as a gap.
What are common controls?
Common controls are controls operated centrally that serve many systems, programs or frameworks at once, such as the policy framework, security awareness training, and identity and access management. NIST SP 800-37 Revision 2 describes identifying and documenting them.
Does NIST publish mappings for CSF 2.0?
Yes. NIST publishes informative references that map CSF 2.0 subcategories to other documents, available through its Cybersecurity and Privacy Reference Tool and the National Online Informative References (OLIR) Program.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.