Assessment Tools
Policy & Control Mapper
Compare how core control areas map across ISO 27001, NIST CSF, CIS Controls, and GDPR. This is intended to support programme design, audit preparation, and policy rationalisation rather than checkbox compliance theatre.
| Control Area | ISO 27001 | NIST CSF | CIS Controls | GDPR | Coverage |
|---|---|---|---|---|---|
| Access Control | A.9 | PR.AC | CIS 5, 6 | Art. 32 | full |
| Incident Response | A.16 | RS.RP | CIS 17 | Art. 33, 34 | full |
| Risk Assessment | A.8 | ID.RA | CIS 3 | Art. 35 | full |
| Encryption | A.10 | PR.DS | CIS 3 | Art. 32 | full |
| Logging & Monitoring | A.12 | DE.CM | CIS 8 | Art. 30 | full |
| Physical Security | A.11 | PR.AC-2 | CIS 3 | Art. 32(1) | partial |
| Asset Management | A.8 | ID.AM | CIS 1, 2 | Art. 30 | full |
| Supplier Security | A.15 | ID.SC | CIS 15 | Art. 28 | full |
| Business Continuity | A.17 | RC.RP | CIS 11 | Art. 32(1)(c) | partial |
| Vulnerability Management | A.12 | ID.RA | CIS 7 | Art. 32 | full |
| Patch Management | A.12.6 | PR.IP-12 | CIS 7 | Art. 32 | full |
| Security Awareness Training | A.7 | PR.AT | CIS 14 | Art. 32(4) | full |
| Network Security | A.13 | PR.AC-5 | CIS 12, 13 | Art. 32 | full |
| Backup & Recovery | A.12.3 | PR.IP-4 | CIS 11 | Art. 32(1)(c) | partial |
| Change Management | A.12.1 | PR.IP-3 | CIS 4 | Art. 25 | partial |
| Identity Management | A.9.2 | PR.AC-1 | CIS 5 | Art. 32 | full |
| Data Classification | A.8.2 | ID.AM-5 | CIS 3 | Art. 30, 32 | full |
| Privacy by Design | A.18 | ID.GV | CIS 3 | Art. 25 | partial |
| Cryptographic Key Management | A.10.1 | PR.DS-2 | CIS 3 | Art. 32 | full |
| Secure Development | A.14 | PR.IP-2 | CIS 16 | Art. 25, 32 | full |


