Framework Crosswalk
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. Presents the single control set viewed per framework (SOC 2, ISO 27001, GDPR, ISO 42001, and others). It supports framework-specific questionnaire responses and identifies requirements with no mapped control.
SCAFFOLD — HAND-MAINTAINED
This page is intended to be generated from the maps_to fields in controls.yml. That file and its loader do not exist yet (see _MIGRATION-PLAN.md step 4), so this page is hand-maintained for now — edit it directly.
How to read
One control may satisfy several requirements, and one requirement may need several controls. These views are lenses over the single Control Register, not separate control lists.
SOC 2 (Trust Services Criteria)
| TSC | Controls | Coverage |
|---|---|---|
| CC6.1 | D4-01, D7-01, D7-02 | 🟠 |
| PI1 (Processing Integrity — STP) | D16-, D17- | 🔴 |
ISO 27001:2022 (Annex A)
To be generated, grouped by Annex A clause.
GDPR / DPDP
To be generated, grouped by article; cross-references Data & Privacy.
ISO 42001 / EU AI Act
To be generated; cross-references AI Governance.
Unmapped requirements
Requirements with no mapped control are listed here automatically as coverage gaps.
Related
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial structure; SOC 2 view seeded. |
Finaisse Internal — Confidential. Not for external distribution.