| 1 | Select Requirement | Take the requirement you’re assessing. | ISO 27001 A.5.15 — Access Control |
| 2 | Read Requirement | Understand exactly what the requirement expects. | Access to information and assets must be controlled. |
| 3 | Identify Control Objective | Define the outcome the control should achieve. | Ensure only authorised people have appropriate access. |
| 4 | Find Existing Controls | Look at LondonBuild’s actual processes, policies and technical measures. | User access approval, MFA, quarterly access reviews, leaver account removal. |
| 5 | Match Control to Requirement | Determine which control addresses the requirement. | Access approval process → A.5.15 |
| 6 | Determine Coverage | Ask whether the control completely or partially satisfies the requirement. | Access approval → Fully covers authorisation aspect. |
| 7 | Identify Multiple Controls | One requirement can be supported by several controls. | Access approval + MFA + access reviews + termination process. |
| 8 | Record the Mapping | Put the relationship into your GRC system/control matrix. | Requirement ID → Control ID → Control Owner → Coverage |
| 9 | Identify Unmapped Areas | Ask: “Is any part of the requirement not covered?” | Requirement requires appropriate access; LondonBuild has approval but no periodic review. |
| 10 | Record Mapping Result | Mark the mapping status. | Fully Mapped / Partially Mapped / Not Mapped |