Map the controls to requirement 

OrderTabWhat you do in real lifeLondonBuild example
1Select RequirementTake the requirement you’re assessing.ISO 27001 A.5.15 — Access Control
2Read RequirementUnderstand exactly what the requirement expects.Access to information and assets must be controlled.
3Identify Control ObjectiveDefine the outcome the control should achieve.Ensure only authorised people have appropriate access.
4Find Existing ControlsLook at LondonBuild’s actual processes, policies and technical measures.User access approval, MFA, quarterly access reviews, leaver account removal.
5Match Control to RequirementDetermine which control addresses the requirement.Access approval process → A.5.15
6Determine CoverageAsk whether the control completely or partially satisfies the requirement.Access approval → Fully covers authorisation aspect.
7Identify Multiple ControlsOne requirement can be supported by several controls.Access approval + MFA + access reviews + termination process.
8Record the MappingPut the relationship into your GRC system/control matrix.Requirement ID → Control ID → Control Owner → Coverage
9Identify Unmapped AreasAsk: “Is any part of the requirement not covered?”Requirement requires appropriate access; LondonBuild has approval but no periodic review.
10Record Mapping ResultMark the mapping status.Fully Mapped / Partially Mapped / Not Mapped

The actual mapping

RequirementControl IDControlCoverageOwner
ISO 27001 A.5.15AC-001User access requires manager approval based on job role and business need.FullIT Manager
ISO 27001 A.5.15AC-002User access is reviewed quarterly.FullIT Manager
ISO 27001 A.5.15AC-003User accounts are disabled when employees leave.Partial/SupportingIT + HR
ISO 27001 A.5.15AC-004MFA is required for Microsoft 365.SupportingIT Manager