| 1 | Select Frameworks | Identify the frameworks you want to compare. | ISO 27001 + NIST CSF |
| 2 | Define Crosswalk Scope | Decide what you’re comparing. | Access Control |
| 3 | Take Framework A | Start with the first framework’s requirement/control. | ISO 27001 A.5.15 |
| 4 | Find Equivalent in Framework B | Search the second framework for a requirement/control addressing the same objective. | NIST CSF 2.0 — Identity Management, Authentication & Access Control |
| 5 | Compare Objectives | Determine whether they are addressing the same security objective. | Both address controlling authorised access. |
| 6 | Determine Mapping | Classify the relationship. | Full / Partial / No Mapping |
| 7 | Document the Crosswalk | Record both framework references and the relationship. | ISO A.5.15 → NIST CSF PR.AA |
| 8 | Identify Coverage Gaps | Look for requirements covered by one framework but not the other. | ISO may have specific organisational requirements not directly represented in NIST CSF. |
| 9 | Identify Common Controls | Determine whether LondonBuild can use one control to satisfy multiple frameworks. | One access-review control supports ISO + NIST. |
| 10 | Record in Crosswalk Matrix | Put the results into your GRC crosswalk. | Framework A → Framework B → Mapping → Common Control → Gap |