Carry out crosswalk

OrderTabWhat you do in real lifeLondonBuild example
1Select FrameworksIdentify the frameworks you want to compare.ISO 27001 + NIST CSF
2Define Crosswalk ScopeDecide what you’re comparing.Access Control
3Take Framework AStart with the first framework’s requirement/control.ISO 27001 A.5.15
4Find Equivalent in Framework BSearch the second framework for a requirement/control addressing the same objective.NIST CSF 2.0 — Identity Management, Authentication & Access Control
5Compare ObjectivesDetermine whether they are addressing the same security objective.Both address controlling authorised access.
6Determine MappingClassify the relationship.Full / Partial / No Mapping
7Document the CrosswalkRecord both framework references and the relationship.ISO A.5.15 → NIST CSF PR.AA
8Identify Coverage GapsLook for requirements covered by one framework but not the other.ISO may have specific organisational requirements not directly represented in NIST CSF.
9Identify Common ControlsDetermine whether LondonBuild can use one control to satisfy multiple frameworks.One access-review control supports ISO + NIST.
10Record in Crosswalk MatrixPut the results into your GRC crosswalk.Framework A → Framework B → Mapping → Common Control → Gap

Example

ISO 27001NIST CSFRelationshipLondonBuild Common Control
A.5.15 Access ControlPR.AA — Identity Management, Authentication, and Access ControlFull/StrongRole-based access + approval
A.5.16 Identity ManagementPR.AAStrongUser identity lifecycle management
A.5.17 Authentication InformationPR.AAStrongMFA/password controls
A.5.18 Access RightsPR.AAStrongQuarterly access reviews
A.6.5 Responsibilities after terminationPR.AAPartial/StrongLeaver account termination