r/ISO27001

Open-sourced the control-to-clause crosswalk mappings I kept rebuilding by hand
▲ 9 r/ISO27001+2 crossposts

Open-sourced the control-to-clause crosswalk mappings I kept rebuilding by hand

I got tired of rebuilding the same compliance crosswalk every time somebody added another framework. We’d finish SOC 2, then they’d want to add a HIPAA rider or something else.

I cleaned up the mapping layer I’d been using and put it out there for anybody to use open-source:

https://github.com/Keel-GRC/compliance-crosswalks

It includes 42 framework-agnostic controls mapped across ISO 27001, SOC 2, NIST CSF, PCI DSS, HIPAA, ISO 9001, NIST 800-171, CIS Controls, GDPR, and ESG. There’s a JSON version and a plain CSV, so you can script against it or just open it in Excel.

Part of the reason I wanted to publish it is that a lot of SMBs are starting their compliance journey without a huge budget to throw at one of the big platforms. Sometimes you just need a solid starting point and a spreadsheet that doesn’t suck.

It’s CC BY 4.0. No copyrighted framework text, just clause references and mappings.

Full disclosure: I’m building a GRC platform (DM me if interested in participating as a pilot), and this is the same mapping data behind it. Still, I’d rather make it useful to people than keep it locked behind a login.

If you think a mapping is off or want another framework added, open an issue or let me know. I’d rather have folks poke holes in it than keep reinventing the same spreadsheet in private. I plan to maintain the crosswalk data as I deep-dive into other frameworks, and as they evolve with new versions.

u/getbrock — 1 day ago

How do you handle the overlap between NIS2, GDPR and ISO 27001?

Many Swedish organisations currently need to work with several sets of requirements at the same time. It's easy to end up creating a separate project, a separate checklist and new governance documents for each regulation.

At the same time, many areas overlap, for example risk management, incident management, supplier governance, accountability and documentation.

One alternative is to first establish a common control structure, and then map each requirement to existing processes, controls and responsibilities.

How do you work with this? Do you have a shared governance model, or do you handle each regulation separately? Which parts have been hardest to align?

reddit.com
u/KristenssonAB — 3 days ago

What is your best practical tip for NIS2, ISO 27001, GDPR or GRC work?

Ahead of the autumn, we're curious to hear practical experiences from organisations working with the Cybersecurity Act (NIS2), ISO 27001, GDPR, GRC or similar requirements.

What has made the biggest difference for you?

Examples:

  • a better current-state assessment,
  • clearer risk ownership,
  • simpler governance documents,
  • stronger management buy-in,
  • external advisory support,
  • technical verification,
  • a clearer CISO/GRC role,
  • better follow-up on remediation actions.

What is your best practical tip?

reddit.com
u/KristenssonAB — 5 days ago
▲ 19 r/ISO27001+1 crossposts

2+ years IT support + ISO 27001 Lead Auditor cert — 6 months job hunting for GRC/IT Audit, no luck. Resume feedback + advice needed

Background: I have 2+ years of experience as a desktop support/system engineer at BFSI company (insurance), where I did endpoint security compliance monitoring — patch checks, antivirus, DLP, access controls. Not formal audit work, just operational compliance checking.

I completed ISO 27001:2022 Lead Auditor certification (CQI-IRCA) — failed first attempt, passed on resit. Been job hunting for GRC/IT Audit entry-level roles for 6 months now.

Results so far: Getting phone screens regularly, but most fall apart when I explain I don't have direct GRC/audit experience just the technical operations background + cert. Got to a Last round with one company but got rejected struggled on TPRM and SIEM questions, and he also grilled me on why I quit my last job to pursue this transition unemployed.

Genuinely asking:

  1. Is my resume the problem, or is this just how brutal the entry-level GRC market is right now?
  2. Am I positioning my experience wrong on my resume?
  3. Should I stop targeting GRC/Audit titles and look at "Security Analyst" or similar instead?
  4. Anyone who broke in from a similar IT support background what actually worked?

Appreciate any honest feedback, even harsh.

u/Particular-Report-12 — 11 days ago

ISO 27001 control dependencies

Has anyone mapped the dependencies between ISO 27001 controls?

One of the things I've come to appreciate about ISO 27001 is the logical structure behind the controls.

After working with the standard for several years, I've started to see the controls less as individual requirements and more as an interconnected system with dependencies between them.

For example, A.5.9 (Inventory of Information and Other Associated Assets) seems fundamental to many other controls. If you don't have a reliable asset inventory/CMDB, how can you be confident that all relevant systems are included in backup, vulnerability management, monitoring, access reviews, and so on?

There are many similar examples:

A.5.12 Classification → A.5.13 Labelling → A.5.14 Information Transfer

A.5.15 Access Control → A.5.16 Identity Management → A.5.18 Access Rights

A.5.29 Information Security During Disruption → A.5.30 ICT Readiness for Business Continuity

Looking at the standard this way, some controls appear to function as foundation controls, while others depend on them to operate effectively.

Has anyone seen a complete dependency map or hierarchy of ISO 27001:2022 Annex A controls?

I'd be very interested in discussing:

  • Which controls you consider the most fundamental.
  • Whether some controls should be treated as prerequisites for others.
  • How this could be visualized as a dependency graph rather than a flat list of 93 controls.

My hypothesis is that controls such as A.5.2 (Roles and Responsibilities), A.5.9 (Asset Inventory), A.5.16 (Identity Management), and A.8.9 (Configuration Management) would end up among the most central nodes in such a model.

Without a complete overview of systems, and their criticality, it's not possible to do correct access review.

Has anyone explored this before?

reddit.com
u/Jesperuc — 10 days ago

How can I get ISO 20022 certificate as a professional

So, is there any professional certification for iOS 20022 payments system. Such as CEH, CCNA?

reddit.com
u/nxnx0002 — 9 days ago

PASSED!

So I passed the Lead Auditor exam yesterday with a small margin. The questions were much harder than the sample questions I worked with. The test took me every bit of the 3 hours.

reddit.com
u/NotAnyOneYouKnow2019 — 14 days ago

Do I need to take ISO/IEC 27001 Foundation before attempting the Lead Implementer exam, or can I go straight for LI , ( I'm asking about PECB Policy side )

reddit.com
u/Manipulation1337 — 13 days ago