Control mapping
Also known as: Cross-walking, Control alignment, Framework mapping
Control mapping is the process of aligning specific internal controls with regulatory requirements, industry standards, or framework objectives. It creates a direct link between what an organization does (the control) and why it does it (the requirement), demonstrating how technical or administrative actions satisfy compliance mandates.
In practice
An auditor typically reviews a "Control Mapping Matrix" to verify that every required safeguard in a framework like ISO 27001 or NIST is addressed by at least one internal policy or technical setting. This prevents gaps in coverage and eliminates the need to test the same control multiple times for different regulations.