Framework mapping — NIST CSF → ISO 27001 → SOC 2
Scenario
NimbusStack's biggest US customer is asking for SOC 2 Type II. Their board wants ISO 27001. Their CTO likes NIST CSF because 'it's practical.' Legal doesn't want three overlapping programmes. You need to prove that ONE control set can satisfy all three. Specifically, you're being asked to map these 8 NIST CSF subcategories to ISO 27001 Annex A controls AND to SOC 2 Trust Services Criteria: ID.AM-1, ID.RA-1, PR.AC-1, PR.AC-4, PR.DS-1, DE.CM-1, RS.RP-1, RC.RP-1.
Your role
You are the GRC lead consultant.
Your task
Produce a 3-way mapping table: - Column 1: NIST CSF subcategory (code + description) - Column 2: ISO 27001:2022 Annex A control (code + name) - Column 3: SOC 2 TSC (CC# + criteria) - Column 4: One-line 'shared control test' that would satisfy all three Then: write a 3-sentence CTO memo explaining WHY this saves work, not just paperwork.
Deliverable format: Markdown table with 8 rows + 3-sentence memo
Toolkit
- NIST CSF subcategory codes are stable — look up official mapping guides
- ISO 27001:2022 has 93 Annex A controls in 4 themes (Organisational, People, Physical, Technological)
- SOC 2 CC = Common Criteria (CC1.x through CC9.x)
- Every mapping row should have a control that could be 'tested once, evidenced three times'
Success criteria (what the AI grades against)
- All 8 NIST subcategories correctly identified with descriptions
- ISO 27001:2022 codes are 2022-era (A.5.x, A.8.x — NOT the old A.5.1.1 numbering)
- SOC 2 mapping uses correct CC codes
- Shared control test is concrete (e.g. 'quarterly access review of admin accounts' not 'access management')
- Memo actually addresses control efficiency, not paperwork reduction
Log in to submit your deliverable for AI review.
Log in / Register