{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:e51379b977b1419d54409b8f2234a3bd42b9682c624787f9394a5998866e47f0","slug":"grc-framework-adoption-cross-mapping","url":"/controls/assets/agent_workflow-grc-framework-adoption-cross-mapping-1d384ecc.b0b2962a71049060.json"},"kind":"record","record":{"attributes":{"department":"compliance-legal","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=grc-framework-adoption-cross-mapping","description":"Adopt or refresh a security/compliance framework (for example NIST CSF 2.0, ISO/IEC 27001:2022, or SOC 2) by scoping the target framework, rating the current profile, defining the target profile, crosswalking requirements to existing controls and adjacent frameworks, prioritizing gaps, and maintaining a live mapping table. The workflow instance runs on an Audit item created at the start of each adoption cycle (audit_type: readiness, or compliance) — its scope/period fields carry the assessment boundary and cycle window, and every step document versions against it. No upstream workflow feeds this one; it consumes the organization's own existing inventory: the risk register (Risk items), the control library / RCM (Control items and their Risk links), the in-scope Process inventory, and any prior Audit items for this or adjacent frameworks. Named deliverables: the framework mapping table (the crosswalk), the risk-ranked prioritized gap list, the coverage/gap dashboard, and the versioned adoption package. In scope: profile construction, crosswalk mapping, gap prioritization, and the closure disposition. Out of scope: authoring the policies and designing the new controls the gaps demand — those are handed off downstream to TWO workflows, Policy Lifecycle Management (policy-driven gaps) and Control Design (control-build gaps).","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=grc-framework-adoption-cross-mapping","capabilities":[],"controls":["UC-GOV-16","UC-RISK-14"],"domains":["grc"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:e51379b977b1419d54409b8f2234a3bd42b9682c624787f9394a5998866e47f0","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-framework-adoption-cross-mapping","standards":["nist-csf-2","iso-27001","soc2"],"teams":["compliance-legal","risk-management"]},"id":"wf:G6","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AG6","slug":"grc-framework-adoption-cross-mapping","sourceIds":["nist-800-53","soc2"],"sourceUrl":null,"title":"Framework Adoption & Cross-Mapping","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:100fe01610faae2684f5795798b84e7f9a0ca6283f57cf35610d13f5c34931c5","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-g6-86d7ed66.json","sourceId":"wf:G6","targetDetailPath":"/controls/data/v1/records/uc-uc-gov-16-694834ac.json","targetId":"uc:UC-GOV-16","type":"oversees"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:252c84fd319ea6cb0455c7eb6fc88af12c07dccc1781fb8b5da2d0799803d1f1","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-g6-86d7ed66.json","sourceId":"wf:G6","targetDetailPath":"/controls/data/v1/records/uc-uc-risk-14-a5d6281b.json","targetId":"uc:UC-RISK-14","type":"oversees"}],"schemaVersion":1}
