Expertise / Frameworks and regulations
Many frameworks. One program.
We cover the frameworks and regulations that matter to your business, and map them into a single program so one set of controls satisfies many requirements.
Frameworks support the story; they don’t define us.
A framework is a set of requirements, not a strategy. Led by requirements alone, you get duplicated controls and repeated evidence work; led by a program, you get one common control framework that many audits can draw on.
Frameworks and regulations we work with.
We work across the major security and privacy frameworks.
SOC 2
Trust services criteria.
ISO/IEC 27001
Information security management.
HITRUST
Healthcare assurance.
NIST
CSF / 800-53 / 800-171.
CMMC
Defense supply chain.
HIPAA
Protected health information.
GDPR and privacy regulations
Data protection obligations.
One program at the core; many frameworks around it.
The payoff of a coordination-first approach is a single operating model at the center, with your applicable frameworks arranged around it. The same governance, risk, and control work satisfies each one, instead of running a separate project per framework. The matrix below shows how that plays out control by control.
A single program core, described as one common control framework, sits at the center. Arranged around it are the frameworks it satisfies: SOC 2, ISO/IEC 27001, NIST, HITRUST, CMMC, HIPAA, and GDPR and other privacy regulations. The same control and evidence work feeds every framework, so requirements are met once as one program rather than rebuilt separately for each.
One GRC program (a common control framework)
- SOC 2
- ISO/IEC 27001
- NIST
- HITRUST
- CMMC
- HIPAA
- GDPR and privacy regulations
Map once, satisfy many.
A common control framework maps a single control set across your applicable frameworks, cutting duplicate controls, evidence requests, and reporting. It is the engine behind covering several requirements as one program, built in Build and Implement and kept current in Managed GRC.
A coverage matrix. Rows are shared controls; columns are frameworks (SOC 2, ISO 27001, NIST CSF, HIPAA). A filled cell means the control contributes to that framework’s requirements. Access control, risk assessment, and incident response each map across multiple frameworks; the HIPAA-specific safeguard maps to HIPAA only.
| Shared control | SOC 2 | ISO 27001 | NIST CSF | HIPAA |
|---|---|---|---|---|
| Access control | Covered by SOC 2 | Covered by ISO 27001 | Covered by NIST CSF | Covered by HIPAA |
| Risk assessment | Covered by SOC 2 | Covered by ISO 27001 | Covered by NIST CSF | Covered by HIPAA |
| Incident response | Covered by SOC 2 | Covered by ISO 27001 | Covered by NIST CSF | Covered by HIPAA |
| Vendor / third-party risk | Covered by SOC 2 | Covered by ISO 27001 | Covered by NIST CSF | Not directly covered by HIPAA |
| PHI safeguards | Not directly covered by SOC 2 | Not directly covered by ISO 27001 | Not directly covered by NIST CSF | Covered by HIPAA |
Start with the program, not the framework.
Talk with a senior advisor about the decisions, ownership, and operating capability your organization needs next.
A conversation with a senior practitioner, not a sales gatekeeper.