ISO 31000:2018
Process

ISO 31000:2018 6.7: Conducting Audit Follow-up

Follow-up activities verify completion of corrective actions and effectiveness in addressing audit findings.

What else in your programme already covers this

This control maps to 514 controls across 246 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary
  • NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C
  • RG5.71-C.3 Cyber Security Training
  • RG5.71-C.5 Recovery and Restoration
  • RG5.71-C.6 Configuration Management

ISO 27043 · 4 controls

ISO/IEC 27011:2024 · 4 controls

ISO/IEC 27400:2022 · 4 controls

ISO/SAE 21434 · 4 controls

  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management

FedRAMP Rev 5 · 3 controls

  • FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters
  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests

ISO 22320:2018 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

MARS-E · 3 controls

MTCS (Singapore) · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-6 Security Test Specifications, Certification, and Conformance

OWASP ASVS · 3 controls

OWASP MASVS · 3 controls

OWASP Top 10:2025 · 3 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training
  • PICSGMP-5 Chapter 5: Production Operations and Material Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management

PTES · 3 controls

UK Bribery Act 2010 · 3 controls

  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-09 Encryption and key management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

GLBA · 2 controls

HKMA SPM · 2 controls

ISMAP (Japan) · 2 controls

ISO 13485 · 2 controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO 27799 · 2 controls

ISO 56002 · 2 controls

MITRE ATT&CK · 2 controls

MITRE D3FEND · 2 controls

  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NISTSP115-1 Scope, Methodology, and Assessment Planning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 2 controls

  • NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates
  • NISTSP123-8 Governance, Policies, and ISMS Integration

NIST SP 800-137 · 2 controls

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment
  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring

NIST SP 800-144 · 2 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-190 · 2 controls

NIST SP 800-61 · 2 controls

  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing
  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection
  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase

NIST SP 800-92 · 2 controls

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

Open Banking Security · 2 controls

  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 2 controls

  • OSSFSC-1 Branch Protection, Code Review, and Repository Governance
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports

PCI P2PE · 2 controls

PCI PIN Security · 2 controls

PCI SSF · 2 controls

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

SOC 2 · 2 controls

  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication

South Korea ISMS-P · 2 controls

  • VP-2 Holder Binding
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)
  • 4.4.1 Resources, Roles, Responsibility, and Authority

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

  • BE-CF-08 Cryptographic protection of data

COBIT 2019 · 1 control

  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

FDA 21 CFR Part 11 · 1 control

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)

FIDO2 / WebAuthn · 1 control

FISMA · 1 control

  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections

HITECH Act · 1 control

  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor

ISO 19011 · 1 control

  • 6.5 Preparing and Distributing Audit Report

ISO 19011:2018 · 1 control

  • 6.7 Conducting audit follow-up

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO/IEC 27003:2017 · 1 control

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27031:2011 · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NHPA-6 Reasonable Data Security and Breach Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • PSPF24-1 Security Culture, Governance, Risk Management

Qatar DPL · 1 control

  • RCEPEC-1 Online Personal Information Protection (12.13)
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

Saudi Arabia PDPL · 1 control

  • SIGSTORE-3 Sigstore for Containers and Artifacts (Cosign)
  • SCA-S2 Interpretation and Definitions

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data

Turkey KVKK · 1 control

  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

WCAG 2.2 · 1 control

  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Process

Query this from an agent

The graph holds this control, the 514 it maps to, and the evidence behind each claim, over MCP and REST.