ISO 27001 to NIST 800-53 Crosswalk for Jira

A Jira Cloud app that turns the 93 ISO/IEC 27001:2022 Annex A requirements into issues, each listing the NIST SP 800-53 Rev 5 controls it evidences. Holding ISO/IEC 27001:2022 evidences 163 of 1,014 NIST SP 800-53 Rev 5 controls (16.1%); 85 of the 93 requirements carry at least one claim, 186 claims in all.

How to use it

  1. Install the app from the Atlassian Marketplace into your Jira Cloud site.
  2. Open any project you can edit and choose "ISO 27001 to NIST 800-53 Crosswalk" in the project tabs (in newer Jira layouts it sits under More).
  3. Read the pair summary, then press "Create issues". The app creates one issue per Annex A requirement, 20 at a time, and shows progress. Running it again skips the issues it already created.
  4. Open any created issue. The description lists the NIST SP 800-53 Rev 5 controls that requirement evidences, the reasoning for each, the date it was judged, and where the claims and rejections are published. The "Crosswalk evidence" panel shows the same for that issue.

How the mappings were made

A mapping is a judgement, not text printed in either standard. For this pair 536 candidate mappings were examined and 342 removed in review; each high-confidence claim that remains was argued against before it was kept, and carries its reasoning and the date it was judged. The requirement texts were checked against the published ISO/IEC 27001:2022 and NIST SP 800-53 Rev 5 (release 5.2.0).

Every claim and every rejected mapping for the pair is public on the audit trail, so you can check any of them before relying on it. Eight requirements evidence no 800-53 control, and their issues say so: evidence for them does not carry over.

What the app stores and sends

Support

Email support@theartofservice.com or see contact. Privacy: privacy policy. Terms: terms.