ISO 27028 control mapping gives security and compliance teams a practical way to describe one control library through multiple lenses. Instead of maintaining separate spreadsheets for ISO 27001, NIS2, DORA and customer questionnaires, organizations can attach consistent attributes, obligations and evidence to each control.

The result is faster due diligence, clearer ownership and less risk of contradictory answers. At publication, ISO/IEC 27028 is a Final Draft International Standard in approval, so teams should use it as informed guidance and verify the final text when released.

Why ISO 27028 control mapping matters

ISO/IEC 27001 establishes ISMS requirements and Annex A reference controls; ISO/IEC 27002 provides implementation guidance and example attributes. NIS2 and DORA express obligations by outcome, risk and sector, while vendor questionnaires often ask binary questions about operational evidence. A direct one-to-one crosswalk therefore creates false equivalence.

Attribute-based mapping separates what a control does from why it exists, which requirement it supports, where it applies, who owns it and how it is proven. One control, such as MFA for privileged access, can support ISO 27001, NIS2 access-control expectations, DORA ICT risk measures and several customer questions without duplicating implementation.

Key components of ISO 27028 control mapping

A canonical control library

Give every control a unique ID, objective, implementation statement, owner, scope and lifecycle status. Keep this internal library framework-neutral, then link it to external requirements.

Mapping attributes and confidence

Record the framework citation, required outcome, control type, confidentiality-integrity-availability impact, cybersecurity function, domain, applicability and mapping strength. Classify relationships as direct, partial or supporting rather than claiming automatic equivalence.

Evidence and assurance

Connect each control to evidence, its system of record, an evidence owner, test frequency, result and expiry date. Distinguish control design from operating effectiveness so an approved policy is not mistaken for proof of execution.

How to implement ISO 27028 control mapping

Normalize requirements before mapping

Break ISO statements, NIS2 measures, DORA obligations and questionnaire prompts into atomic requirements. Split compound questions so every mapped relationship has one testable meaning.

Map many-to-many and document rationale

Link each requirement to one or more controls and each control to all relevant requirements. Record the rationale, scope, gaps, compensating controls, source version and reviewer.

Operationalize reusable answers

Generate response records containing the answer, scope, evidence, exceptions, approval and last review date. Use a GRC platform or governed data model instead of uncontrolled spreadsheets, with change workflows for controls and source requirements.

Common challenges and considerations

Common failures include mapping labels instead of intent, treating certification as proof of every control, ignoring regulatory scope and attaching stale evidence. Version-control NIS2 transposition and DORA technical standards. Apply confidentiality review before sharing diagrams, penetration-test reports or vulnerability details with customers.

Best practices

  • Keep source references and internal interpretations in separate fields.
  • Assign business, control and evidence owners with review dates.
  • Use direct, partial and supporting ratings with independent quality review.
  • Measure requirement coverage, evidence freshness, exceptions and questionnaire response time.

Conclusion

ISO 27028 control mapping turns fragmented compliance work into a governed security knowledge model. Start with critical services and high-volume questionnaires, then expand. The goal is not fewer obligations; it is one defensible implementation and evidence base reused with clear context.

At B2BCyber, we support organizations with cybersecurity, compliance, governance, risk management, cloud security, security architecture, IAM/PAM, and regulatory readiness. If you need delivery support, explore our Security and Compliance Project Delivery. If you need to add cybersecurity skills quickly, see our Cybersecurity Experts on Demand model.

Compliance Checklist

  • A canonical control library is approved, scoped and versioned.
  • Each external requirement is atomic and linked to its source version.
  • Every mapping has a rationale, strength rating, owner and reviewer.
  • Evidence demonstrates both control design and operating effectiveness.
  • Gaps, exceptions, risk owners and remediation dates are tracked.
B2B Cyber Security Team

B2B Cyber Security Team publishes practical cybersecurity insights and guidance covering governance, risk and compliance, risk management, security architecture, cloud security, vulnerability management, threat intelligence, incident response, identity and access management (IAM/PAM), regulatory compliance, and industry best practices. Content is based on hands-on experience supporting organisations across regulated and technology-driven industries.