Control mapping template¶
Mapping metadata¶
| Field | Value |
|---|---|
| Source framework and edition | |
| Authoritative source | |
| Jurisdiction and applicability | |
| System or service scope | |
| Mapping owner | |
| Legal/compliance reviewer | |
| Last validated | |
| Next review or trigger |
Traceability matrix¶
| Source ID | Requirement summary | Applicability | Architecture layer/capability | Responsible owner | Implementation evidence | Validation method/evidence | Inherited from | Status | Gap or residual risk |
|---|---|---|---|---|---|---|---|---|---|
| Example | Paraphrase only; link authoritative text | Applicable / Not applicable / Conditional | Planned / Implemented / Verified |
Mapping rules¶
- Preserve identifiers, link to the authoritative source, and follow licensing restrictions for standards text.
- Separate requirement interpretation, implementation, and validation.
- Explain non-applicability and inherited controls.
- Record source versions and reassess after material changes.
- Obtain qualified review before using the mapping in an assurance claim.