PISF Requirement → Control Mapping

PISF Requirement to Control Mapping — Base Version

Every PISF requirement mapped against a comprehensive cyber security control catalog, tiered into Essential / Foundational / Advanced implementation groups — domain-first with an explicit cross-domain allowance, not filtered by matching domain names.

Mapped Controls by PISF Area, split by Implementation Group

Count of accepted (requirement, control) instances per area — the same control mapped against several requirements is counted once per requirement.

Essential Foundational Advanced

Click an area to filter the list below to it.

Cyber Security Domains ↔ PISF Areas

Every PISF Area draws its selected and additional candidates controls from across the Cyber Security Domains.

Cyber Security Domains
PISF Areas ↔ Cyber Security Domains Mapping
PISF Areas

Mapped Controls by PISF Area, split by Implementation Group (Essential, Foundational and Advanced)

Essential Foundational Advanced

Browse each requirement, adjust which controls are Selected vs. Additional Candidates and at what tier, reorder them, then Save. Save persists your edits; "Mark Reviewed" is separate and just finalizes your review of the requirement currently on screen -- use it once you're done deciding on that requirement, whether or not you changed anything. All Controls / PISF Mapping / Mapping by Area always show the original AI-suggested baseline, unaffected by review changes.

Add a control not already listed below (e.g. Other control mapping or Unreferenced Controls)
0 pending changes

Refine the exact control-statement wording your organization will adopt for each selected control, with AI suggestions grounded in your organization's context and documents, then Save.

Organization Profile used for AI suggestions

Context of Organization

Scope of Organization

Documents (policies, regulations, etc.)

    0 statements written