Control library and crosswalks
One control set, based on NIST SP 800-53 rev. 5 and organised by the NIST CSF 2.0 functions, with Ansvar-added controls where a framework needs one. Each control maps to requirements in ISO 27001 and 27002, NIS2, DORA, CRA, C5, NIST SP 800-171 and other frameworks. Each mapping says how closely the control and the requirement match, from equivalent to only related, and a person reviews it before it counts.
Plan Team and Company.
Try it
Using Ansvar, crosswalk NIS2 Article 21 to ISO 27001: show the canonical controls in between and which ISO requirements those controls map to, with the review status of each mapping.More examples:
Using Ansvar, get control AC-2 from the control library and list the framework requirements it maps to.Using Ansvar, give me a coverage summary for DORA in the control library, then list the requirements that are only partially covered.What comes back
Your assistant gets control and requirement references with how they relate and whether a person has reviewed the link. The library does not reproduce requirement text; it tells your assistant where to fetch it, under your own plan and add-ons.
For developers, the fields to read:
- Relationship type per mapping: equivalent, subset-of, superset-of, intersects-with, related-to
- Review status per mapping; only approved mappings count by default
- Citation descriptors (source, edition, reference, lookup parameters). For NIS2, DORA and CRA the text comes from the EU regulations corpus; for ISO, from your org standards library or the ISO standards add-on, whichever holds the standard
- Coverage per framework: covered, partially covered with the remaining gap, and unmapped
Which plan
Team and Company. The control library page explains the model behind it.
Tools
list_controlslists controls, filtered by family, function, framework or baseline.get_controlreturns one control and the requirements it maps to.get_requirementslists the framework requirements one control maps to.crosswalkgoes from one framework's requirement to another framework's, through the shared controls.coveragereports how much of a framework the reviewed mappings cover.list_obligationslists the obligations recorded under a framework edition.resolvetells your assistant where to fetch a requirement's text.changesreports each framework's pinned version.
Limits
- Only reviewed mappings count unless you ask for the proposed ones too; coverage then shows them separately.
- A mapping is not proof that a control satisfies a requirement. Subset-of and intersects-with links cover only part of it, and a related-to link states a relationship without claiming any coverage.
- A crosswalk shows the stored links along each path and labels the path as a related link or as needing review. It never derives a cross-framework coverage claim from an indirect path.
- The obligation list includes proposed, approved and declined rows unless you filter for approved ones; proposed rows are marked provisional.
- Mapping coverage describes the library, not your organisation. It does not say you comply.
- An unknown framework, edition or reference returns an error naming the known ones, and an empty crosswalk says why it is empty.
- Change detection between catalogue versions is not built yet; the tool says so rather than returning an empty change list.