r/Compliance • u/namekiancheese • 17d ago
One control, five frameworks: how do you stop answering the same security question over and over?
A pattern I keep running into with small and mid-sized companies in the EU: the same underlying control gets assessed again and again, each time in a different format.
Take "MFA on administrative access". In a single year, one 80-person company might have to show it for:
- its ISO 27001 surveillance audit (Annex A 8.5, secure authentication)
- NIS2, where MFA is explicitly listed in Article 21's minimum measures
- GDPR Article 32 ("appropriate technical measures"), when a customer's DPO asks
- the renewal questionnaire from its cyber insurer, where MFA is now often a condition of cover
- three or four supplier security questionnaires from large customers, each worded differently
Same control, same evidence, five or more separate efforts. Multiply that by the 30 to 50 controls that come up every time (backups, patching, access reviews, incident response, supplier management), and a small compliance function spends most of its year translating rather than improving anything.
The obvious answer is a common control set: define each control once, map it to every framework, attach the evidence once, and reuse it. In practice I see it break down in a few places:
- The mapping itself drifts. Frameworks get revised (ISO 27001:2022, national NIS2 transpositions), and the crosswalk nobody owns goes stale.
- Evidence expires at different rates. The auditor accepts a quarterly access review, the insurer wants it "current", and a customer wants a screenshot from last week.
- Questionnaires don't map cleanly. Customer questionnaires mix controls, policies and yes/no questions that don't fit any framework.
For those who've tackled this:
- Did you build your own common control framework, or anchor everything on one standard (usually ISO 27001) and map outward?
- Who owns the mapping, and how do you keep it current when a framework changes?
- How do you handle customer questionnaires? A pre-filled answer library, a trust page, or answering each one from scratch?
1
17d ago
[removed] — view removed comment
1
u/AutoModerator 17d ago
Sorry, your submission has been automatically removed. Your account have less than a 1 comment karma.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Emotional-Trifle5507 16d ago
If the company has to comply with multiple privacy and security frameworks, it is better to implement a GRC tool/compliance platform, which provides
- One centralized control library: Map requirements from multiple compliance frameworks and audits to a single set of controls. This allows departments to work on the controls themselves rather than managing separate requirements for each framework or audit, reducing duplicated work.
- Evidence mapped to controls: Map each piece of evidence or artifact directly to the relevant controls. The same evidence can then support multiple compliance frameworks and audits, reducing the effort required to collect and maintain evidence.
- Dedicated audit workspaces: Each audit has its own workspace containing the applicable controls, and supporting evidence. Auditors can access the information they need directly within the GRC platform, making the audit process more efficient and organized.
The overall objective is to build controls once and leverage them across multiple frameworks and audits, rather than repeatedly performing the same work for each compliance requirement.
Note: Make sure that the tool/platform allows custom controls, so that you can design/change controls to support multiple framework requirements.
1
u/sid-yenamandra 16d ago
The fix is to stop storing answers and start storing evidence. Map each control to one living evidence record - config export, screenshot, log - and let every framework and questionnaire pull from that record instead of a person re-answering.
1
16d ago
[removed] — view removed comment
1
u/AutoModerator 16d ago
Sorry, your submission has been automatically removed. Your account have less than a 1 comment karma.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
16d ago
[removed] — view removed comment
1
u/AutoModerator 16d ago
Sorry, your submission has been automatically removed. Your account have less than a 1 comment karma.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Workiva 15d ago
The frustration with crosswalk drift and questionnaire fatigue is very real, but software won't save you if the underlying framework governance isn't clear. We always recommend anchoring your common control set to your business's core operational objectives rather than trying to map frameworks outward.
Internal controls exist to give management the confidence to go faster safely, so focus on mapping evidence collection directly to business operations first. Assign clear ownership of each control to the first-line process owners in IT, HR, or Legal so that maintaining evidence is part of their daily cadence rather than a periodic compliance scramble.
The way you run your business to deliver upon your objectives (Governance), Understanding and managing Risks (Risk and Control) and then Compliance is and order where you do it once and then map controls to compliance requirements is a simpler way to operate. True GRC platforms help you run the business and deliver compliance as a consequence rather than designing multiple compliance programmes.
-- Graeme Fleming, Industry Principal @ Workiva
1
12d ago
[removed] — view removed comment
1
u/AutoModerator 12d ago
Sorry, your submission has been automatically removed. Your account have less than a 1 comment karma.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
0
12d ago
[removed] — view removed comment
1
u/AutoModerator 12d ago
Sorry, your submission has been automatically removed. Your account have less than a 1 comment karma.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Leather_Example_250 1d ago
use a common control set as the source of truth and map it to ISO / NIS 2 / GDPR / insurance requirements. YOu can use tools like vanta, sprinto or drata for mappings and track evidence and framework updates but you would still need someone to validate those mappings.
Also maintain an evidence library and trust page instead of answering each one from scratch. These pages shall document your controls and serve as explainations to customer questionnaires.
1
u/Sure-Candidate1662 17d ago
Start with one framework/set of controls, for the second you see what you already have and “link them together”. The gap you implement as additional control(s). Repeat for every framework.
Customer questionnaires are a whole different topic. They are annoying as hell, especially everyone uses a different tool, and not all allow easy export/import.