Compliance mapping: cross-standard posture mapping

The compliance mappings feature enables you to evaluate existing compliance postures from one standard to another using catalog files, eliminating the need to generate assessments repeatedly and accelerating cross-framework compliance analysis.

What is compliance mapping

The compliance mappings feature streamlines cross-standard compliance mapping by translating compliance posture between standards using predefined compliance catalog files. This reduces manual effort, improves consistency, and accelerates gap analysis. You can easily see how your current compliance posture aligns with another standard without recreating assessments from scratch.

Use cases

Compliance mapping is useful in many ways:
  • Converting postures between compliance catalogs existing within Concert.
    Draft comment:
    or is it just conversion to Soverign Control Framework is possible?
  • Uploading custom mapping files for your organization specific requirements.
  • Extending converted postures with additional target controls.
  • Accelerating compliance assessments by reusing existing compliance assessments.

Creating a mapped assessment

To create a mapped assessment:

  1. Navigate to Dimensions > Compliance > Postures.
  2. Click Create assessment and choose Create mapped assessment.
  3. Provide a unique Assessment name and select a Source posture from available postures.
  4. Select a Target catalog from available catalogs in Concert. If your catalog is not listed or you want to select your custom catalog as per your organizations needs, the click hyperlinkGo to Mapped Catalog under Target catalog. Click Add mapping and upload your custom catalog.
    Note: You can also review the list of available target catalogs go to Compliance > Catalogs > Compliance mappings .
  5. Optionally select any additional controls as per need. You can see all mapped controls related to the selected Target catalog.
  6. Click Create.
You can see the new compliance posture under Postures.
Note: The newly created posture name will be combination of Source posture name and Profile name. For example if selected Posture name is "Test Posture" and selected Profile name is India_Information_Technology_Rules_2011_profile, then newly created posture name will be "Test Posture_India_Information_Technology_Rules_2011_profile".
You can click open the new posture and see it tagged as The new posture will be tagged as Mapped against the posture name. Under Assessment history you can see the reused assessment, validated against new catalog and its corresponding compliance level and compliance score.

You can upload more compliance assessment files or create a new one for this posture if needed.

Benefits

  • Reduced manual effort: Eliminate repetitive assessment work across standards.
  • Improved consistency: Use standardized mapping files for reliable translations.
  • Accelerate gap analysis: Quickly identify alignment and gaps between different frameworks.
  • Flexibility: Extend beyond predefined mappings with manual control selection.
  • Traceability: Maintain clear visibility into mapping sources and versions.

Troubleshooting

If you encounter issues with compliance mappings, refer to the following solutions:

Table 1. Compliance mapping troubleshooting
Problem Solution

Mapping file upload fails: File format is incorrect or file size exceeds limits

  • Verify whether the compliance assessment file is in supported JSON format.
  • Ensure file size does not exceed 20 MB.
  • Validate file structure against mapping file schema.
  • Remove any corrupted or invalid characters from the file.

Conversion produces incomplete results: Partial mappings or missing control definitions

  • Review unmapped controls in the conversion results.
  • Manually select additional target controls to fill gaps.
  • Verify source posture contains all required control data.
  • Check if mapping file covers all source controls.

Unexpected control mappings: Mapping file contains incorrect or outdated mappings

  • Review mapping file content.
  • Upload corrected mapping file if errors are found.
  • Report mapping discrepancies to mapping file maintainer.

Cannot initiate conversion: Missing prerequisites or permissions

  • Verify whether source posture exists and is accessible.
  • Check if you have the right permissions for conversion.
  • Check whether target catalog is uploaded and available for use.
  • Ensure mapping file is properly loaded in Concert.

Conversion takes too long to complete: Large posture size or complex mapping file

  • Check resource availability.
  • Break large postures into smaller segments if possible.
  • Verify mapping file is optimized.
  • Monitor conversion progress and check for errors if any.

Unresponsive UI: Browser timeout or memory constraints

  • Refresh your browser and retry conversion.
  • Clear your browser cache and cookies.
  • Try using a different browser.
  • Check your network connectivity and speed.

Additional controls cannot be selected: Target catalog not fully loaded or permissions issue

  • Check whether you have uploaded target.
  • Check your permissions for accessing the catalog.
  • Try refreshing catalog data in the UI.
  • Upload target catalog again if corrupted.

Best Practices

  • Validate your mapping files before uploading them using schema validation tools.
  • Keep compliance assessment files updated to match latest standard versions.
  • Test your compliance mapping conversions with small postures before processing large datasets.
  • Maintain backup copies of assessment files and source postures.