Compliance mapping: cross-standard posture mapping
The compliance mappings feature enables you to evaluate existing compliance postures from one standard to another using catalog files, eliminating the need to generate assessments repeatedly and accelerating cross-framework compliance analysis.
What is compliance mapping
The compliance mappings feature streamlines cross-standard compliance mapping by translating compliance posture between standards using predefined compliance catalog files. This reduces manual effort, improves consistency, and accelerates gap analysis. You can easily see how your current compliance posture aligns with another standard without recreating assessments from scratch.
Use cases
- Converting postures between compliance catalogs existing within Concert.
- Uploading custom mapping files for your organization specific requirements.
- Extending converted postures with additional target controls.
- Accelerating compliance assessments by reusing existing compliance assessments.
Creating a mapped assessment
To create a mapped assessment:
- Navigate to .
- Click Create assessment and choose Create mapped assessment.
- Provide a unique Assessment name and select a Source posture from available postures.
- Select a Target catalog from available catalogs in Concert. If your catalog is not listed or you want to select your custom catalog as per your organizations needs, the click hyperlinkGo to Mapped Catalog under Target catalog. Click Add mapping and upload your custom catalog.
Note: You can also review the list of available target catalogs go to .
- Optionally select any additional controls as per need. You can see all mapped controls related to the selected Target catalog.
- Click Create.
against the posture name. Under Assessment history you can see the reused assessment, validated against new catalog and its corresponding compliance level and compliance score.You can upload more compliance assessment files or create a new one for this posture if needed.
Benefits
- Reduced manual effort: Eliminate repetitive assessment work across standards.
- Improved consistency: Use standardized mapping files for reliable translations.
- Accelerate gap analysis: Quickly identify alignment and gaps between different frameworks.
- Flexibility: Extend beyond predefined mappings with manual control selection.
- Traceability: Maintain clear visibility into mapping sources and versions.
Troubleshooting
If you encounter issues with compliance mappings, refer to the following solutions:
| Problem | Solution |
|---|---|
|
Mapping file upload fails: File format is incorrect or file size exceeds limits |
|
|
Conversion produces incomplete results: Partial mappings or missing control definitions |
|
|
Unexpected control mappings: Mapping file contains incorrect or outdated mappings |
|
|
Cannot initiate conversion: Missing prerequisites or permissions |
|
|
Conversion takes too long to complete: Large posture size or complex mapping file |
|
|
Unresponsive UI: Browser timeout or memory constraints |
|
|
Additional controls cannot be selected: Target catalog not fully loaded or permissions issue |
|
Best Practices
- Validate your mapping files before uploading them using schema validation tools.
- Keep compliance assessment files updated to match latest standard versions.
- Test your compliance mapping conversions with small postures before processing large datasets.
- Maintain backup copies of assessment files and source postures.
or is it just conversion to Soverign Control Framework is possible?