TrustPoint

Frameworks and standards in one register.

Assess a requirement once. Where a mapping set exists, related controls in other frameworks are suggested with the relationship recorded.

How the mapping engine works

Take one requirement. You assess it once against a perimeter: status, score, notes and attached evidence.

The engine then looks through the mapping sets in the library for controls in other frameworks that this one relates to, and surfaces them as suggestions. Today the library includes the NCA ECC to ISO/IEC 27001:2022 mapping set.

Each rule records its relationship (equal, subset, superset, intersecting or related) and a strength score. A requirement that is only partly covered stays partly covered, and what it does not cover stays visible as a gap.

No suggestion is applied silently. A person accepts or rejects it, and who did so and when is on the record. Your auditor will ask, and the answer will be a name and a date.

Assessed once

NCA-ECC-2-2-6

Session management and single sign-on

  • ISO/IEC 27001:2022 A.5.15Access controlintersecting
  • ISO/IEC 27001:2022 A.8.5Secure authenticationrelated
Example rules from the NCA ECC to ISO/IEC 27001:2022 mapping set included in the platform.

NCA ECC control 2-2-6, on session management and single sign-on, is assessed once. The mapping set included in the platform suggests two ISO/IEC 27001:2022 controls: A.5.15 Access control, recorded as intersecting, and A.8.5 Secure authentication, recorded as related. A person accepts or rejects each suggestion.

The library

For each framework, the table shows the issuing body, the supported version and availability: included in the platform, available as an add-on pack, or planned.

Showing 24 of 24 entries

The library
NameCodePublisherVersionAvailability
Oman
Cyber Security and Resilience FrameworkCBO CS&RFCentral Bank of Oman2023Included in the platform
FSA Oman, Information SecurityFSA ISFinancial Services Authority, OmanTo be confirmedPlanned
FSA Oman, Corporate GovernanceFSA CGFinancial Services Authority, OmanTo be confirmedPlanned
FSA Oman, Anti-money launderingFSA AML/CFTFinancial Services Authority, OmanTo be confirmedPlanned
FSA Oman, Capital MarketFSA CMFinancial Services Authority, OmanTo be confirmedPlanned
FSA Oman, InsuranceFSA INSFinancial Services Authority, OmanTo be confirmedPlanned
Personal Data Protection LawOman PDPLSultanate of OmanRoyal Decree 6/2022Planned
Saudi Arabia
Essential Cybersecurity ControlsNCA ECCNational Cybersecurity Authority, Saudi ArabiaECC-1:2018Included in the platform
Cyber Security FrameworkSAMA CSFSaudi Central BankTo be confirmedPlanned
International
Information security management systemsISO/IEC 27001ISO/IEC2022Included in the platform
Information security controlsISO/IEC 27002ISO/IEC2022Included in the platform
Adversary tactics and techniques libraryMITRE ATT&CKMITRETo be confirmedPlanned
Payment Card Industry Data Security StandardPCI DSSPCI Security Standards Council4.0Planned
Governance and management of enterprise ITCOBITISACA2019Planned
Industrial automation and control systems securityIEC 62443-3-3IEC3-3Planned
Business continuity management systemsISO 22301ISO2019Planned
Privacy information managementISO 27701ISO/IEC2019Planned
Risk management guidelinesISO 31000ISO2018Planned
European Union
General Data Protection RegulationGDPREuropean Union2016/679Planned
Consumer IoT cyber securityETSI EN 303 645ETSIv2.1.1Planned
United States
Cybersecurity FrameworkNIST CSFNIST, United States2.0Planned
Operational technology security guideNIST SP 800-82NIST, United Statesr3Planned
Health Insurance Portability and Accountability ActHIPAAHHS, United StatesTo be confirmedPlanned
Trust Services CriteriaSOC 2AICPATSC 2017Planned

Framework upgrades

Frameworks in TrustPoint are versioned. When a standard revises, you do not lose the work you did against the previous edition.

A guided upgrade carries your existing assessments forward onto the new version and previews what was renamed, merged, split, introduced or retired, with a 24-hour rollback.

In practice that is the difference between reviewing a delta and running a reassessment project.

Content packs

Frameworks, reference controls, mapping sets, policy templates, evidence templates and incident playbooks are delivered through the Marketplace as Ed25519-signed, versioned content packs.

Connected sites sync them automatically each day. Air-gapped sites install the same signed pack by manual upload, and the signature is what makes that path safe rather than a hole in it.

See it on the frameworks you actually run.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.