Frameworks and standards in one register.
Assess a requirement once. Where a mapping set exists, related controls in other frameworks are suggested with the relationship recorded.
How the mapping engine works
Take one requirement. You assess it once against a perimeter: status, score, notes and attached evidence.
The engine then looks through the mapping sets in the library for controls in other frameworks that this one relates to, and surfaces them as suggestions. Today the library includes the NCA ECC to ISO/IEC 27001:2022 mapping set.
Each rule records its relationship (equal, subset, superset, intersecting or related) and a strength score. A requirement that is only partly covered stays partly covered, and what it does not cover stays visible as a gap.
No suggestion is applied silently. A person accepts or rejects it, and who did so and when is on the record. Your auditor will ask, and the answer will be a name and a date.
Assessed once
NCA-ECC-2-2-6
Session management and single sign-on
- ISO/IEC 27001:2022 A.5.15Access controlintersecting
- ISO/IEC 27001:2022 A.8.5Secure authenticationrelated
NCA ECC control 2-2-6, on session management and single sign-on, is assessed once. The mapping set included in the platform suggests two ISO/IEC 27001:2022 controls: A.5.15 Access control, recorded as intersecting, and A.8.5 Secure authentication, recorded as related. A person accepts or rejects each suggestion.
The library
For each framework, the table shows the issuing body, the supported version and availability: included in the platform, available as an add-on pack, or planned.
Showing 24 of 24 entries
| Name | Code | Publisher | Version | Availability |
|---|---|---|---|---|
| Oman | ||||
| Cyber Security and Resilience Framework | CBO CS&RF | Central Bank of Oman | 2023 | Included in the platform |
| FSA Oman, Information Security | FSA IS | Financial Services Authority, Oman | To be confirmed | Planned |
| FSA Oman, Corporate Governance | FSA CG | Financial Services Authority, Oman | To be confirmed | Planned |
| FSA Oman, Anti-money laundering | FSA AML/CFT | Financial Services Authority, Oman | To be confirmed | Planned |
| FSA Oman, Capital Market | FSA CM | Financial Services Authority, Oman | To be confirmed | Planned |
| FSA Oman, Insurance | FSA INS | Financial Services Authority, Oman | To be confirmed | Planned |
| Personal Data Protection Law | Oman PDPL | Sultanate of Oman | Royal Decree 6/2022 | Planned |
| Saudi Arabia | ||||
| Essential Cybersecurity Controls | NCA ECC | National Cybersecurity Authority, Saudi Arabia | ECC-1:2018 | Included in the platform |
| Cyber Security Framework | SAMA CSF | Saudi Central Bank | To be confirmed | Planned |
| International | ||||
| Information security management systems | ISO/IEC 27001 | ISO/IEC | 2022 | Included in the platform |
| Information security controls | ISO/IEC 27002 | ISO/IEC | 2022 | Included in the platform |
| Adversary tactics and techniques library | MITRE ATT&CK | MITRE | To be confirmed | Planned |
| Payment Card Industry Data Security Standard | PCI DSS | PCI Security Standards Council | 4.0 | Planned |
| Governance and management of enterprise IT | COBIT | ISACA | 2019 | Planned |
| Industrial automation and control systems security | IEC 62443-3-3 | IEC | 3-3 | Planned |
| Business continuity management systems | ISO 22301 | ISO | 2019 | Planned |
| Privacy information management | ISO 27701 | ISO/IEC | 2019 | Planned |
| Risk management guidelines | ISO 31000 | ISO | 2018 | Planned |
| European Union | ||||
| General Data Protection Regulation | GDPR | European Union | 2016/679 | Planned |
| Consumer IoT cyber security | ETSI EN 303 645 | ETSI | v2.1.1 | Planned |
| United States | ||||
| Cybersecurity Framework | NIST CSF | NIST, United States | 2.0 | Planned |
| Operational technology security guide | NIST SP 800-82 | NIST, United States | r3 | Planned |
| Health Insurance Portability and Accountability Act | HIPAA | HHS, United States | To be confirmed | Planned |
| Trust Services Criteria | SOC 2 | AICPA | TSC 2017 | Planned |
Nothing matches those filters.
Regulator reference
- NCA ECCEssential Cybersecurity ControlsNational Cybersecurity Authority, Saudi Arabia
- CBO CS&RFCyber Security and Resilience FrameworkCentral Bank of Oman
- ISO/IEC 27001Information security management systemsISO/IEC
- NIST CSFCybersecurity FrameworkNIST, United States
- Oman PDPLPersonal Data Protection LawSultanate of Oman
Framework upgrades
Frameworks in TrustPoint are versioned. When a standard revises, you do not lose the work you did against the previous edition.
A guided upgrade carries your existing assessments forward onto the new version and previews what was renamed, merged, split, introduced or retired, with a 24-hour rollback.
In practice that is the difference between reviewing a delta and running a reassessment project.
Content packs
Frameworks, reference controls, mapping sets, policy templates, evidence templates and incident playbooks are delivered through the Marketplace as Ed25519-signed, versioned content packs.
Connected sites sync them automatically each day. Air-gapped sites install the same signed pack by manual upload, and the signature is what makes that path safe rather than a hole in it.
See it on the frameworks you actually run.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.