{
  "edition": "2026.1",
  "licence": "CC BY 4.0",
  "published": "2026-09-10",
  "notice": "DTCF is published by the Association of Digital Trust Practitioners under CC BY 4.0. Attribution required. Framework references are the property of their publishers.",
  "contributors": [
    {
      "Name": "Association of Digital Trust Practitioners",
      "Role": "author",
      "Organization": null,
      "Statement": "Authors and maintains DTCF. The framework is published free under CC BY 4.0 and is not tied to any product."
    },
    {
      "Name": "A sponsoring contributor",
      "Role": "sponsoring_contributor",
      "Organization": null,
      "Statement": "A sponsoring contributor to the 2026.1 edition contributed mapping research and review. Sponsors do not own or control DTCF; like any vendor they may state conformance to it."
    }
  ],
  "objectives": [
    {
      "Code": "GOV-01",
      "FamilyCode": "GOV",
      "Title": "Accountable owner for digital trust",
      "Statement": "A named individual is accountable for the digital trust programme, with the authority and budget to direct it.",
      "Intent": "Programmes without a name attached become everybody\u0027s intention and nobody\u0027s work.",
      "Evidence": "Appointment record, role description, board or leadership minute naming the owner.",
      "SmeNote": "One founder or manager, named in writing, is enough.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC1.3",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.2",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.RR-02",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "partial",
          "Reference": "12.1.3",
          "Reason": "Scoped to cardholder data responsibilities only."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(2)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 24",
          "Reason": "Accountability sits with the controller as an entity; no named individual is required except where Art. 37 applies."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 26",
          "Reason": "Deployer duties imply an accountable person without naming the role."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 2.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "GRC-201"
        },
        {
          "Kind": "policy_doc_type",
          "Ref": "INFOSEC_POLICY"
        },
        {
          "Kind": "course",
          "Ref": "DTF-101"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    },
    {
      "Code": "GOV-02",
      "FamilyCode": "GOV",
      "Title": "Approved policy set",
      "Statement": "Policies covering the organization\u0027s obligations are approved, dated, owned and reviewed on a stated cycle.",
      "Intent": "An unapproved policy is a draft; an unreviewed one is a claim about the past.",
      "Evidence": "Policy register with owner, approval date, next review; approval record.",
      "SmeNote": "A dozen policies, approved once a year, with the founder as owner.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC5.3",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.1",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.PO-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.316(a)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 24(2)",
          "Reason": "Policies are required only where proportionate."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "The Act imposes system-level obligations and quality management for providers; it does not require an organizational policy set."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 1.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "INFOSEC_POLICY"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-010"
        },
        {
          "Kind": "course",
          "Ref": "GRC-210"
        },
        {
          "Kind": "course",
          "Ref": "GRC-202"
        },
        {
          "Kind": "course",
          "Ref": "GRC-250"
        },
        {
          "Kind": "course",
          "Ref": "AIG-230"
        }
      ]
    },
    {
      "Code": "GOV-03",
      "FamilyCode": "GOV",
      "Title": "Roles and responsibilities defined",
      "Statement": "Security, privacy and compliance responsibilities are assigned and communicated to the people who hold them.",
      "Intent": "People perform duties they know they hold.",
      "Evidence": "Role descriptions, RACI, acknowledgement records.",
      "SmeNote": "A one-page list of who does what, acknowledged by each person.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC1.4",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.3",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.RR-02",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.4",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(3)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32",
          "Reason": "Implied through appropriate measures rather than stated."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 26(2)",
          "Reason": "Human oversight must be assigned to competent persons."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 2.2",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AUD-201"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-010"
        },
        {
          "Kind": "course",
          "Ref": "OPS-220"
        },
        {
          "Kind": "course",
          "Ref": "GRC-260"
        }
      ]
    },
    {
      "Code": "GOV-04",
      "FamilyCode": "GOV",
      "Title": "Code of conduct and ethics affirmation",
      "Statement": "Expected conduct is published and affirmed by staff on joining and annually.",
      "Intent": "Culture is what people affirm and what leadership enforces.",
      "Evidence": "Code of conduct, affirmation records, disciplinary process.",
      "SmeNote": "Signed on joining, re-affirmed each year at review time.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC1.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "partial",
          "Reference": "A.6.2",
          "Reason": "Covered through terms of employment rather than a separate code."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "partial",
          "Reference": "GV.RR-04",
          "Reason": "Addressed through workforce expectations."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "partial",
          "Reference": "12.6",
          "Reason": "Framed as security awareness acknowledgement."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(1)(ii)(C)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "No conduct code obligation; confidentiality of processing staff is required under Art. 28(3)(b) instead."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 4",
          "Reason": "AI literacy duty touches conduct without a code."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 3.2",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "CODE_OF_CONDUCT"
        },
        {
          "Kind": "course",
          "Ref": "DTF-110"
        }
      ]
    },
    {
      "Code": "RSK-01",
      "FamilyCode": "RSK",
      "Title": "Risk assessment performed and repeated",
      "Statement": "Risks to objectives are identified and assessed on a defined cadence and on material change.",
      "Intent": "A one-off assessment describes a company that no longer exists.",
      "Evidence": "Assessment method, dated assessments, register entries.",
      "SmeNote": "One workshop a year plus a re-look after any big change.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC3.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "6.1.2",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "ID.RA-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.3.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(1)(ii)(A)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32(1)",
          "Reason": "Risk to rights and freedoms of individuals, not to the organization."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 9",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MAP 1.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "RSK-201"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-021"
        },
        {
          "Kind": "course",
          "Ref": "PRV-250"
        },
        {
          "Kind": "course",
          "Ref": "RSK-210"
        }
      ]
    },
    {
      "Code": "RSK-02",
      "FamilyCode": "RSK",
      "Title": "Risk register with owners and treatment",
      "Statement": "Risks are recorded with inherent and residual judgement, an owner, a treatment decision and a review date.",
      "Intent": "A register nobody owns is a list.",
      "Evidence": "Risk register, treatment plans, review evidence.",
      "SmeNote": "A spreadsheet reviewed quarterly by the leadership team.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC3.4",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "6.1.3",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "ID.RA-05",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "partial",
          "Reference": "12.3.1",
          "Reason": "Targeted risk analyses only, not an enterprise register."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(1)(ii)(B)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "No register of organizational risk is required; Art. 30 requires a record of processing activities, which is a different artefact."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 9(2)",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MANAGE 1.3",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "OPS-201"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-020"
        },
        {
          "Kind": "course",
          "Ref": "DTF-MICRO"
        },
        {
          "Kind": "course",
          "Ref": "GRC-202"
        },
        {
          "Kind": "course",
          "Ref": "CYB-210"
        },
        {
          "Kind": "course",
          "Ref": "RSK-210"
        },
        {
          "Kind": "course",
          "Ref": "TRS-220"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    },
    {
      "Code": "RSK-03",
      "FamilyCode": "RSK",
      "Title": "Acceptances expire",
      "Statement": "Accepted risks and control exceptions carry an accountable executive, a compensating control and an expiry date.",
      "Intent": "An acceptance without an end date is a decision nobody revisits.",
      "Evidence": "Exception register with expiry and review outcomes.",
      "SmeNote": "The founder accepts in writing and revisits every quarter.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "partial",
          "Reference": "CC3.4",
          "Reason": "Implicit in risk response; expiry is not required."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "partial",
          "Reference": "6.1.3(f)",
          "Reason": "Acceptance is required to be approved, not time-bound."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "partial",
          "Reference": "GV.RM-06",
          "Reason": "Expressed as risk response tracking."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "partial",
          "Reference": "12.3.3",
          "Reason": "Applies to compensating controls, reviewed annually."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "none",
          "Reference": null,
          "Reason": "No exception mechanism is defined; addressable specifications carry their own documented rationale instead."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "No concept of accepting non-compliance."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "No exception mechanism for high-risk obligations."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MANAGE 1.2",
          "Reason": "Risk acceptance is described but not time-bound."
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "RSK-220"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-022"
        }
      ]
    },
    {
      "Code": "RSK-04",
      "FamilyCode": "RSK",
      "Title": "Appetite and indicators",
      "Statement": "Risk appetite is stated in terms someone can measure, with indicators and thresholds that trigger action.",
      "Intent": "Appetite that cannot be measured cannot be exceeded, so it is never discussed.",
      "Evidence": "Appetite statement, KRI definitions, threshold breach records.",
      "SmeNote": "Three indicators leadership actually watches.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "partial",
          "Reference": "CC3.1",
          "Reason": "Objectives and tolerances are required; appetite language is not."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "partial",
          "Reference": "6.1.2(a)",
          "Reason": "Risk criteria including acceptance criteria."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.RM-02",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "none",
          "Reference": null,
          "Reason": "Prescriptive standard; no appetite concept."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "none",
          "Reference": null,
          "Reason": "No appetite concept in the Security Rule."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "Risk is assessed against individuals\u0027 rights, not against an organizational appetite."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 9(5)",
          "Reason": "Residual risk must be judged acceptable."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 1.3",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "RSK-230"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-033"
        },
        {
          "Kind": "course",
          "Ref": "OPS-220"
        },
        {
          "Kind": "course",
          "Ref": "RSK-210"
        }
      ]
    },
    {
      "Code": "OBL-01",
      "FamilyCode": "OBL",
      "Title": "Obligation inventory",
      "Statement": "Legal, regulatory and contractual obligations that apply are identified, owned and kept current.",
      "Intent": "You cannot meet an obligation you have not written down.",
      "Evidence": "Obligation register with source, owner and evidence link.",
      "SmeNote": "One register, reviewed when a contract or law changes.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC2.3",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.31",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.OC-03",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "partial",
          "Reference": "12.1",
          "Reason": "Scoped to PCI DSS obligations."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.316",
          "Reason": "Documentation duty rather than an inventory."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 30",
          "Reason": "Records of processing rather than obligations."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 16",
          "Reason": "Provider obligations are enumerated by the Act itself."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 1.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "DTF-120"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-004"
        },
        {
          "Kind": "course",
          "Ref": "PRV-240"
        },
        {
          "Kind": "course",
          "Ref": "DTF-MICRO"
        },
        {
          "Kind": "course",
          "Ref": "DTF-101"
        },
        {
          "Kind": "course",
          "Ref": "PRV-201"
        },
        {
          "Kind": "course",
          "Ref": "PRV-202"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    },
    {
      "Code": "OBL-02",
      "FamilyCode": "OBL",
      "Title": "Scope decided and documented",
      "Statement": "What is in scope for each framework or certification is decided, justified and recorded, including deliberate exclusions.",
      "Intent": "Undecided scope expands until the team drowns.",
      "Evidence": "Scope statement, exclusion justifications, reopening triggers.",
      "SmeNote": "One product, one cloud, written down in a page.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC1.5",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "4.3",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.OC-04",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.5.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.306(a)",
          "Reason": "Scope follows ePHI wherever it exists."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 3",
          "Reason": "Territorial scope is set by law, not chosen."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 6",
          "Reason": "Scope follows the risk classification of the system."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MAP 1.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AUD-250"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-017"
        },
        {
          "Kind": "course",
          "Ref": "DTF-MICRO"
        },
        {
          "Kind": "course",
          "Ref": "GRC-203"
        },
        {
          "Kind": "course",
          "Ref": "GRC-202"
        },
        {
          "Kind": "course",
          "Ref": "GRC-240"
        },
        {
          "Kind": "course",
          "Ref": "PRV-202"
        },
        {
          "Kind": "course",
          "Ref": "GRC-250"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    },
    {
      "Code": "OBL-03",
      "FamilyCode": "OBL",
      "Title": "Training and awareness",
      "Statement": "People receive role-relevant training on joining and at a defined cadence, and completion is evidenced.",
      "Intent": "Awareness that leaves no record cannot be shown to have happened.",
      "Evidence": "Assignment records, completion evidence, content version.",
      "SmeNote": "Annual awareness plus a short induction module.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC1.4",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.6.3",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.AT-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.6.3",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(5)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 39(1)(b)",
          "Reason": "Awareness raising is a DPO task where a DPO exists."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 4",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 2.2",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "SAT-101"
        },
        {
          "Kind": "course",
          "Ref": "GRC-210"
        },
        {
          "Kind": "course",
          "Ref": "GRC-260"
        },
        {
          "Kind": "course",
          "Ref": "SAT-102"
        },
        {
          "Kind": "course",
          "Ref": "SAT-103"
        },
        {
          "Kind": "course",
          "Ref": "SAT-104"
        },
        {
          "Kind": "course",
          "Ref": "SAT-105"
        },
        {
          "Kind": "course",
          "Ref": "SAT-106"
        },
        {
          "Kind": "course",
          "Ref": "SAT-107"
        },
        {
          "Kind": "course",
          "Ref": "SAT-108"
        },
        {
          "Kind": "course",
          "Ref": "SAT-109"
        },
        {
          "Kind": "course",
          "Ref": "SAT-110"
        }
      ]
    },
    {
      "Code": "DAT-01",
      "FamilyCode": "DAT",
      "Title": "Data inventory and classification",
      "Statement": "Data held is inventoried, classified and assigned an owner.",
      "Intent": "Everything downstream depends on knowing what you hold.",
      "Evidence": "Data map, classification scheme, owner assignment.",
      "SmeNote": "A single sheet listing systems, data types and owners.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.9",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "ID.AM-07",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.5.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.310(d)(2)",
          "Reason": "Media and device accountability rather than a data map."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 30",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 10",
          "Reason": "Data governance applies to training and testing data."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MAP 2.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "DGV-210"
        },
        {
          "Kind": "course",
          "Ref": "DGV-220"
        },
        {
          "Kind": "course",
          "Ref": "GRC-240"
        },
        {
          "Kind": "course",
          "Ref": "PRV-220"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    },
    {
      "Code": "DAT-02",
      "FamilyCode": "DAT",
      "Title": "Lawful, minimised processing",
      "Statement": "Personal data is processed on a stated basis, limited to what is needed and kept only as long as needed.",
      "Intent": "Minimisation is the cheapest control there is.",
      "Evidence": "Processing records, retention schedule, deletion evidence.",
      "SmeNote": "A retention line per data type, applied on a calendar.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "partial",
          "Reference": "P4.0",
          "Reason": "Only when privacy criteria are in scope."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "partial",
          "Reference": "A.5.34",
          "Reason": "Privacy of PII is required; lawful basis is not."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "partial",
          "Reference": "GV.OC-03",
          "Reason": "Through legal requirements."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "3.2.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.502(b)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 5, 6",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 10(5)",
          "Reason": "Special category processing for bias detection."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MAP 4.1",
          "Reason": "Privacy risk mapping."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "DATA_PRIVACY"
        },
        {
          "Kind": "policy_doc_type",
          "Ref": "DATA_RETENTION"
        },
        {
          "Kind": "course",
          "Ref": "PRV-240"
        },
        {
          "Kind": "course",
          "Ref": "DTF-MICRO"
        },
        {
          "Kind": "course",
          "Ref": "PRV-201"
        },
        {
          "Kind": "course",
          "Ref": "PRV-210"
        },
        {
          "Kind": "course",
          "Ref": "PRV-202"
        },
        {
          "Kind": "course",
          "Ref": "PRV-250"
        },
        {
          "Kind": "course",
          "Ref": "PRV-270"
        },
        {
          "Kind": "course",
          "Ref": "PRV-220"
        },
        {
          "Kind": "course",
          "Ref": "PRV-230"
        },
        {
          "Kind": "course",
          "Ref": "PRV-203"
        },
        {
          "Kind": "course",
          "Ref": "PRV-280"
        },
        {
          "Kind": "course",
          "Ref": "SAT-109"
        }
      ]
    },
    {
      "Code": "DAT-03",
      "FamilyCode": "DAT",
      "Title": "Deliberate data sharing",
      "Statement": "Data leaves the organization only through a decided channel, with a defined end and a record of what was shared.",
      "Intent": "Most exposure is not a breach; it is sharing nobody ended.",
      "Evidence": "Sharing decision records, data room logs, revocation evidence.",
      "SmeNote": "A record per share, and a close-out when it ends.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.7",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.14",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.DS-02",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "4.2.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(b)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 28, 44",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "No general data sharing duty; obligations attach to the AI system and its documentation."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MAP 4.1",
          "Reason": "Third-party data flows are mapped."
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "DGV-230"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-001"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-002"
        },
        {
          "Kind": "course",
          "Ref": "DTF-MICRO"
        },
        {
          "Kind": "course",
          "Ref": "PRV-230"
        },
        {
          "Kind": "course",
          "Ref": "PRV-280"
        },
        {
          "Kind": "course",
          "Ref": "SAT-103"
        },
        {
          "Kind": "course",
          "Ref": "SAT-110"
        }
      ]
    },
    {
      "Code": "DAT-04",
      "FamilyCode": "DAT",
      "Title": "Complete disposal",
      "Statement": "Data is removed from primary systems, backups, caches, exports and third parties when it is no longer needed or on request.",
      "Intent": "Deletion that stops at the database is not deletion.",
      "Evidence": "Disposal procedure, backup expiry evidence, third-party confirmations.",
      "SmeNote": "Know your backup horizon and state it honestly.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.5",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.10",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.DS-03",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "3.2.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.310(d)(2)(i)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 17",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "No disposal obligation; record-keeping durations are specified instead."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "none",
          "Reference": null,
          "Reason": "Out of scope: the framework addresses AI risk, not data lifecycle disposal."
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "DGV-230"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-003"
        },
        {
          "Kind": "course",
          "Ref": "PRV-210"
        },
        {
          "Kind": "course",
          "Ref": "PRV-270"
        },
        {
          "Kind": "course",
          "Ref": "SAT-108"
        }
      ]
    },
    {
      "Code": "ACC-01",
      "FamilyCode": "ACC",
      "Title": "Joiners, movers, leavers",
      "Statement": "Access is provisioned on a documented request, changed when a role changes and removed promptly on departure.",
      "Intent": "Most access findings are movers nobody re-baselined.",
      "Evidence": "Provisioning records, termination checklist, timing evidence.",
      "SmeNote": "A checklist run the same day someone leaves.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.18",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.AA-05",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "8.2.4",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(3)(ii)(C)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32",
          "Reason": "Through appropriate access measures."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed; access control is left to sectoral and general law."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MANAGE 2.2",
          "Reason": "Access to AI systems within risk treatment."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "ACCESS_CONTROL"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-003"
        },
        {
          "Kind": "course",
          "Ref": "GRC-230"
        }
      ]
    },
    {
      "Code": "ACC-02",
      "FamilyCode": "ACC",
      "Title": "Access reviewed on a cadence",
      "Statement": "Entitlements are reviewed by someone who can judge them, with revocations tracked to completion.",
      "Intent": "A review that produces no revocations was not a review.",
      "Evidence": "Review packs, reviewer decisions, revocation evidence, completeness statement.",
      "SmeNote": "Quarterly, one reviewer per system, evidence kept.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.3",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.18",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.AA-05",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "7.2.4",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(4)(ii)(C)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32",
          "Reason": "Implied by appropriate measures."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed at control level."
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "CYB-240"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-018"
        },
        {
          "Kind": "course",
          "Ref": "GRC-230"
        }
      ]
    },
    {
      "Code": "ACC-03",
      "FamilyCode": "ACC",
      "Title": "Strong authentication",
      "Statement": "Authentication is proportionate to risk, with multi-factor authentication on administrative and remote access.",
      "Intent": "Credential theft remains the most common entry point.",
      "Evidence": "Authentication configuration, MFA coverage report, exceptions.",
      "SmeNote": "MFA on everything that matters, with no shared logins.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.5",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.AA-03",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "8.4",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.312(d)",
          "Reason": "Person or entity authentication without specifying factors."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32",
          "Reason": "Through appropriate measures."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed at control level."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "PASSWORD_POLICY"
        },
        {
          "Kind": "course",
          "Ref": "SAT-102"
        },
        {
          "Kind": "course",
          "Ref": "CYB-250"
        }
      ]
    },
    {
      "Code": "ACC-04",
      "FamilyCode": "ACC",
      "Title": "Privileged access controlled",
      "Statement": "Administrative access is limited, separately approved, monitored and time-bound where possible.",
      "Intent": "Standing administrative access is the largest single blast radius.",
      "Evidence": "Privileged account inventory, approval records, session logs.",
      "SmeNote": "Two named admins, reviewed monthly.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.2",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.AA-05",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "7.2.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.308(a)(4)",
          "Reason": "Through access authorisation."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "No privileged access concept; covered generally by Art. 32."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed at control level."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "ACCESS_CONTROL"
        },
        {
          "Kind": "course",
          "Ref": "GRC-230"
        },
        {
          "Kind": "course",
          "Ref": "CYB-250"
        }
      ]
    },
    {
      "Code": "OPS-01",
      "FamilyCode": "OPS",
      "Title": "Change management",
      "Statement": "Changes to production are requested, reviewed, tested and recorded, with emergency changes reconciled afterwards.",
      "Intent": "Undocumented change is the most common cause of unexplained outage.",
      "Evidence": "Change records, approvals, emergency change log.",
      "SmeNote": "Pull request review plus a release note is enough.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC8.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.32",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.PS-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "6.5.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.308(a)(8)",
          "Reason": "Through periodic evaluation."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed; change discipline is implied only through security of processing."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 43(4)",
          "Reason": "Substantial modification triggers reassessment."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MANAGE 4.1",
          "Reason": "Post-deployment monitoring of changes."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "CHANGE_MGMT"
        },
        {
          "Kind": "course",
          "Ref": "AUD-201"
        },
        {
          "Kind": "course",
          "Ref": "GRC-230"
        }
      ]
    },
    {
      "Code": "OPS-02",
      "FamilyCode": "OPS",
      "Title": "Vulnerability management",
      "Statement": "Vulnerabilities are discovered, prioritised by risk and remediated within stated timeframes, with exceptions recorded.",
      "Intent": "Discovery without a clock is a backlog.",
      "Evidence": "Scan output, remediation SLAs, exception records.",
      "SmeNote": "Monthly scan, critical fixed in days, documented.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC7.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.8",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "ID.RA-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "11.3",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.308(a)(1)(ii)(B)",
          "Reason": "Through risk management."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32(1)(d)",
          "Reason": "Regular testing of measures."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 15",
          "Reason": "Robustness and cybersecurity of the system."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MEASURE 2.7",
          "Reason": "Security and resilience testing."
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "CYB-220"
        },
        {
          "Kind": "policy_doc_type",
          "Ref": "LOGGING_MONITORING"
        },
        {
          "Kind": "course",
          "Ref": "CYB-201"
        },
        {
          "Kind": "course",
          "Ref": "CYB-210"
        },
        {
          "Kind": "course",
          "Ref": "CYB-250"
        }
      ]
    },
    {
      "Code": "OPS-03",
      "FamilyCode": "OPS",
      "Title": "Logging and monitoring",
      "Statement": "Security-relevant events are logged, retained and reviewed, with alerts that reach a person who acts.",
      "Intent": "Logs nobody reads are storage, not detection.",
      "Evidence": "Logging configuration, retention, alert handling records.",
      "SmeNote": "Cloud provider logs, one alert channel, reviewed weekly.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC7.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.15",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "DE.CM-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "10.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.312(b)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32",
          "Reason": "Implied by appropriate measures."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 12",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MEASURE 3.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "LOGGING_MONITORING"
        }
      ]
    },
    {
      "Code": "OPS-04",
      "FamilyCode": "OPS",
      "Title": "Endpoint and device protection",
      "Statement": "Devices with access to organizational data are hardened, patched, encrypted and recoverable.",
      "Intent": "The laptop is the office.",
      "Evidence": "Device inventory, configuration baseline, encryption evidence.",
      "SmeNote": "MDM or a documented baseline with proof for each device.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC6.8",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.1",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.PS-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "5.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.310(c)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32(1)(a)",
          "Reason": "Encryption named as an example measure."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed at control level."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "REMOTE_WORK"
        },
        {
          "Kind": "course",
          "Ref": "SAT-104"
        }
      ]
    },
    {
      "Code": "OPS-05",
      "FamilyCode": "OPS",
      "Title": "Secure development",
      "Statement": "Security requirements, review and testing are part of how software is built and released.",
      "Intent": "Fixing design in production is the most expensive way to work.",
      "Evidence": "SDLC documentation, review records, test evidence.",
      "SmeNote": "Code review, dependency scanning, a release checklist.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC8.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.25",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.PS-06",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "6.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "none",
          "Reference": null,
          "Reason": "No development obligations in the Security Rule."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 25",
          "Reason": "Data protection by design and by default."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 17",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MAP 2.3",
          "Reason": "System design documentation."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "SECURE_SDLC"
        },
        {
          "Kind": "course",
          "Ref": "AUD-230"
        },
        {
          "Kind": "course",
          "Ref": "CYB-201"
        }
      ]
    },
    {
      "Code": "TPR-01",
      "FamilyCode": "TPR",
      "Title": "Third-party inventory",
      "Statement": "Third parties with access to data or systems are inventoried with an owner and a criticality judgement.",
      "Intent": "You cannot assess a vendor you have not listed.",
      "Evidence": "Vendor register with owner, data access and criticality.",
      "SmeNote": "One list, updated when someone signs a new tool.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC9.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.19",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.SC-04",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.8.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(b)(1)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 28",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 25",
          "Reason": "Responsibilities along the AI value chain."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 6.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "TPR-201"
        },
        {
          "Kind": "course",
          "Ref": "TPR-215"
        },
        {
          "Kind": "course",
          "Ref": "TPR-230"
        },
        {
          "Kind": "course",
          "Ref": "CYB-201"
        },
        {
          "Kind": "course",
          "Ref": "TRS-220"
        },
        {
          "Kind": "course",
          "Ref": "TPR-240"
        },
        {
          "Kind": "course",
          "Ref": "TPR-250"
        },
        {
          "Kind": "course",
          "Ref": "TPR-270"
        }
      ]
    },
    {
      "Code": "TPR-02",
      "FamilyCode": "TPR",
      "Title": "Due diligence proportionate to risk",
      "Statement": "Third parties are assessed before onboarding and periodically thereafter, at a depth proportionate to what they touch.",
      "Intent": "A questionnaire sent to everyone is a questionnaire nobody reads.",
      "Evidence": "Assessment records, tiering rationale, reassessment dates.",
      "SmeNote": "Two tiers, a short set of questions for the lower one.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC9.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.21",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.SC-07",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.8.4",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.308(b)",
          "Reason": "Satisfactory assurances through the agreement."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 28(1)",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 25",
          "Reason": "Contractual duties between value chain actors."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 6.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "TPR-210"
        },
        {
          "Kind": "course",
          "Ref": "TPR-220"
        },
        {
          "Kind": "course",
          "Ref": "TRS-201"
        },
        {
          "Kind": "course",
          "Ref": "TPR-215"
        },
        {
          "Kind": "course",
          "Ref": "TPR-230"
        },
        {
          "Kind": "course",
          "Ref": "CYB-210"
        },
        {
          "Kind": "course",
          "Ref": "TPR-240"
        },
        {
          "Kind": "course",
          "Ref": "TPR-250"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    },
    {
      "Code": "TPR-03",
      "FamilyCode": "TPR",
      "Title": "Contractual terms and offboarding",
      "Statement": "Contracts carry security, privacy and breach terms, and access and data are recovered when the relationship ends.",
      "Intent": "The end of a relationship is where data is most often left behind.",
      "Evidence": "Executed terms, offboarding checklist, deletion confirmations.",
      "SmeNote": "A short addendum and a close-out checklist.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC9.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.20",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.SC-05",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.8.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.314(a)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 28(3)",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 25(4)",
          "Reason": "Written agreements along the value chain."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "GOVERN 6.2",
          "Reason": "Contingency for third-party failure."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "VENDOR_MGMT"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-003"
        },
        {
          "Kind": "course",
          "Ref": "PRV-203"
        },
        {
          "Kind": "course",
          "Ref": "TPR-230"
        },
        {
          "Kind": "course",
          "Ref": "PRV-280"
        },
        {
          "Kind": "course",
          "Ref": "TRS-220"
        },
        {
          "Kind": "course",
          "Ref": "SAT-107"
        },
        {
          "Kind": "course",
          "Ref": "TPR-240"
        },
        {
          "Kind": "course",
          "Ref": "TPR-270"
        }
      ]
    },
    {
      "Code": "RES-01",
      "FamilyCode": "RES",
      "Title": "Incident response plan and roles",
      "Statement": "An incident response plan exists, names roles, and is exercised.",
      "Intent": "Plans nobody has rehearsed fail in the first hour.",
      "Evidence": "Plan document, exercise records, contact tree.",
      "SmeNote": "A two-page plan and one tabletop a year.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC7.4",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.24",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "RS.MA-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.10.1",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(6)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 33",
          "Reason": "Notification duty implies a process."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 73",
          "Reason": "Serious incident reporting for providers."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MANAGE 4.3",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "INCIDENT_RESPONSE"
        },
        {
          "Kind": "course",
          "Ref": "CYB-230"
        },
        {
          "Kind": "course",
          "Ref": "PRV-260"
        },
        {
          "Kind": "course",
          "Ref": "SAT-105"
        }
      ]
    },
    {
      "Code": "RES-02",
      "FamilyCode": "RES",
      "Title": "Breach notification within statutory time",
      "Statement": "Reportable incidents are assessed and notified to regulators and affected people within the applicable deadlines.",
      "Intent": "The clock starts at awareness, not at certainty.",
      "Evidence": "Assessment records, notification evidence, timing.",
      "SmeNote": "Know your deadlines before you need them.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "partial",
          "Reference": "CC7.5",
          "Reason": "Communication of incidents without statutory deadlines."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "partial",
          "Reference": "A.5.24",
          "Reason": "Reporting without statutory timing."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "RS.CO-02",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "partial",
          "Reference": "12.10.1",
          "Reason": "Notification to brands and acquirers."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.404",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 33, 34",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 73",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "none",
          "Reference": null,
          "Reason": "No notification obligation; the framework is voluntary guidance."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "INCIDENT_RESPONSE"
        },
        {
          "Kind": "course",
          "Ref": "PRV-260"
        },
        {
          "Kind": "course",
          "Ref": "PRV-203"
        }
      ]
    },
    {
      "Code": "RES-03",
      "FamilyCode": "RES",
      "Title": "Backups that restore",
      "Statement": "Backups exist, are protected from the same failure as production, and restoration is tested.",
      "Intent": "An untested backup is a hope with a storage bill.",
      "Evidence": "Backup configuration, restore test records, retention.",
      "SmeNote": "One restore test a year, written down.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "A1.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.8.13",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "PR.DS-11",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "partial",
          "Reference": "12.10.1",
          "Reason": "Referenced through recovery in incident response."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(7)(ii)(A)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 32(1)(c)",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MANAGE 4.3",
          "Reason": "Resilience to failure."
        }
      ],
      "resources": [
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-003"
        },
        {
          "Kind": "course",
          "Ref": "CYB-250"
        }
      ]
    },
    {
      "Code": "RES-04",
      "FamilyCode": "RES",
      "Title": "Continuity and recovery objectives",
      "Statement": "Critical processes have recovery objectives, a continuity plan and a tested route back to service.",
      "Intent": "Objectives set before an outage are decisions; after one they are excuses.",
      "Evidence": "BIA, RTO and RPO, plan, exercise records.",
      "SmeNote": "Know which three processes matter and how long you can be down.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "A1.3",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.29",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "RC.RP-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "none",
          "Reference": null,
          "Reason": "Continuity is out of scope; the standard addresses cardholder data protection."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(7)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32(1)(c)",
          "Reason": "Timely restoration of availability."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "partial",
          "Reference": "MANAGE 4.3",
          "Reason": "Contingency planning."
        }
      ],
      "resources": [
        {
          "Kind": "policy_doc_type",
          "Ref": "BCP"
        },
        {
          "Kind": "policy_doc_type",
          "Ref": "DR_PLAN"
        },
        {
          "Kind": "course",
          "Ref": "TPR-250"
        },
        {
          "Kind": "course",
          "Ref": "TPR-270"
        }
      ]
    },
    {
      "Code": "AIG-01",
      "FamilyCode": "AIG",
      "Title": "AI system inventory",
      "Statement": "AI and automated decision systems in use are inventoried with purpose, owner, data and risk classification.",
      "Intent": "You cannot govern models you have not listed, including the ones staff adopted quietly.",
      "Evidence": "AI inventory, classification records, owner assignment.",
      "SmeNote": "One list including the tools people already use.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "none",
          "Reference": null,
          "Reason": "No AI-specific criteria; AI systems are treated as any other system."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "none",
          "Reference": null,
          "Reason": "Annex A is technology-neutral; ISO/IEC 42001 addresses AI management systems instead."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "partial",
          "Reference": "ID.AM-01",
          "Reason": "Through asset inventory."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "none",
          "Reference": null,
          "Reason": "Out of scope."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "none",
          "Reference": null,
          "Reason": "Out of scope."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 22, 30",
          "Reason": "Automated decision-making records where applicable."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 6, 49",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MAP 1.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AIG-201"
        },
        {
          "Kind": "course",
          "Ref": "AIG-230"
        }
      ]
    },
    {
      "Code": "AIG-02",
      "FamilyCode": "AIG",
      "Title": "AI risk assessed before deployment",
      "Statement": "AI systems are assessed for harm, bias, robustness and transparency before use, and the assessment is revisited on change.",
      "Intent": "The cost of a bad model is paid by people outside the room.",
      "Evidence": "Assessment records, bias testing, sign-off before deployment.",
      "SmeNote": "One assessment page per model, honestly completed.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "none",
          "Reference": null,
          "Reason": "No AI-specific criteria."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed in Annex A."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "partial",
          "Reference": "ID.RA-01",
          "Reason": "Through risk identification."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "none",
          "Reference": null,
          "Reason": "Out of scope."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "none",
          "Reference": null,
          "Reason": "Out of scope."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 35",
          "Reason": "DPIA where processing is high risk."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 9, 27",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MEASURE 2.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AIG-210"
        },
        {
          "Kind": "course",
          "Ref": "PRV-250"
        },
        {
          "Kind": "course",
          "Ref": "AIG-230"
        }
      ]
    },
    {
      "Code": "AIG-03",
      "FamilyCode": "AIG",
      "Title": "Human oversight and disclosure",
      "Statement": "People affected by automated decisions are told, and a competent person can intervene.",
      "Intent": "Automation without a human path becomes a wall.",
      "Evidence": "Disclosure text, oversight procedure, intervention records.",
      "SmeNote": "Say when a model was used and who to ask.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "none",
          "Reference": null,
          "Reason": "No AI-specific criteria."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "none",
          "Reference": null,
          "Reason": "Out of scope."
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "none",
          "Reference": null,
          "Reason": "Out of scope."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 22(3)",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 14, 50",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 3.2",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AIG-220"
        },
        {
          "Kind": "course",
          "Ref": "SAT-106"
        },
        {
          "Kind": "course",
          "Ref": "AIG-230"
        }
      ]
    },
    {
      "Code": "ASR-01",
      "FamilyCode": "ASR",
      "Title": "Controls have owners",
      "Statement": "Every control has one accountable owner and named performers for its tasks.",
      "Intent": "Shared ownership is the reliable route to nothing happening.",
      "Evidence": "Control ownership matrix, attestations.",
      "SmeNote": "One person, twelve controls, written down.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC1.3",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "A.5.2",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.RR-02",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.4.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.308(a)(2)",
          "Reason": "Security official responsibility."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "No control ownership concept."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 2.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AUD-201"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-010"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-011"
        },
        {
          "Kind": "course",
          "Ref": "TPR-215"
        }
      ]
    },
    {
      "Code": "ASR-02",
      "FamilyCode": "ASR",
      "Title": "Populations are complete",
      "Statement": "Where a control is tested by sample, the population is defined and its completeness can be demonstrated.",
      "Intent": "A sample from an incomplete population proves nothing.",
      "Evidence": "Population definitions, extraction method, completeness argument.",
      "SmeNote": "Small populations tested whole.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "partial",
          "Reference": "CC4.1",
          "Reason": "Evaluation is required; population completeness is an audit expectation rather than a criterion."
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "partial",
          "Reference": "9.2",
          "Reason": "Audit programme requirements."
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "none",
          "Reference": null,
          "Reason": "The Framework describes outcomes, not testing method."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "Testing procedures",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "none",
          "Reference": null,
          "Reason": "No testing methodology defined."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "No testing methodology defined."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "none",
          "Reference": null,
          "Reason": "Not addressed."
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AUD-210"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-012"
        },
        {
          "Kind": "course",
          "Ref": "DTF-MICRO"
        },
        {
          "Kind": "course",
          "Ref": "GRC-220"
        }
      ]
    },
    {
      "Code": "ASR-03",
      "FamilyCode": "ASR",
      "Title": "Evidence is dated, attributable and retained",
      "Statement": "Evidence shows what was done, by whom and when, and is kept for the period the obligation requires.",
      "Intent": "Evidence without a date is an assertion.",
      "Evidence": "Evidence index, retention schedule, storage controls.",
      "SmeNote": "A folder per control with dated files.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC4.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "7.5",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "partial",
          "Reference": "GV.OV-03",
          "Reason": "Through performance review."
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.10.7",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.316(b)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "full",
          "Reference": "Art. 5(2)",
          "Reason": null
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "full",
          "Reference": "Art. 18",
          "Reason": null
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "GOVERN 1.4",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AUD-220"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-013"
        },
        {
          "Kind": "course",
          "Ref": "GRC-203"
        },
        {
          "Kind": "course",
          "Ref": "AUD-260"
        },
        {
          "Kind": "course",
          "Ref": "GRC-220"
        },
        {
          "Kind": "course",
          "Ref": "TPR-260"
        },
        {
          "Kind": "course",
          "Ref": "TRS-210"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    },
    {
      "Code": "ASR-04",
      "FamilyCode": "ASR",
      "Title": "Independent testing and reporting",
      "Statement": "Controls are tested by someone other than the person who performs them, and results are reported without softening.",
      "Intent": "Self-assessment that never finds anything is a marketing document.",
      "Evidence": "Test plans, results, findings and management responses.",
      "SmeNote": "A peer, an adviser or a rotating reviewer.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC4.1",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "9.2",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "GV.OV-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.11",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "full",
          "Reference": "164.308(a)(8)",
          "Reason": null
        },
        {
          "FrameworkCode": "GDPR",
          "State": "partial",
          "Reference": "Art. 32(1)(d)",
          "Reason": "Regular testing and evaluation."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 17",
          "Reason": "Quality management system includes verification."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MEASURE 4.1",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "AUD-240"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-016"
        },
        {
          "Kind": "course",
          "Ref": "TRS-201"
        },
        {
          "Kind": "course",
          "Ref": "AUD-260"
        },
        {
          "Kind": "course",
          "Ref": "TPR-260"
        },
        {
          "Kind": "course",
          "Ref": "TRS-210"
        }
      ]
    },
    {
      "Code": "ASR-05",
      "FamilyCode": "ASR",
      "Title": "Findings are closed with evidence",
      "Statement": "Findings carry an owner, a date, a remediation and evidence that the fix works.",
      "Intent": "A closed finding without evidence is an open finding with better paperwork.",
      "Evidence": "Findings register, remediation evidence, verification.",
      "SmeNote": "A tracker leadership reviews monthly.",
      "mappings": [
        {
          "FrameworkCode": "SOC2",
          "State": "full",
          "Reference": "CC4.2",
          "Reason": null
        },
        {
          "FrameworkCode": "ISO27001",
          "State": "full",
          "Reference": "10.1",
          "Reason": null
        },
        {
          "FrameworkCode": "NISTCSF",
          "State": "full",
          "Reference": "ID.IM-01",
          "Reason": null
        },
        {
          "FrameworkCode": "PCIDSS",
          "State": "full",
          "Reference": "12.11.2",
          "Reason": null
        },
        {
          "FrameworkCode": "HIPAA",
          "State": "partial",
          "Reference": "164.308(a)(1)(ii)(B)",
          "Reason": "Through risk management."
        },
        {
          "FrameworkCode": "GDPR",
          "State": "none",
          "Reference": null,
          "Reason": "No findings process defined."
        },
        {
          "FrameworkCode": "EUAIACT",
          "State": "partial",
          "Reference": "Art. 20",
          "Reason": "Corrective actions by providers."
        },
        {
          "FrameworkCode": "AIRMF",
          "State": "full",
          "Reference": "MANAGE 2.4",
          "Reason": null
        }
      ],
      "resources": [
        {
          "Kind": "course",
          "Ref": "OPS-210"
        },
        {
          "Kind": "template",
          "Ref": "ADTP-TPL-016"
        },
        {
          "Kind": "course",
          "Ref": "GRC-220"
        },
        {
          "Kind": "course",
          "Ref": "TPR-260"
        },
        {
          "Kind": "course",
          "Ref": "OPS-290"
        }
      ]
    }
  ]
}