At a glance
| Input | Action | Output | Limit |
|---|---|---|---|
| Supported requirement catalog | Select the relevant framework view | Requirement list | Catalog content is not legal advice |
| Internal evidence reference | Map it to a requirement | Recorded evidence relationship | A link does not prove sufficiency |
| Missing or incomplete evidence | Preserve the gap state | Readiness signal | Teams own remediation and applicability |
| Custom control need | Save supported custom context | Organization-specific mapping | Governance and review remain external |
How it works
- Open Requirements Mapper.
- Select the supported catalog or custom context.
- Review each requirement.
- Attach the relevant recorded evidence.
- Keep missing or incomplete items visible.
- Have qualified owners review applicability and sufficiency.
Example
A security team maps its incident terminology evidence to one control requirement. The mapper shows that evidence is recorded, while a separate requirement remains incomplete. Leadership sees the documented posture without receiving a certification claim.
What this does not mean
Mapping is organizational evidence management. It is not a legal interpretation, audit opinion, certification, or guarantee of regulatory compliance. Catalog updates and applicability decisions require qualified review.
Related questions
Next step
Use the mapper to expose gaps, then have control owners evaluate sufficiency.
View on Atlassian Marketplace