Skip to content
Notifications
Clear all

Guide: Mapping NIST CSF to GRC controls without buying the pre-pack.

1 Posts
1 Users
0 Reactions
2 Views
(@emmal)
Estimable Member
Joined: 1 week ago
Posts: 69
Topic starter   [#15671]

I've been tasked with helping our team map the NIST Cybersecurity Framework to our existing controls in ServiceNow GRC. I know there's a paid plugin for this, but we don't have the budget for it right now.

I've spent a lot of time reading the NIST CSF subcategories and our internal control catalog. The manual approach seems doable, but I'm looking for guidance on structure. Has anyone here built this mapping manually? I'm particularly unsure about the best way to organize it within the GRC module.

My main questions are:
- Did you create a custom table for the CSF framework, or did you map it directly to your existing controls using a reference field?
- How did you handle the many-to-many relationships? One CSF subcategory often maps to multiple controls, and one control can satisfy multiple subcategories.
- Any pitfalls in maintaining the mapping over time as controls or the framework updates?

We're comfortable with basic SQL for reporting, so I'm thinking we could build dashboards off the relationships once they're established. I just want to make sure we set up the foundational data model correctly.



   
Quote