Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Standard Selection and Control Mapping Processes in Cybersecurity Frameworks
University West, Department of Engineering Science.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This thesis investigates both the feasibility and the inherent limitations of mapping cybersecurity controls across a diverse set of regulatory and industry frameworks. In an era where many organizations seek to consolidate their cybersecurity compliance efforts under a unified approach, the findings reveal that relying solely on control descriptions for mapping is fundamentally unreliable. Few sources of indeterminism were identified such as control relationships, variations in the granularity of control statements, divergent semantic interpretations of similar languages, and distinct organizational contexts assumed by each framework. In response to these challenges a structured mapping approach based on the Secure Controls Framework (SCF) methodology is proposed. By leveraging SCF’s modular architecture, where high-level objectives are systematically decomposed into granular control sets, organizations can streamline the alignment of multiple frameworks. Nonetheless, this paper underscores that no amount of automation can fully replace the need for expert judgment. Accurate and effective cross-framework compliance demands an expert to be present in conducting or validating the process. Automated tools based on Natural Language Processing (NLP) or Large Language Models (LLM) can be integrated to enhance consistency and efficiency but require fine tuning and human oversight to interpret intent, resolve ambiguities, and ensure that control mappings genuinely reflect an organization’s risk profile and operational realities.

Place, publisher, year, edition, pages
2025. , p. 67
Keywords [en]
Cybersecurity multi-framework, Control mapping, Compliance
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-23692Local ID: EXD600OAI: oai:DiVA.org:hv-23692DiVA, id: diva2:1979332
Subject / course
Computer science
Educational program
Master in Cybersecurity
Supervisors
Examiners
Available from: 2025-07-22 Created: 2025-06-30 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 54 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf