Security Frameworks and Standards

How to enable compliance framework mappings on Settings → Organization.

Security Frameworks and Standards is the second section on Settings → Organization. Its description reads Enable compliance framework mappings for risk assessments.

Each framework has its own card with a switch. Turn a switch on to enable that framework's mappings, or off to disable them. Only users who can manage settings can change the switches.

Framework

Description in the UI

NIST CSF 2.0

NIST Cybersecurity Framework — risk-based subcategory mappings derived from SP 800-53 controls

PCI DSS 4.0

Payment Card Industry Data Security Standard — requirement-level mappings for cardholder data protection

HIPAA Security Rule

Health Insurance Portability and Accountability Act — technical safeguard mappings for protected health information

SOC 2 Type II

Service Organization Control — Trust Services Criteria mappings for service providers

CIS Controls v8

Center for Internet Security Critical Security Controls — implementation-focused control mappings

These switches do not change SSO or scan settings.