Skip to content

Framework explorer

Compliance

One control, many regulations. Spine maps 395 requirements from 15 frameworks across the US, Canada, India, the UK and EU onto 118 common controls, so one piece of evidence answers every framework that asks the same question.

How the crosswalk works

Answer the question once, for every framework.

Regulators ask the same things in different words. A common control set turns fifteen checklists into one.

  1. Ask the question once

    Each common control is one plain question, such as "is access checked before anyone gets in". Frameworks ask it in their own words.

  2. Map every framework to it

    Each framework requirement points at exactly one common control, so SOC 2, ISO 27001 and DPDP wording all land on the same row.

  3. Collect evidence once

    The platform collects evidence against the common control, so one record answers every framework that asks. Less duplicate work before an audit.

Explorer

Pick a region or a framework, then a control.

Selecting a control lists every framework requirement it covers. This is the crosswalk the Compliance Center collects evidence against.

Frameworks (15)

Select a framework to see only its controls. Select it again to clear.

118 of 118 common controls, all frameworks.

CCF-AC-01 · Access control

Role-based access and least privilege

Access is granted by role on a need-to-know basis and the data layer enforces it.

Covers 11 requirements across 10 frameworks.

  • CCPA / CPRAUS
    • 1798.150 Reasonable security procedures and practices
  • DPDP ActIndia
    • s.8(5) Reasonable security safeguards to prevent a personal data breach
  • GDPR / UK GDPRUK/EU
    • Art 28(3)(c) All measures required by Article 32 taken
  • GLBA SafeguardsUS
    • 314.4(c)(1) Access controls limit customer information to authorised users
  • HIPAA SecurityUS
    • 164.308(a)(4) Information access management
  • ISO/IEC 27001Global
    • A.5.15 Access control
    • A.8.3 Information access restriction
  • NIST CSF 2.0US
    • PR.AA Identity Management, Authentication and Access Control
  • PCI DSSGlobal
    • Req 7 Access restricted by need to know
  • PIPEDACanada
    • 4.7.3(c) Technological measures: authentication and tamper-evident records
  • SOC 2US
    • CC6.3 Least privilege at the data layer

Scope

Controls mapped, not certification.

What this page shows

Each mapping says a common control is designed to support that requirement and that the platform collects evidence for it. It is not an audit opinion and we make no claim of third party assurance on this site. Your auditors and your own compliance team decide what the evidence proves.

In the product, the Compliance Center tracks evidence, owners, attestations and waivers against these same controls, and its Guardian agent explains each gap in plain words.

Questions

Common questions about the mapping.

Map your obligations onto one control set.

Tell us which regulators you answer to. We will show where the evidence for each requirement comes from.