One control architecture. Every framework maps to it.
A control architecture earns its keep the day someone tries to break it — an auditor sampling across frameworks, a penetration tester, a new regulation. Architectures designed framework-by-framework drift apart: three versions of access control, two of logging, no single place where "what we enforce" lives.
TruSecure inverts it: model the architecture once as patterns — identity, segmentation, logging, incident response — attach controls to the patterns, and let every framework's citations fan out from the controls. The crosswalk is generated, not maintained by hand.
What changes for the design
- Model patterns, not documents
Identity, segmentation, logging, response — architecture patterns with controls attached, in one library that describes what is actually enforced.
- Map frameworks onto it
Each control carries its citations — NIS2, DORA, ISO 27001, NIST CSF, SOC 2, and the rest — so the mapping is a property of the model, not a spreadsheet kept beside it.
- Test coverage, not intent
The crosswalk shows every framework's expectations against implemented controls. Coverage gaps appear per pattern, with the missing citation named.
- Keep it current
A change to a pattern re-evaluates its mappings. The architecture review and the compliance review stop being separate ceremonies.
What you'd actually look at
One pattern from the library — click it in the dashboard and this is the definition a reviewer works from:
- Controls
- 3
- Implemented
- 3/3 · evidence linked
- Covers
- NIS2 Art. 21(2)(j) · ISO 27001 A.8.5 · NIST CSF PR.AA
- Gaps
- none
- Last change
- CR-0921 · reviewed
What the design is held against
| What it expects of the architecture | Citation | Where it is answered |
|---|---|---|
| NIS2 · security in network and system development and maintenance | Art. 21(2)(e) | Pattern library |
| NIS2 · risk-analysis policies and effectiveness assessment | Art. 21(2)(a) · (f) | Crosswalk coverage |
| ISO 27001 · network segregation, monitoring, logging | A.8.22 · A.8.16 · A.8.15 | Control library |
| NIST CSF 2.0 · Protect and Respond functions | PR · RS | Crosswalk coverage |
How architects usually start
A demo with your own architecture vocabulary in it — your patterns, your naming — then a Resilience Sprint that models the first domain end to end, then the subscription. No self-serve checkout, no per-seat maths; packaging is scoped in the conversation.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.