The most expensive mistake in a compliance project is not a missed control. It is documentation written a second time, because nobody checked what already existed.
The Regulation anticipated this. Article 49 provides for a correlation overview of the measures, mapping every sub-measure of Annex II onto recognised standards and good practice.
What it maps to
| Source | What it covers |
|---|---|
| ISO/IEC 27001:2022 | The information security management system framework |
| ISO/IEC 27002:2022 | Implementation guidance for the controls, in four themes |
| ISO/IEC 22301:2019 | Business continuity |
| NIST CSF 2.0 | Six functions, including the new Govern |
| NIST SP 800-53 | An extensive set of technical and organisational controls |
| CIS v8 | Practical controls, including cloud and mobile |
| ZSIS control catalogue | The 132 controls used in the self-assessment |
If you hold ISO 27001, the correlation overview tells you, for every sub-measure, which of your existing controls are thematically related. That is not proof of compliance, but it is a list of the places where the evidence probably already exists. Instead of 99 empty fields you start with 99 fields that have a candidate.
The trap the overview itself points out
The guidance notes something easy to miss: the scope of each control from the international standards exceeds the scope of the sub-measure being mapped. A control from ISO 27002 appearing next to sub-measure 3.2 also covers things that sub-measure does not require, and may not cover everything it does.
The consequence: mapping is a starting point, not a conclusion. A tick in the correlation table is not evidence. Evidence is a record answering what the sub-measure requires, to the extent it requires it.
How to use it so it genuinely saves work
- Start from your Statement of Applicability. For each applicable control, see which sub-measures it appears against in the correlation. That gives you the reverse mapping - from what you have towards what is required.
- Mark three states, not two. Covered, partly covered, not covered. Partly is the largest group and the most useful, because it is resolved by extending an existing document rather than writing a new one.
- Check the level. A control satisfying the basic level need not satisfy the medium one. The correlation does not distinguish levels - you must.
- Record the reasoning for every link. At verification you will have to explain why you considered an existing document to cover a sub-measure. A sentence written at the time of mapping is worth more than a reconstruction six months later.
Who benefits most
- An organisation with ISO 27001 and 22301 - the greatest benefit. Much of measures 2, 3, 7, 8 and 12 already has an evidential basis.
- An organisation working to CIS v8 - technical measures 5, 6, 7 and 9 are largely covered; the organisational ones are not.
- An organisation reporting against NIST CSF - the correlation is also a bridge to board reporting, since the six functions remain as the presentation frame.
- An organisation with none of these - still useful as a guide to what to write, because it points to controls describing how a sub-measure is usually implemented.
The correlation overview is an aid, not law. The authority assesses compliance with the measures of Annex II and the controls of the catalogue, not with the standards the overview points to. An ISO 27001 certificate replaces neither the self-assessment nor the audit.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.