Cross-framework mappings.
Most Australian organisations are held to more than one framework at a time. These crosswalks show where controls cover the same ground, so evidence you already hold can be reused rather than rebuilt.
Control Stack is a free Australian reference covering 1,423 cyber security controls: all 1,143 ASD ISM controls, 149 Essential Eight controls across all four maturity levels, all 93 ISO/IEC 27001:2022 Annex A controls and all 38 ISO/IEC 42001:2023 Annex A controls. Every one of them is cross-mapped between the four frameworks and readable in full without an account.
ISO 27001 to Essential Eight
arrow_forwardWhich ISO/IEC 27001:2022 Annex A controls line up with each Essential Eight mitigation strategy. Hand-verified, and deliberately strict about what counts as a direct match.
Hand-verified crosswalk
ISO 27001 to ASD ISM
arrow_forwardThe ISM controls that cover the same ground as each Annex A control. The densest mapping on the site, because the two frameworks overlap heavily in subject matter.
93 of 93 controls mapped
Essential Eight to ASD ISM
arrow_forwardThe ISM controls behind each Essential Eight requirement, at every maturity level. Both frameworks come from ASD, so the relationships are unusually direct.
149 of 149 controls mapped
ISO 27001 to ISO 42001
arrow_forwardWhere information security management meets AI management. The thinnest crosswalk here, because ISO 42001 governs AI specifically and most of ISO 27001 has no AI counterpart.
39 of 93 controls mapped
How to read a mapping
A mapping means two controls address related risk. It does not mean satisfying one satisfies the other, and it is not a certification shortcut. Each pairing carries a relationship label, such as partially meets, partially overlaps, supports or depends on, and the honest answer for many pairs is that no counterpart exists. Those rows say so rather than stretching for a match.