Risk Management Frameworks

ISO, NIST, SOC 2, DORA — map your controls once, evidence them everywhere.

ISO 27001, NIST CSF, NIST 800-53, SOC 2, DORA, NIS2, EU AI Act, GDPR, PCI DSS — most of them ask for the same controls in different words. Lojycal brings a little Lojyc to compliance: one live control library, one evidence stream, every framework satisfied from the same source of truth.

What every risk framework actually asks for

Strip the vocabulary away and the modern GRC frameworks converge on six obligations. Lojycal produces all six directly from operational systems — instead of from spreadsheets and screenshots a week before the audit.

  • Defined scope and asset register

    What's in scope — systems, data, vendors, locations, AI models. ISO calls it the ISMS scope, SOC 2 calls it the boundary, DORA calls it the ICT estate. Same thing, three names.

  • Risk assessment with ownership

    Threats, likelihood, impact, residual risk, owner. ISO 27001 Clause 6, NIST CSF Govern/Identify, SOC 2 CC3, DORA Art. 6, NIS2 Art. 21, AI Act Art. 9 — the structure is identical.

  • A control catalogue you can prove

    Annex A, NIST 800-53, SOC 2 TSC, PCI DSS 4.0 requirements — pick your reference set, map your implementation, evidence operating effectiveness.

  • Continuous monitoring, not annual photos

    Frameworks moved from point-in-time to continuous a decade ago. SOC 2 Type II, ISO 27001 surveillance, DORA continuous monitoring, NIS2 supervision — auditors want the stream, not a snapshot.

  • Incident detection, classification and reporting

    Detect, classify, escalate, report within the framework's window. NIS2 24/72h, DORA major-incident, AI Act Art. 73, GDPR 72h breach — the timer starts the moment you know.

  • Third-party and supply-chain risk

    Every modern framework now treats vendors as in-scope. ISO 27001 A.5.19–A.5.23, DORA TPRM, NIS2 supply-chain, SOC 2 vendor due diligence, GDPR Art. 28 processors.

Four Lojycal workspaces. Every framework covered.

One model, many frameworks. Add a control once, map it to every standard that asks for it, and let evidence accumulate continuously — instead of rebuilding the same audit pack three times a year.

Unified control library

Every control implementation linked to ISO, NIST, SOC 2, DORA, NIS2, AI Act, GDPR and PCI references at once. Add once, satisfy everywhere.

Trust Center → Control Library

Live evidence stream

Configuration, access, MFA, change, MDM, SIEM and HRIS events streamed into a WORM ledger — the evidence behind every control, current to the minute.

Audit Log + Evidence Pack

Risk register

Risks scored with likelihood, impact, owner and treatment. The same register feeds ISO Clause 6, SOC 2 CC3, DORA Art. 6 and AI Act Art. 9 risk records.

Trust Center → Risk

Incident & audit ledger

Detection, classification, owner, timeline, regulator notification draft. NIS2, DORA, AI Act, GDPR — one ledger, every reporting window.

Incident Ledger → Report Builder

Which framework asks for what — at a glance

Most teams running ISO 27001 are already 80% of the way to SOC 2 and 70% of the way to NIST CSF — they just don't know it. Lojycal makes the overlap explicit. A sampled mapping:

FrameworkWhat it's forLojycal source
ISO 27001:2022ISMS + Annex A controls — certifiableControl Library → SoA
NIST CSF 2.0Govern · Identify · Protect · Detect · Respond · RecoverControl Library → CSF view
NIST 800-53 / 800-171Federal control baselines + CUIControl Library → 800-53 view
SOC 2 (Trust Services Criteria)Type I/II attestation for service orgsControl Library + Evidence Stream
DORAICT risk + TPRM for EU financial entitiesTrust Center → DORA
NIS2Risk + incident reporting for essential/important entitiesRisk Register + Incident Ledger
EU AI ActAI inventory + post-market monitoringAI System Register
GDPRRecords of processing + DSAR + breach 72hPrivacy Workspace + Incident Ledger
PCI DSS 4.0Cardholder-data environment controlsControl Library → PCI view

Sampled — not exhaustive. Frameworks evolve; each Lojycal control row carries its current reference version and a last-mapped date.

Map controls once, evidence them everywhere

The hidden cost of compliance isn't the audit. It's the third spreadsheet of the year, the fourth screenshot exercise, the fifth conversation about the same control.

Lojycal stops the duplication. Every control implementation is mapped to every framework reference that asks for it; every evidence write is a WORM audit-log entry; every Evidence Pack is a signed JSON+CSV+PDF bundle with a detached HMAC signature using a per-organisation key. Hand the same bundle to your ISO surveillance auditor, your SOC 2 firm, your DORA examiner, your NIS2 supervisor — and let them verify it independently.

From framework spaghetti to one signed source — 90 days

Teams that try to roll out ISO, SOC 2, DORA and NIS2 as separate programmes burn out by Q2. Teams that run them on one control library finish the first audit in 90 days and the second one almost for free.

  1. Days 0–30

    Phase 1 — Inventory & crosswalk

    Pull existing controls from spreadsheets, GRC tools and shared drives into the Lojycal Control Library. Crosswalk against the frameworks in scope. Identify duplicates, gaps and unowned controls.

  2. Days 31–60

    Phase 2 — Control consolidation

    Collapse duplicate controls into single implementations. Connect operational systems (IdP, MDM, SIEM, ticketing, HRIS) so evidence flows automatically. Sign off owners and review cadence.

  3. Days 61–90

    Phase 3 — Continuous evidence

    Switch the framework you cared about first into surveillance mode. Generate the first signed Evidence Pack. Run the second framework off the same data with no new operational work.

Risk management frameworks — common questions

ISO 27001 vs NIST CSF vs SOC 2 — which one do I actually need?

Different goals, different audiences. ISO 27001 is a certifiable international ISMS standard — best when customers, regulators or tenders ask for a certificate. NIST CSF 2.0 is a voluntary framework — best as an internal organising model and the default starting point in the US. SOC 2 is an attestation by a CPA firm against the Trust Services Criteria — table stakes for US SaaS selling to mid-market and up. Most mature programmes run ISO + SOC 2 together because the underlying controls overlap by ~80%, and use NIST CSF as the organising language inside.

Do I have to choose, or can I run multiple frameworks at once?

You can run multiple — and most regulated companies do. The trick is to map each control implementation to every framework reference it satisfies, instead of implementing the same control three times. Lojycal's Control Library is built around that mapping: add MFA-on-everything once, and it satisfies ISO A.5.17 + A.8.5, NIST CSF PR.AA-03, NIST 800-53 IA-2, SOC 2 CC6.1, PCI DSS 8.4, DORA Art. 9 and NIS2 Art. 21 simultaneously.

How much overlap is there really between ISO 27001 and SOC 2?

Practically: ~80% by control count. ISO 27001:2022 Annex A has 93 controls; the SOC 2 Trust Services Criteria has roughly 64 common criteria plus optional categories. A solid majority map one-to-one or one-to-many. Authentication, change management, vulnerability management, incident response, vendor management and logical access are essentially identical in substance — the language differs more than the obligation.

SOC 2 Type I vs Type II — what's the difference?

Type I is point-in-time: 'on this date, the controls were designed appropriately'. Type II is operating effectiveness over a period (usually 6–12 months): 'between these dates, the controls operated continuously and were tested by sampling'. Type II is what enterprise buyers ask for. Lojycal's continuous evidence stream gives a Type II auditor a population to sample from instead of forcing your team to reconstruct one each quarter.

Does ISO 27001 cover DORA?

Partially. ISO 27001 + ISO 22301 + ISO 27036 cover most of the ICT risk-management surface DORA Art. 5–14 demands, but DORA adds explicit obligations on major-incident classification and reporting, threat-led penetration testing for significant entities, and a structured ICT third-party register that ISO doesn't impose. Lojycal's DORA workspace inherits ISO evidence where it overlaps and adds the DORA-specific artefacts on top.

Where does the EU AI Act fit alongside ISO and GDPR?

The AI Act sits on top of GDPR (which applies whenever a model processes personal data) and complements ISO 42001 (the AI management system standard). For high-risk AI systems you need ISO-style risk and quality records, GDPR's data governance and DPIA evidence, and the AI Act's risk tiering, technical documentation, post-market monitoring and serious-incident reporting. Lojycal links each AI system to its GDPR Record of Processing and its ISO control set so the same data governance work counts for all three.

What does NIST CSF 2.0 add over CSF 1.1?

The big change is the new Govern function: a sixth pillar covering organisational context, risk-management strategy, roles, policy, oversight and supply-chain risk. CSF 2.0 also broadens its audience beyond critical infrastructure and adds explicit profiles and tiers guidance. Lojycal's CSF view defaults to 2.0 and surfaces the Govern outcomes alongside the existing five functions.

Can I generate auditor evidence directly from Lojycal?

Yes. The Trust Center → Evidence Pack action bundles the selected control(s), the supporting WORM audit-log entries, the signed configuration snapshots and the period's incident records into a JSON + CSV + PDF bundle with a detached HMAC signature using a per-organisation signing key. Your auditor can verify the bundle independently — no shared screenshot folder, no 'send us a CSV by Friday' email.

Bring a little Lojyc to compliance.

One control library. One evidence stream. Every framework — ISO, NIST, SOC 2, DORA, NIS2, EU AI Act, GDPR, PCI — satisfied from the same source of truth.