CyberTrustWorks — One Platform. Total Trust.

Fussion_GRC frameworks

One control. Multiple frameworks.

Define a control once, map it to every framework that requires it, and collect evidence a single time.

Supported frameworks

Frameworks you can map to

ISO 27001

Information security management system controls and Statement of Applicability.

SOC 2

Trust Services Criteria for security, availability and confidentiality.

NIST CSF

Govern, Identify, Protect, Detect, Respond and Recover functions.

PCI DSS

Requirements for environments that store, process or transmit card data.

DPDP

India's Digital Personal Data Protection Act obligations.

RBI

Reserve Bank of India cyber security directions for regulated entities.

SEBI

SEBI cybersecurity and cyber resilience framework for market entities.

CERT-In

Incident reporting and logging directions.

Custom frameworks

Internal policies, customer contracts or group standards.

How mapping works

Reusable controls, cross-framework evidence

  • 1. A control such as "quarterly privileged access review" is defined once with an owner and frequency.
  • 2. It is mapped to the matching requirement in each framework you follow.
  • 3. Evidence collected for that control counts towards every mapped requirement.
  • 4. Gaps per framework show where a requirement has no mapped control or fresh evidence.

2026 research

Download the 2026 CISO Security Governance Report

See how security leaders are connecting risk, compliance, vulnerabilities, identity, third-party risk and evidence into one operating model.

Get the CISO Report