TrustSecurity frameworks

Security frameworks

Map your controls to industry frameworks using this template.

Framework overview

SOC 2

  • Coverage: Security, Availability, Confidentiality.
  • Status: Certified
  • Notes: Bridge letter available for periods between audits.

ISO 27001

  • Coverage: Annex A controls mapped to internal policies.
  • Status: In progress
  • Notes: Certification target: Q1 2026 with quarterly readiness checkpoints.

GDPR

  • Coverage: Lawful bases documented per processing activity.
  • Status: Certified
  • Notes: Data Protection Impact Assessments (DPIAs) required for new high-risk features.

NIST CSF

  • Coverage: Identify, Protect, Detect, Respond, Recover functions.
  • Status: Certified
  • Notes: Regular updates and reviews.

Mapping table (optional)

Function / control familyKey activitiesSource doc
IdentifyAsset inventory, risk assessmentsSecurity governance
ProtectAccess controls, encryption, secure SDLCSecurity policies
DetectLogging, anomaly detection, alertingMonitoring plan
RespondIncident response playbooks, communicationIR plan
RecoverBackup testing, post-incident reviewsBusiness continuity plan

Last reviewed: Security governance · 2025-09-10