Framework crosswalk
Sekit CSFISO/IEC 27001:2022
Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Frameworks
Family
Lens
The company formally assesses privacy risks before starting new data processing activities
Assessing privacy risk before new processing begins is one specific legal obligation, under data protection law, that this control's broader tracking should capture.
A written commitment to assess privacy risk before new processing begins covers the DPIA trigger piece of this control, not the full range of PII protections A.5.34 requires, such as consent, transfers or rights handling.