Common controls
Manage the controls you actually operate, once.
OneCSF
Powered by ValueMentor
Stop managing ISO 27001, SOC 2, PCI DSS, HITRUST and other compliance programs as separate projects. OneCSF maps overlapping requirements into a unified control framework so you can implement controls once, maintain evidence once and use the same security program across multiple compliance requirements.
The definition
Manage the controls you actually operate, once.
Map each control to the requirements it supports.
Attach evidence to a control and reuse it across frameworks.
See what is covered and what still needs work.
Your organization may start with ISO 27001.
Then an enterprise customer asks for SOC 2.
A payment requirement introduces PCI DSS.
A healthcare customer asks about HITRUST.
New privacy, cybersecurity or AI governance requirements follow.
When each framework is managed separately, the same security activities are repeatedly documented, implemented, tested and evidenced. The result?
There is a better way.
Most cybersecurity and compliance standards are not completely independent of one another. Requirements around access control, vulnerability management, incident response, risk management, security awareness, logging, supplier security and other areas frequently address similar underlying security objectives.
OneCSF creates a common control layer between your organization and the frameworks you need to satisfy. Instead of asking “What do we need to do for ISO 27001?” and then “What do we need to do again for SOC 2?”, OneCSF helps you ask: “What security controls should we operate, and which requirements do those controls satisfy?”
That changes compliance from a collection of individual projects into a structured security program.
Frameworks you can bring in
How it works
Identify the cybersecurity, privacy, industry and governance frameworks relevant to your organization, such as ISO/IEC 27001, SOC 2, PCI DSS, HITRUST, HIPAA, NIST-based frameworks and AI governance requirements.
OneCSF identifies requirements that address the same or similar security objectives and maps them to a common control, so your team manages the underlying control centrally.
Define who is responsible for implementing, maintaining and evidencing each control, so your program is operational rather than a checklist.
Attach policies, configurations, reports, screenshots and records to the underlying control. Relevant evidence can then support mapped requirements across multiple frameworks.
See where an existing control satisfies requirements and where additional framework-specific work is required. When you add a framework, see what is already covered before starting remediation.
Track controls, evidence, risks, remediation and compliance status continuously rather than rebuilding the program immediately before an audit.
Implement once. Map many times.
Your organization operates a vulnerability management process. OneCSF treats that process as an organizational control, which can then be mapped against applicable vulnerability-management requirements across the frameworks you maintain.
Mapped from the Vulnerability Management control
Mapped from the Vulnerability Management control
Mapped from the Vulnerability Management control
Mapped from the Vulnerability Management control
Mapped from the Vulnerability Management control
The exact requirements and evidence needed can still differ between frameworks. OneCSF helps you identify both the overlap and the remaining framework-specific obligations.
Maintain the controls your organization actually operates rather than separate control lists for every framework.
Map common organizational controls against applicable requirements from multiple cybersecurity and compliance frameworks.
Associate evidence with controls and make it available against relevant mapped requirements instead of repeatedly collecting the same evidence.
Assign responsibility to people and teams so every control has clear accountability.
See which requirements are satisfied, partially addressed or still require additional work.
Turn gaps into actions, assign owners and monitor progress from identification through resolution.
Connect compliance requirements with your wider cyber risk program instead of managing compliance and risk separately.
Extend the framework for organization-specific security requirements, contractual commitments or internal standards.
Move from periodic audit preparation toward ongoing control and evidence management.
Suppose your organization has built its security program around ISO 27001 and a customer then asks for SOC 2. OneCSF helps distinguish between:
Existing organizational controls map to the new requirement.
The underlying control exists but additional evidence, testing or implementation may be required.
Additional controls or activities are needed specifically for the new framework.
Your next compliance program can begin with your existing security posture rather than an empty checklist.
OneCSF sits inside the wider Secusy cybersecurity and compliance platform, so your compliance program can connect with related security activities.
Track security risks and connect remediation with your control environment.
Bring identified vulnerabilities into your wider risk and compliance workflow.
Centralize supporting evidence and associate it with the relevant controls and requirements.
Track implementation and readiness across the frameworks relevant to your organization.
Manage the policies and procedures supporting your controls.
Organize controls, evidence and outstanding actions before assessment.
Automate the workflows behind your controls with Secusy Compliance Automation.
Automatically collect and reuse evidence against your mapped controls.
Connect your controls to the cyber risks they are designed to reduce.
Operate vulnerability management as a common security control across multiple frameworks.
Prepare mapped controls and supporting evidence for assessment.
Connect your controls to the policies and procedures that define how they operate.
Technology can organize your cybersecurity program. Leadership determines what you should prioritize.
Secusy vCISO Services combine the OneCSF platform with experienced cybersecurity leadership from ValueMentor. Your vCISO can use OneCSF to help:
This gives growing organizations both the platform to manage cybersecurity and the expertise to decide what to do next.
Finding a compliance gap is only useful if you know how to close it. If OneCSF identifies additional requirements, you can access related services delivered by ValueMentor through Secusy.
Build and prepare your information security management system for independent ISO/IEC 27001 certification.
Learn morePrepare your controls and evidence for a SOC 2 Type I report.
Learn morePrepare your controls and evidence for a SOC 2 Type II report.
Learn moreAssess and validate applicable PCI DSS requirements with ValueMentor's PCI expertise.
Learn moreSelf-assessment support for merchants who fully outsource cardholder-data handling.
Learn morePrepare for HITRUST assessment with ValueMentor, an Authorized HITRUST External Assessor.
Learn morePrepare for HITRUST i1 assessment with ValueMentor.
Learn moreAdd ongoing cybersecurity leadership to build and operate the security program behind your compliance requirements.
Learn moreTraditional GRC platforms give you software. Traditional consulting engagements give you people. Secusy brings the two together.
Manage controls, requirements, evidence, risks and remediation digitally.
Build the organizational controls behind your compliance requirements instead of maintaining disconnected audit projects.
Access ValueMentor cybersecurity specialists for implementation, advisory, assessment, testing and managed security requirements.
Powered by ValueMentor. Secusy is the digital sales and service-delivery platform for ValueMentor cybersecurity services. OneCSF combines Secusy's technology with the practical cybersecurity and compliance experience behind ValueMentor's advisory, assurance, security testing and managed security services.
Establish a security foundation once and reuse it as enterprise customers begin requesting different certifications and assurance reports.
Manage overlapping customer, security, privacy and compliance requirements without creating independent programs for each.
Bring multiple compliance initiatives into one governance structure and give management clearer visibility into security priorities.
Connect regulatory and industry requirements with the cybersecurity controls already operating across the organization.
Reduce duplicate administration and spend more time improving the underlying security program.
Without OneCSF
Framework A → Controls → Evidence → Tracker
Framework B → Controls → Evidence → Tracker
Framework C → Controls → Evidence → Tracker
Framework D → Controls → Evidence → Tracker
With OneCSF
Frameworks A, B, C, D → OneCSF → Common Controls → Evidence → Risks → Remediation
Add another framework without rebuilding the entire compliance program.
Questions
Learn about vCISO Services → · Explore the Secusy cybersecurity platform.
Stop running every certification, customer request and regulatory requirement as a separate project. Use OneCSF to create a common control environment, maintain evidence centrally and understand what changes when your next compliance requirement arrives.
OneCSF by Secusy — Powered by ValueMentor.