OneCSF

Powered by ValueMentor

One control framework. Multiple compliance requirements.

Stop managing ISO 27001, SOC 2, PCI DSS, HITRUST and other compliance programs as separate projects. OneCSF maps overlapping requirements into a unified control framework so you can implement controls once, maintain evidence once and use the same security program across multiple compliance requirements.

Control libraryOne set of common controls
FrameworksMapped, not duplicated
EvidenceCollected once, reused
ReadinessContinuous, not pre-audit

The definition

What is OneCSF?

OneCSF is Secusy's unified control framework for managing requirements from multiple cybersecurity, privacy, governance and compliance frameworks through a common organizational control structure.
  • Common controls

    Manage the controls you actually operate, once.

  • Framework mapping

    Map each control to the requirements it supports.

  • Shared evidence

    Attach evidence to a control and reuse it across frameworks.

  • Gap visibility

    See what is covered and what still needs work.

Stop rebuilding your compliance program for every framework

Your organization may start with ISO 27001.

Then an enterprise customer asks for SOC 2.

A payment requirement introduces PCI DSS.

A healthcare customer asks about HITRUST.

New privacy, cybersecurity or AI governance requirements follow.

When each framework is managed separately, the same security activities are repeatedly documented, implemented, tested and evidenced. The result?

  • Duplicate controls
  • Repeated evidence requests
  • Multiple spreadsheets and trackers
  • Different owners for similar requirements
  • Conflicting remediation priorities
  • Higher compliance effort
  • More work every time a new framework is added

There is a better way.

Stop managing frameworks. Start managing controls.

Most cybersecurity and compliance standards are not completely independent of one another. Requirements around access control, vulnerability management, incident response, risk management, security awareness, logging, supplier security and other areas frequently address similar underlying security objectives.

OneCSF creates a common control layer between your organization and the frameworks you need to satisfy. Instead of asking “What do we need to do for ISO 27001?” and then “What do we need to do again for SOC 2?”, OneCSF helps you ask: “What security controls should we operate, and which requirements do those controls satisfy?”

That changes compliance from a collection of individual projects into a structured security program.

Frameworks you can bring in

  • ISO/IEC 27001
  • SOC 2
  • PCI DSS
  • HITRUST
  • HIPAA
  • NIST-based frameworks
  • AI governance requirements
  • Industry or regulatory frameworks supported within Secusy

How it works

How OneCSF works

  1. Step 1

    Select your frameworks

    Identify the cybersecurity, privacy, industry and governance frameworks relevant to your organization, such as ISO/IEC 27001, SOC 2, PCI DSS, HITRUST, HIPAA, NIST-based frameworks and AI governance requirements.

  2. Step 2

    Map requirements to common controls

    OneCSF identifies requirements that address the same or similar security objectives and maps them to a common control, so your team manages the underlying control centrally.

  3. Step 3

    Assign control ownership

    Define who is responsible for implementing, maintaining and evidencing each control, so your program is operational rather than a checklist.

  4. Step 4

    Implement and maintain evidence

    Attach policies, configurations, reports, screenshots and records to the underlying control. Relevant evidence can then support mapped requirements across multiple frameworks.

  5. Step 5

    Identify framework-specific gaps

    See where an existing control satisfies requirements and where additional framework-specific work is required. When you add a framework, see what is already covered before starting remediation.

  6. Step 6

    Maintain continuous readiness

    Track controls, evidence, risks, remediation and compliance status continuously rather than rebuilding the program immediately before an audit.

Implement once. Map many times.

Example: Vulnerability Management

Your organization operates a vulnerability management process. OneCSF treats that process as an organizational control, which can then be mapped against applicable vulnerability-management requirements across the frameworks you maintain.

  • ISO 27001 requirement

    Mapped from the Vulnerability Management control

  • SOC 2 criteria

    Mapped from the Vulnerability Management control

  • PCI DSS requirement

    Mapped from the Vulnerability Management control

  • HITRUST requirement

    Mapped from the Vulnerability Management control

  • Other applicable frameworks

    Mapped from the Vulnerability Management control

The exact requirements and evidence needed can still differ between frameworks. OneCSF helps you identify both the overlap and the remaining framework-specific obligations.

One compliance architecture for your organization

  • Unified control library

    Maintain the controls your organization actually operates rather than separate control lists for every framework.

  • Framework mapping

    Map common organizational controls against applicable requirements from multiple cybersecurity and compliance frameworks.

  • Evidence reuse

    Associate evidence with controls and make it available against relevant mapped requirements instead of repeatedly collecting the same evidence.

  • Control ownership

    Assign responsibility to people and teams so every control has clear accountability.

  • Gap management

    See which requirements are satisfied, partially addressed or still require additional work.

  • Remediation tracking

    Turn gaps into actions, assign owners and monitor progress from identification through resolution.

  • Risk integration

    Connect compliance requirements with your wider cyber risk program instead of managing compliance and risk separately.

  • Custom controls

    Extend the framework for organization-specific security requirements, contractual commitments or internal standards.

  • Continuous compliance

    Move from periodic audit preparation toward ongoing control and evidence management.

Need another compliance framework? Don't start from zero.

Suppose your organization has built its security program around ISO 27001 and a customer then asks for SOC 2. OneCSF helps distinguish between:

  • Already addressed

    Existing organizational controls map to the new requirement.

  • Partially addressed

    The underlying control exists but additional evidence, testing or implementation may be required.

  • New requirement

    Additional controls or activities are needed specifically for the new framework.

Your next compliance program can begin with your existing security posture rather than an empty checklist.

More than framework mapping

OneCSF sits inside the wider Secusy cybersecurity and compliance platform, so your compliance program can connect with related security activities.

  • Cyber Risk Management

    Track security risks and connect remediation with your control environment.

  • Vulnerability Management

    Bring identified vulnerabilities into your wider risk and compliance workflow.

  • Evidence Management

    Centralize supporting evidence and associate it with the relevant controls and requirements.

  • Compliance Management

    Track implementation and readiness across the frameworks relevant to your organization.

  • Security Documentation

    Manage the policies and procedures supporting your controls.

  • Audit Preparation

    Organize controls, evidence and outstanding actions before assessment.

Automate the workflows behind your controls with Secusy Compliance Automation.

Automatically collect and reuse evidence against your mapped controls.

Connect your controls to the cyber risks they are designed to reduce.

Operate vulnerability management as a common security control across multiple frameworks.

Prepare mapped controls and supporting evidence for assessment.

Connect your controls to the policies and procedures that define how they operate.

Combine OneCSF with an experienced vCISO

Technology can organize your cybersecurity program. Leadership determines what you should prioritize.

Secusy vCISO Services combine the OneCSF platform with experienced cybersecurity leadership from ValueMentor. Your vCISO can use OneCSF to help:

  • Establish your cybersecurity governance program
  • Prioritize security initiatives
  • Review cyber risks
  • Define and monitor security controls
  • Coordinate compliance programs
  • Track remediation
  • Prepare for customer and regulatory requirements
  • Build cybersecurity roadmaps
  • Report security posture to leadership

This gives growing organizations both the platform to manage cybersecurity and the expertise to decide what to do next.

Software when you want automation. Experts when you need help.

Traditional GRC platforms give you software. Traditional consulting engagements give you people. Secusy brings the two together.

  • One platform

    Manage controls, requirements, evidence, risks and remediation digitally.

  • One security program

    Build the organizational controls behind your compliance requirements instead of maintaining disconnected audit projects.

  • Expert support when needed

    Access ValueMentor cybersecurity specialists for implementation, advisory, assessment, testing and managed security requirements.

Powered by ValueMentor. Secusy is the digital sales and service-delivery platform for ValueMentor cybersecurity services. OneCSF combines Secusy's technology with the practical cybersecurity and compliance experience behind ValueMentor's advisory, assurance, security testing and managed security services.

Built for organizations managing growing security requirements

  • Startups

    Establish a security foundation once and reuse it as enterprise customers begin requesting different certifications and assurance reports.

  • SaaS & technology companies

    Manage overlapping customer, security, privacy and compliance requirements without creating independent programs for each.

  • Mid-market organizations

    Bring multiple compliance initiatives into one governance structure and give management clearer visibility into security priorities.

  • Regulated businesses

    Connect regulatory and industry requirements with the cybersecurity controls already operating across the organization.

  • Security & compliance teams

    Reduce duplicate administration and spend more time improving the underlying security program.

One source of truth for your compliance program

Without OneCSF

Framework A → Controls → Evidence → Tracker

Framework B → Controls → Evidence → Tracker

Framework C → Controls → Evidence → Tracker

Framework D → Controls → Evidence → Tracker

With OneCSF

Frameworks A, B, C, D → OneCSF → Common Controls → Evidence → Risks → Remediation

Add another framework without rebuilding the entire compliance program.

Questions

Frequently asked questions

Learn about vCISO Services → · Explore the Secusy cybersecurity platform.

Build the security program once. Use it across your compliance journey.

Stop running every certification, customer request and regulatory requirement as a separate project. Use OneCSF to create a common control environment, maintain evidence centrally and understand what changes when your next compliance requirement arrives.

OneCSF by Secusy — Powered by ValueMentor.