WEEK 12
Governance & Standards Crosswalk
Operational scenario
The board asks: 'Are we NIST or ISO?' Build the crosswalk that shows it's the same control in different words.
Week completion
0%
~11.5 hours this week
Assessment: Knowledge check 11; acronym quiz 6
Deliverable: Control crosswalk artifact
Learning objectives
- Interpret and compare NIST, ISO, CIS and ISA/IEC 62443
- Build a control crosswalk
Classroom topics
- CSF 2.0 & RMF
- SP 800-53/61/82/171
- ISO 27001/27002/22301/31000
- ISA/IEC 62443
- SOC 2, PCI DSS, HIPAA, NERC CIP intro
- Framework ≠ compliance
Standards · vocabulary
NIST CSF 2.0ISO 27001:2022CIS v8.1ISA/IEC 62443
RMFSOC 2PCI DSSNERC CIP
Open glossaryCompetency demonstrated: Applies and compares governance frameworks.
Four-mode learning matrix
Physical hands-on lab
None (documentation week).
~2 h
Docker container lab
Lab 14 — Test approved firewall / access-control rules.
~0.5 h
AR/VR immersive scenario
Create 62443 zones and conduits; navigate the Purdue Model. Role: Governance and compliance analyst.
No headset? Desktop crosswalk + zone template. Printed and mobile versions are also available.
Individual technical assignment
Crosswalk five controls across the frameworks.
Team exercise
Compare two frameworks and brief the trade-offs.
Required hardware
- Workstation
Required software
- Crosswalk template
- Docker
Workplace application
GRC analysts build crosswalks so one control satisfies several audits.
Docker progression step
L14 Testing approved firewall and access-control rules
Open the Docker rangeTest each ACL rule for allow and deny; record the evidence pair.
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Governance & risk oversightRisk assessmentNetwork security & segmentation
See the full crosswalkReflection & rubric for week 12 Modes tracked: 0/5