Skip to content

The control mapping, stated exactly

The twelve frameworks people ask us about, and a plain answer for each one: what TabTotal does for it, and where the claim stops.

Your audit trail writes itself while you work.

Verifiable by your auditor

Governed changes land in a hash-chained ledger using plain SHA-256 with no secret key, so your auditor can re-verify its integrity from the export with their own tools.

What a mapping is, and what it is not

A control mapping says which control a given check relates to. A certification says an independent auditor examined a system against a standard and issued an opinion. They are different things, and only one of them is on this page.

Boreon holds no audited certification of its own. There is no SOC 2 report and no ISO 27001 certificate for this product, and if a page on this website ever implies otherwise, that page is wrong. What the product does hold is a deterministic control reference on the findings one application raises, an audit trail your own auditor can re-verify, and a habit of tracing every claim back to the code that produces it.

You are reading this on the vendor’s own website. Treat it as a starting point and check it. Every claim below names the surface that produces it.

The frameworks people ask us about

Named the way their publishers name them, because a control reference nobody can look up is a control reference nobody can use.

  • CIS Controls v8.1
  • NIST CSF 2.0
  • SOC 2
  • ISO 27001
  • HIPAA
  • GDPR
  • PCI DSS
  • CCPA
  • NIST 800-53
  • FINMA
  • nLPD/revDSG
  • DORA

Which ones a shipped check carries

Two of them arrive with the control reference already stamped on the finding. The rest are frameworks the product helps you evidence, and a person still does the mapping.

Each framework, what TabTotal does for it, and where the claim stops
What TabTotal doesWhere the claim stops
CIS Controls v8.1Stamped by a shipped checkCenter for Internet SecurityEvery finding Guard raises carries a Safeguard ID. A fixed table stamps it the same way every time, before any model takes part. The ID rides with the finding into the CSV, the SARIF, the PDF and the screen.Four safeguards are in use today. They cover credentials in content and injectable query text. This maps the checks that ship. It is not a coverage claim over the whole catalogue. CIS Benchmarks are a separate CIS publication of secure setup baselines. This maps nothing to them.
NIST CSF 2.0Stamped by a shipped checkNISTThe same finding carries its CSF function, from the same fixed table. Your security team gets the control reference already attached. It arrives in a format their own software reads.The functions in use are Identify, Protect and Detect. Govern, Respond and Recover cover work that happens around the product. No finding claims them.
SOC 2Evidence you mapAICPAYou get the change approval, the person who gave it, and a hash-chained record of both, made as you work. A common-criteria walkthrough asks for exactly this.Boreon holds no SOC 2 report of its own. Your own auditor issues your own report, about your own controls.
ISO 27001Evidence you mapISO and IECThe product produces access review, credential handling and a record of admin change. Each one exports.Boreon holds no ISO 27001 certificate of its own. This page says nothing about your own certification scope.
HIPAAEvidence you mapUS Department of Health and Human ServicesRisk finds protected health identifiers inside published content and reports where they sit. Provider identifiers are checked by their real check digit, not by a pattern that looks right.Detection tells you where the data is. Whether a use is allowed is a judgement about your organisation. The product makes none.
GDPREvidence you mapEuropean UnionPersonal data in published content is found, and ownership is resolved. Lineage answers where a field came from. That is the question a record of processing keeps asking.A register of processing is a document your organisation keeps. The product supplies the findings for it. You write the register itself.
PCI DSSEvidence you mapPCI Security Standards CouncilCard numbers in content are found and checked with the real Luhn check. A report names candidates that pass it, not any sixteen digits in a row.Scope, segmentation and the assessment itself belong to your qualified assessor.
CCPAEvidence you mapState of CaliforniaThe same detection and ownership surfaces show which published content holds personal information. They also name who is responsible for it.Your organisation answers consumer requests. The product helps you find the data, and you send the reply.
NIST 800-53Evidence you mapNISTAudit records, access enforcement and configuration change all come out as evidence you can export. A control owner can attach it to a body of evidence.Today the stamped control references are CIS Controls v8.1 and NIST CSF 2.0. Identifiers from this catalogue are not stamped on any output.
FINMAEvidence you mapSwiss Financial Market Supervisory AuthorityAccess management and the record of who changed what are the operational-risk artefacts asked for most. Both are made as you work, not assembled before a review.What your regulator expects applies to your institution. Where you choose to host is a fact about where data sits. It carries no regulatory approval.
nLPD/revDSGEvidence you mapSwitzerlandPersonal data is found in published content. On the hosted edition, processing stays inside the single deployment that serves you. The sub-processor list is published, not described.Your own processing register and your own transparency notices remain yours to write.
DORAEvidence you mapEuropean UnionField level lineage answers what a change will hit, before it is made. The migration and approval trails record ICT change the way a dependency review reads it.Register of information, incident classification and testing programmes sit with your institution.

What the product hands your auditor

Evidence produced while the work happens, not assembled the week before a review.

A finding with its control already attached

Guard raises a finding. A fixed table tags it with a Safeguard ID and a CSF function. It exports as CSV, as SARIF for the software your security team already runs, and as a PDF for people who will never open a SARIF file.

A record you can prove is intact

Governed changes land in a hash-chained ledger. It uses plain SHA-256 with no secret key, so your auditor can re-check the export with their own tools.

An approval, with the person who gave it

A change is applied only after somebody approves the plan. The record holds the approval, what was proposed, and when.

The dependency answer, at field level

From dashboard to field to column to warehouse table. A change review asks where a change will land, and the answer is read, not rebuilt.

Where the personal data is

Detection runs across published content. Identifiers are checked by their real check digit. A report names the candidates worth reviewing.

Who could reach it, resolved

The effective permission, worked out and not inferred from the rules behind it. Beside it sits the gap between what a group should hold and what it holds.

Questions an auditor asks first

Do you hold a SOC 2 report or an ISO 27001 certificate for this product?

Boreon holds no audited certification of its own. What we do hold is a control mapping on shipped checks, a hash-chained audit trail, and a security page whose claims are each traceable to the code behind them.

Is a control mapping the same thing as a certification?

They differ. A mapping says which control a given check relates to. A certification says an outside auditor examined a system against a standard and gave an opinion. We publish the first and claim nothing about the second.

Can I hand a Guard finding straight to my auditor?

Yes. The Safeguard ID and the CSF function are stamped on the finding before it leaves the product. The CSV, the SARIF and the PDF all carry the reference. Your auditor gets a finding with a control already on it.

Where does the mapping come from, and can I see it?

From a fixed table shipped as data in the scanner. The same rule always gives the same control reference, and no model helps choose it. Ask us, and we will show you the file.

Is your hosting certified?

Whichever provider hosts the deployment publishes its own certifications for the facilities it runs. Those are theirs rather than ours. Ask us for the current scope, and we will point you at their own published statement.

What happens when a framework changes?

The mapping table moves with the product. This page names the version it maps against. When a control reference changes, the change lands in a release.

Take the mapping to your security team

Every claim on this page names the surface that produces it, and we will happily show you the file.