Use when asked to map, crosswalk, align, compare, or gap-analyze any two cybersecurity frameworks, control catalogs, or regulatory requirements using NIST IR 8477 Set-Theory Relationship Mapping (STRM). Triggers on terms like "map controls", "crosswalk", "framework alignment", "gap analysis", or producing a STRM CSV output file.
Installation
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Use when asked to map, crosswalk, align, compare, or gap-analyze any two cybersecurity frameworks, control catalogs, or regulatory requirements using NIST IR 8477 Set-Theory Relationship Mapping (STRM). Triggers on terms like "map controls", "crosswalk", "framework alignment", "gap analysis", or producing a STRM CSV output file.
license
Apache-2.0
compatibility
Designed for Qoder. Also compatible with any Agent Skills-compatible assistant. Run Qoder from the repository root so relative paths resolve correctly.
metadata
{"author":"austinsonger","version":"2.0.0","methodology":"NIST IR 8477","standard":"agentskills.io"}
NIST IR 8477 STRM Mapping — GRC Toolkit Skill
When to Activate
Activate this skill whenever the user asks to:
Map, crosswalk, align, or compare any two frameworks, catalogs, or control sets
Create a STRM CSV output file between any two documents
Perform a gap analysis between any source and target document
Extend or verify an existing STRM mapping file
Working Directory
All work must be performed inside the working-directory/ folder at the repository root.
Open Qoder from the repository root so relative paths resolve correctly.
Read input files from working-directory/, knowledge/, or examples/
Write all in-progress and output files to working-directory/
Never write output to the repo root or any other location
Saving Completed Mappings
When a mapping is fully complete, create a dated artifact folder:
medium for ambiguity; low for significant inference
NIST IR-8477 Rational
semantic
functional for same outcome via different mechanisms. When mapping across different regulatory domains (for example healthcare → law enforcement, financial → defense), default to functional unless control wording and scope are substantially identical. Use syntactic only for word-for-word similarity (<1%).
4. Write the Output CSV
File Naming Convention
Set Theory Relationship Mapping (STRM)_ [(<Focal>-to-<Bridge>)-to-<Target>] - <Focal> to <Target>.csv
For direct mappings, repeat the focal name as bridge.
CSV Structure
Copy TEMPLATE_Set Theory Relationship Mapping (STRM).csv and add data from Row 2:
Row 1: FDE#,FDE Name,Focal Document Element (FDE),Confidence Levels,NIST IR-8477 Rational,STRM Rationale,STRM Relationship,Strength of Relationship,<Target> Requirement Title,Target ID #,<Target> Requirement Description,Notes
Row 2+: <data rows>
Column definitions:
Col
Header
Content
A
FDE#
Source control ID
B
FDE Name
Short label for the source control
C
Focal Document Element (FDE)
Full source control text
D
Confidence Levels
high / medium / low
E
NIST IR-8477 Rational
semantic / functional / syntactic
F
STRM Rationale
Narrative explaining both controls and the relationship