skip to content

Control to Check

A control is a sentence about intent, and the gap between that sentence and something a machine can fail is where the work lives. Interviewers start here because candidates jump straight to the rule.

on this pageshow

explore

questions

12

Why map one TLS-minimum check to clauses in three compliance frameworks instead of writing three checks?

level: juniorimportance: must knowfreq 62%

answer

  1. one fact, three reports
  2. assertion versus compliance claim
  3. the mapping is data, not code
  4. duplicate rules drift apart
  5. one failure fans out to three findings

basics

~10 s

The check is the same engineering fact; only the reporting differs. One check with three mapping edges means one rule to maintain and three audit reports that can never disagree about the same listener.

solid answer

~50 s

A crosswalk separates the technical assertion from the compliance claim. The assertion — every externally reachable listener negotiates TLS 1.2 or higher — is one rule producing one result set. The crosswalk is a mapping that says this result answers a NIST SP 800-53 transmission-protection control, a SOC 2 common criterion in the CC6 logical-access series, and PCI DSS Requirement 4 on protecting cardholder data in transit over open, public networks. Three separate copies of the rule drift: someone tightens the cipher list in the PCI copy and not the others, and two reports quietly disagree about the same host. The mapping also works in the failing direction — one failed listener fans out into three findings, in three reports, with three different remediation deadlines. And because the mapping is data rather than code, adding a fourth framework is a new edge, not a new scanner.

go deeper

for a junior

Be ready to state the difference between the technical assertion a check evaluates and the framework clause it is claimed to answer, and to say that a crosswalk is the mapping between them.

for a middle

Explain the mechanics of the duplication failure: how copied rules drift after the first fix, and how a single failed resource fans out into several findings with different remediation clocks.

for a senior

Show you have operated this. Talk about edges carrying conditions — one framework's clause applying only to a subset of listeners — and about the crosswalk changing reporting rather than enforcement.

for a principal

Own the argument that the mapping is data with an owner, so a new customer framework is a set of rows rather than a new scanning programme. Be able to say what that decision costs when a mapping is wrong.

## Two different objects A compliance framework clause and a policy check are not the same kind of thing, and a crosswalk exists because of that gap. - **The assertion** is engineering: *every externally reachable listener negotiates TLS 1.2 or higher*. It is evaluable. It runs on a schedule, it looks at a concrete set of resources, and it returns pass or fail per resource with a timestamp. - **The claim** is compliance: *we protect data in transit*. It is a sentence written by a standards body for thousands of organisations, and it deliberately does not name your load balancers. A crosswalk is the mapping between the two: a table of edges, each saying "this check's result is part of the answer to that clause of that framework at that revision". ## The worked case One TLS-minimum check plausibly touches three frameworks at once: | Framework | What the edge says | |---|---| | NIST SP 800-53 | Answers the transmission confidentiality and integrity control for the components in the mapping's scope | | SOC 2 | Supports a common criterion in the CC6 logical-access series, as tested against your own stated policy | | PCI DSS | Answers Requirement 4, protecting cardholder data with strong cryptography in transit over open, public networks | Note what is already visible here: the three edges are not identical. The PCI edge carries a condition — it only speaks to listeners inside the cardholder-data environment reachable from a public network. The SOC 2 edge is tested against what your own policy document says you do. So even the "one check answers three clauses" case is really "one result, three edges, each with its own qualifier". Recording those qualifiers is the whole craft. ## Why not three checks The obvious alternative is to let each compliance workstream own its own rule. It fails in four predictable ways. 1. **Drift.** The copies start identical and diverge on the first fix. A cipher suite gets banned in one copy after an incident; the others still pass. Now two reports about the same host disagree, and nobody can say which is right without reading three rule bodies. 2. **Cost of the estate.** Three rules is three sets of false positives, three exception lists, three sets of people to argue with, and three things to update when TLS 1.2 stops being an acceptable floor. 3. **Incoherent evidence.** An auditor who sees two results for one listener does not conclude that one report is stale; they conclude the control is not operating reliably. The point of a control is that it works the same way every time. 4. **Frameworks multiply.** A customer contract adds a fourth framework. With a crosswalk that is a handful of new rows written by the control owner. With copied rules it is another scanner configuration to build, run and keep green. ## What a crosswalk changes and what it does not It changes **reporting**, not enforcement. The mapping never blocks a deployment, never mutates a resource, never gates a pipeline. It decides which report a failure appears in and under which heading. If you removed the crosswalk entirely, exactly the same listeners would pass and fail; you would simply be unable to say which audit cares. It also does not, on its own, prove the control. A passing check proves the assertion held on the resources it looked at, at the times it ran. Most clauses want more than that: a documented standard saying TLS 1.2 is the floor, a record that the check ran continuously, and a story about what happened when it failed. The crosswalk edge is the pointer that connects those pieces to the clause; it is not the evidence. ## What good looks like in an interview Say the assertion out loud, separately from the clause. Then describe the mapping as data with an owner, kept next to the rule and reviewed when it changes. Then mention the failure direction — that one failed resource means three findings, and that the frameworks may impose different remediation clocks on the same fix, which is a real operational consequence of the mapping and the first thing a control owner notices in practice.

  • What breaks first when each compliance workstream keeps its own copy of the same check?
    The copies diverge on the first fix. Someone tightens the cipher list in one copy after an incident and leaves the others alone, so two reports now disagree about the same listener. An auditor reading both does not assume one is stale — they conclude the control does not operate consistently, which is a worse finding than the original gap.
  • Does a passing check ever fully satisfy a framework clause by itself?
    Rarely. The check proves the assertion held on the resources it examined, at the times it ran. Clauses usually also want a documented standard that fixes the threshold, and confidence the check ran continuously rather than once before the audit. The crosswalk edge points at those pieces; it does not replace them.

One thermometer, three forms. The temperature is measured once; the school, the airline and the clinic each have their own box to copy it into, with their own rules about what counts as too high.

saying these in an interview costs you the question

  • Treats the three frameworks' clauses as identical requirements
  • Copies the rule per framework and calls that coverage
  • Says a passing check proves the control rather than the assertion
  • Thinks the crosswalk enforces or blocks something
  • Forgets that one failure now opens three findings

context

open as a page

What does it mean to decompose a compliance control into automated checks?

level: juniorimportance: must knowfreq 66%

basics

~20 s

Decomposition turns one control sentence into the separate facts a machine can test. "Audit logging enabled and retained 365 days" becomes distinct checks: a log destination exists, retention is at least 365, tamper-evidence is on, delivery still succeeds.

open as a page

A control report says 98% of database instances are encrypted at rest — what does that number hide?

level: juniorimportance: must knowfreq 63%

basics

~20 s

A pass rate hides its denominator. The 98% counts only instances the check actually enumerated; anything in an account, region or project the tooling never reached sits outside both numbers, so unseen systems are invisible rather than failing.

open as a page

Three of five assertions for an audit-logging control are automated — do you mark it green?

level: seniorimportance: must knowfreq 54%

basics

~20 s

No. Report status per assertion, not per control, and mark the control partially covered. Green on a control whose automation touches three of five assertions tells every reader that all five were tested, which is a claim your evidence does not support.

open as a page

What belongs in a machine-readable crosswalk mapping one check to clauses in several frameworks?

level: middleimportance: should knowfreq 47%

basics

~10 s

Per framework: the catalog revision being mapped against, the clause identifier, the check that answers it, how strongly it answers it, and an owner. OSCAL expresses this as one control-implementation block per framework.

open as a page

A control requires annual security-awareness training — how do you handle a control with no machine check?

level: middleimportance: should knowfreq 45%

basics

~20 s

Say so explicitly. Training and background checks decompose to evidence collection, not a pass-or-fail rule: automate gathering dated records, then have a named owner attest the control. Never invent a proxy rule to make the dashboard green.

open as a page

How do you build the applicability set for an encryption-at-rest control across cloud accounts?

level: middleimportance: should knowfreq 54%

basics

~20 s

Enumerate from an authoritative source that owns the whole estate — the organisation's account directory, then each account's own resource listing — never from the checking tool's own findings. Reconcile against the asset inventory and treat every discrepancy as a finding.

open as a page

How do you record a key-rotation check that fully satisfies one framework's clause but only partly another?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Give every mapping edge an explicit strength, and on anything less than full, name the remainder: what else must be true and which artifact carries it. Partial edges must render as partial, never as a green tick.

open as a page

How do you detect production systems that no asset inventory or account list knows about?

level: seniorimportance: should knowfreq 43%

basics

~20 s

Not by scanning the inventory: a system missing from it is invisible to it. Enumerate instead from sources every workload touches anyway — billing, identity, DNS, egress — and treat anything present there but absent from your registered estate as a finding.

open as a page

How does a control crosswalk survive a framework revision that splits or withdraws control ids?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Treat a revision as a migration, not a find-and-replace. Load the new catalog alongside the old, diff the identifier sets, re-decide every affected edge by hand, and keep the old mapping intact for audits still running against the old revision.

open as a page

With hundreds of framework controls and one engineer-quarter, how do you choose which get automated checks?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Prioritise by how silently a control's state drifts and how much evidence toil it costs each cycle, not by how easy the check is. Controls the provider satisfies need a citation, and process controls need an attestation; neither deserves engineering time.

open as a page

Your encryption-at-rest control passes on 92% of the 60% of systems you can assess — how do you report it?

level: principalimportance: nice to knowfreq 36%

basics

~20 s

Report both numbers separately, never their product and never the flattering one alone: coverage of the estate, and pass rate within that coverage. Name what is unassessed and who owns closing it, with a dated plan to raise coverage first.

open as a page