Mapping principles
Rule 1
Use the current authoritative publisher page where possible and record whether the referenced publication is final, draft or a living resource.
Rule 2
Map only to a documented Cybatar capability, record or workflow. Do not map aspirational or unimplemented functionality.
Rule 3
Prefer high-level operating outcomes over invented control-level equivalence when the external framework does not provide an official product mapping.
Rule 4
Keep dependencies beside the mapping: source coverage, configuration, ownership, specialist controls, legal requirements and human judgement still matter.
Rule 5
Treat platform evidence as evidence of recorded activity, not automatic evidence of effectiveness, compliance or risk reduction.
Rule 6
Separate first-party Cybatar interpretation from the external publisher’s own words and link readers to the authoritative source.
Rule 7
Review mappings when the external framework, public Cybatar capability model or relevant product evidence changes.