Library

From a pile of standards to one library that tells you what is still missing.

More than 60 frameworks and 25 laws with their articles, cross-referenced at the level of the individual control. Pick the framework you need to meet and see per requirement what you already cover. Load your own standard and let the library compare it with a recognised one. Built and hosted in the EU.

From a stack of PDFs to substantiated coverage

ISO 27001, NIS2, DORA, GDPR: every framework arrives as its own document with its own numbering. The question that matters is how much of framework B you already have with framework A, and where the gap is.

Now

Every framework in its own PDF

Controls, domains and versions sit in separate documents. Every comparison starts from zero.

With Library

One catalogue with the controls included

Per framework the controls with description and testing approach, the domain structure, the version history and a frozen version an audit can refer to.

Now

Double work for a second standard

An organisation with ISO 27001 starts again for NIS2 or DORA, although much of it is already in place.

With Library

Matrix: what do you already meet?

Choose the framework you need to meet and the frameworks you have. Per requirement you see the best matching control with a coverage percentage and the analysis behind it.

Now

An internal policy fits no package

Your own standard, a client standard or a sector agreement stays outside every comparison.

With Library

Your own framework in the library

Load your own framework, visible only to your organisation, and request a cross-reference against a library framework. The result states per criterion what is covered and what is missing.

Now

A percentage without reasoning

A mapping sheet says 60% without saying why. The debate returns at every audit.

With Library

Every number shows where it comes from

A cell shows whether coverage comes from a direct analysis of the pair or from a rougher estimate, and unfolds into the sub-requirements with what is covered and what is not.

Now

An empty risk register at the start

A new organisation or a new domain begins with an empty table and a workshop.

With Library

Starter sets per sector

Processes, risks and controls for, say, a municipality or a housing association, taken over into the Risk Heat Map with a single confirmation.

A selection from Library

Click a thumbnail for that screen, or the image itself for the full-size view.

Nl ex kader en1 / 6 shown

What you want to know about Library up front

What is Library?

Library is the standards library of the Audirium suite: more than 60 frameworks and 25 laws with their articles, cross-referenced at control level. The application shows the controls per framework, puts frameworks side by side to calculate coverage, holds an organisation's own frameworks and provides starter sets for a new risk register.

Who is Library for?

For security officers, compliance officers, auditors and advisers who work with more than one framework. An organisation that has implemented ISO 27001 and needs to meet NIS2 or DORA sees per requirement what is already covered. Organisations with their own standard or a client standard load it and compare it with a recognised one. The catalogue is readable by every user with access.

What does Library do in practice?

Library shows per framework the controls with description and testing approach, searches literally or by meaning across frameworks, controls and legal articles, calculates in Matrix and Coverage per requirement how much another framework already covers, holds your own frameworks with a cross-reference against the library, and offers starter sets with risks and controls that the Risk Heat Map adopts.

How does Library differ from a mapping sheet?

A mapping sheet gives a percentage. Library adds the reasoning: per control pair an analysis of what covers what and what does not, broken down into sub-requirements, and for every cell whether the number comes from a direct analysis or an estimate. Frameworks have frozen versions an audit can refer to, and the cockpit reports which frameworks or links still lack substantiation.

How does AI work in Library and who decides?

AI does three things: semantic search, the analysis of cross-references between controls, and a proposal for an adapted control where your own framework has a gap. Every analysis and proposal is marked as such, with provenance and timestamp. Adopting, confirming or rejecting is done by an editor or administrator of your organisation; AI writes nothing into your framework by itself.

How are data and hosting handled?

The library itself is the same for every organisation and contains no organisational data. Your own frameworks are stored separately per organisation and are visible to that organisation only. Everything is hosted on servers in the EU. Texts from copyrighted frameworks such as ISO appear as a standard number or our own description, never as the source text.

One source for standards, laws and the links between them

The library is the same for every organisation and is maintained centrally. CRAFT and the other applications of the suite read from it, so a framework means the same thing everywhere.

AI built in, not bolted on

Semantic search, the analysis of cross-references and a proposal for an adapted control come from AI. Every proposal carries its provenance, and an editor decides whether it is adopted.

More than 60 frameworks

ISO 27001, NIS2, DORA, GDPR, the EU AI Act and the IIA Topical Requirements, with their controls. Per framework you see how many controls carry a translation.

The law behind the requirement

25 laws with their articles, linked to the controls that follow from them. Search literally or by meaning across frameworks, controls and legal articles at once.

Cross-references on two levels

Level 1 says that two standards touch, through a shared unified control. Level 2 says why and how far, per control pair, with a coverage percentage substantiated per sub-requirement.

Matrix and Coverage

Framework beside framework, per requirement covered, partly or not. Guided for those who do not know the codes, Expert for the full matrix, and a task list in Word of what is still missing.

Your own frameworks

Internal standards, client standards and sector agreements, visible only to your organisation. With a cross-reference against the library, the result in Excel and a link into your audit in CRAFT.

Starter sets

Generic risks and threats in six categories, plus sector sets with processes, risks and controls. Taken over into the Risk Heat Map after the administrator confirms.

A cockpit on the quality of the material

One score on usability: frameworks without controls, without translation, without a frozen version, cross-references without reasoning. Every shortfall is listed as a gap with a click-through.

From finding a framework to adopting it in five steps

1

Find the framework

Browse the catalogue or search literally or by meaning across frameworks, controls and legal articles.

2

Read the controls

Open a control for its description and testing approach, filter by domain or layer, check the version history.

3

Put frameworks side by side

In Matrix or Coverage choose what you need to meet and what you have, and read per requirement what is covered and what is missing.

4

Load your own framework

Add an internal or client standard to your organisation's library and request a cross-reference against a recognised standard.

5

Adopt

Set a validated cross-reference as a link in your audit in CRAFT, or a starter set in the risk register of the Risk Heat Map.

Want to know how much of the next framework you already meet?

Request a demo or get in touch for more information about Library for your organisation.