Compliance crosswalk / 05
Compliance is documented, not asserted.
A framework-versioned view of the controls AegisGrid was designed to support — with the institutional assessment boundary left explicit.
AegisGrid is a software platform. AegisGrid does not hold third-party security certifications at the time of writing. What AegisGrid does is implement controls designed to align with the published frameworks below. Compliance with these frameworks in a specific institutional deployment requires a formal assessment by the institution's qualified individual.
Framework crosswalk
Specific mappings. Cautious language.
AegisGrid was designed against the frameworks on this page. We use "aligned with", "designed for", and "maps to" deliberately, because a CISSP reads the difference between an alignment claim and a certification claim. The mappings below are specific; each framework section names the clauses AegisGrid was designed to support.
HECVAT 4.1.6 is published by EDUCAUSE; 4.1.6 is the current release. AegisGrid's extraction workflow is designed to support all 35 question categories across the 8 published evaluation tabs. The conditional AI subsection (32 questions, aligned to NIST AI RMF AIPL-05) is supported as a first-class workflow with explicit citation lineage for each question.
mapping posture: designed to support · not a completed HECVAT response or certificationInstitutional boundary
Your qualified individual makes the final attestation.
Compliance is documented, not asserted. AegisGrid provides architecture diagrams, control mappings, deployment guides, and immutable audit logs that an institution's qualified individual can review. Final compliance attestation is the institution's responsibility.
Next: inspect the evidence
Review the proof, not a badge.
See the redacted artifact workflow, control lineage, and audit-log evidence that an institutional team can evaluate.