Platform rules explained

Frequently asked questions

Clear answers about Policies and documents, Assets, Risk, Controls, ISO 27001, SOC 2, Cyber Essentials/Plus, NIST CSF 2.0, CIS Controls v8.1, Third-Party Risk and PurpAI.

Why do I need an Asset before I can assess a Risk?

PurpleWASP uses the Asset as authoritative context for the standard Asset-driven Risk workflow. The Asset supplies ownership, taxonomy and confidentiality, integrity and availability values before scenario-specific Risk assessment begins.

What determines how a governed document behaves?

The selected document type carries capabilities such as approval, publication, acknowledgement, quiz support, review cycles, group targeting and external linking. That is more important than assuming every Policy, procedure or standard follows exactly the same lifecycle.

What is the difference between approval and publication?

Approval records the governance decision that the content is acceptable. Publication makes an approved document available to its intended audience immediately or on a scheduled date where scheduling is used. An approved document is not automatically the same as a published document.

What is the difference between Reject and Request Changes?

Reject returns the submission with an overall reason. Request Changes supports a revision cycle with targeted review comments so the owner can address specific issues and resubmit.

Why can I not publish an approved document?

The document type or publication workflow may require additional conditions, such as an eligible audience or a quiz. Check the document-type capabilities, quiz state, audience and publication date.

Are document reads and quizzes tied to a version?

Yes. PurpleWASP tracks reading/acknowledgement and quiz activity against the relevant document version so a later revision does not erase the history of the version that a user actually read or completed.

What is the difference between a catalogue Control and an organisation Control?

A catalogue Control is the reusable PurpleWASP control definition. Once adopted, the organisation has its own Control record for scope, implementation, assessment, testing, issues and other operational governance. The two identities should not be treated as interchangeable.

Is an applicable Control automatically implemented?

No. Applicability answers whether the Control is required for the selected context. Implementation answers whether it is operating. PurpleWASP can also distinguish organisation-wide implementation from the state of the same Control on an individual Asset.

Does linked evidence prove a Control is effective?

Not by itself. Evidence supports an assessment or test, while the assurance conclusion records what the reviewer determined. Link evidence to the specific Control, assessment or test run it supports.

What is the difference between a Control exception and a Risk exception?

A Control exception records a departure from the intended Control implementation and can reference a compensating Control. A Risk exception is the formal decision to accept residual Risk outside normal appetite for a defined period. They can be related, but they are different governance decisions.

What happens when the CIA scale changes?

Changing the organisation-wide CIA model can recalculate related Asset and Risk values. Treat the change as governed configuration and review thresholds, priorities and reports afterwards.

What is the difference between Risk appetite and tolerance?

Appetite is the level of exposure the organisation is prepared to operate within. Tolerance is the upper boundary before stronger escalation. A Risk can be within tolerance while still above appetite and therefore still require treatment or an approved exception.

Does reassessment overwrite the previous Risk assessment?

No. Reassessment preserves prior assessment history and creates the next assessment state/version so reviewers can distinguish earlier decisions from the current position.

Why does FAIR require a specific threat?

FAIR estimates frequency and loss magnitude for one defined threat scenario. Different threats can have different frequencies, capabilities and consequences, so they should be modelled separately.

What does Expected Annual Loss mean?

It is the average annual financial loss across the simulated periods. It is not a prediction that the organisation will lose exactly that amount in a particular year.

Why must I justify an SoA Control marked Not Applicable?

The Statement of Applicability should explain why the Annex A Control is outside scope or not necessary for the organisation's ISMS position. Blank or generic justification undermines the traceability of that decision.

Is the Statement of Applicability the same as Control Management?

No. The SoA is the compliance decision layer for the standard: applicability, justification and implementation status. Control Management owns the organisation Control lifecycle, scope, Asset implementation and assurance such as assessments, tests, issues and exceptions.

Does the Compliance percentage prove certification?

No. It is an operational indicator based on the records maintained in PurpleWASP. Certification remains an external assurance decision and should be supported by the full ISMS, evidence and audit process.

Does Discover from Assets automatically create third parties?

No. It creates discovery candidates from vendor references already present in Assets. A user must review each candidate and explicitly accept or dismiss it before it becomes a managed TPRM relationship.

Is a TPRM tier the same as a Risk score?

No. TPRM tiering determines the governance intensity required for the relationship, such as due diligence and review frequency. Enterprise current/residual Risk remains owned by Risk Management and is linked explicitly when required.

Does a strong questionnaire score mean the vendor has no material gaps?

Not necessarily. Review failed questions and material findings independently of the overall percentage. A high total score can still contain a gap that requires remediation or Risk escalation.

Is a monitoring event automatically a finding or incident?

No. A monitoring event is a signal. Review the source, severity, confidence and context, then decide whether it should be dismissed, tracked, escalated to a finding or linked to an incident.

Can PurpAI change or approve records for me?

PurpAI can navigate to existing workflows, prepare supported editable drafts and start a small allow-listed set of Third-Party work after explicit confirmation. It does not autonomously approve, accept, close or publish governed decisions, and it does not bypass the owning module's permissions, validation or audit controls.

Can PurpAI see records I cannot access?

PurpAI is intended to operate within the user's authorised module context and organisation AI settings. If you cannot access the underlying governed record, PurpAI should not be used as a route around that permission boundary.

How do I get useful support help quickly?

Include the module, record ID, affected role, timestamp, expected and actual result, steps to reproduce, screenshots and the complete error text. Remove passwords, tokens and unnecessary personal data.

Why does PurpAI ask “Which record?”

When the current result contains several records, a phrase such as “open it” is ambiguous. PurpAI intentionally refuses to choose one automatically. Use an ordinal such as “open the first one” or “open the second one”, or select the record directly.

Is Suggested Attention a PurpleWASP score?

No. Suggested Attention is a bounded triage view of current authorised warning and danger signals. It does not calculate an overall PurpleWASP score, decide Risk appetite or approve management priorities.

Why does PurpAI ask me to confirm some actions?

Confirmation is required when a supported PurpAI action will create governed work, such as starting a Third-Party periodic review or due-diligence workflow. Cancelling leaves the workflow unchanged; confirming still uses the module's normal permissions and audit path.

What does PurpleWASP SOC 2 support today?

PurpleWASP supports SOC 2 readiness management and audit preparation: engagement setup, Trust Services Category selection, system and engagement scope, criteria review, candidate Control intelligence, organisation Control coverage decisions, implementation, assessments, evidence, testing, issues, exceptions, remediation, operational readiness and engagement-level audit readiness.

Does PurpleWASP issue a SOC 2 report or auditor opinion?

No. PurpleWASP helps the organisation prepare and manage the evidence, Control and readiness work. The independent SOC 2 examination and service auditor opinion remain with the appropriately qualified independent service auditor.

Does a positive SOC 2 readiness status mean we have passed the audit?

No. PurpleWASP readiness statuses are internal management indicators based on the records maintained in the platform. They help identify gaps before fieldwork but are not an auditor conclusion or report opinion.

Are all SOC 2 candidate Controls mandatory?

No. Candidate mappings are PurpleWASP intelligence suggestions. Management reviews the actual system and explicitly selects the organisation Controls it intends to rely on for each criterion. A large candidate count is not a requirement to adopt every suggested Control.

Can PurpleWASP support SOC 2 Type I and Type II readiness?

Yes. The engagement setup records the examination type. Type I readiness focuses on the scoped system and Control design at the relevant point in time. Type II readiness also evaluates operating evidence and test activity against the defined engagement period.

What does PurpleWASP support for Cyber Essentials and Cyber Essentials Plus?

PurpleWASP supports scope, the Danzell questionnaire, the five Cyber Essentials technical areas, readiness review, remediation, management declaration and submission preparation. Cyber Essentials Plus adds preflight, sampling, technical testing, findings/remediation, outcome review, assessor evidence-pack preparation and certificate/renewal records.

Does a high Cyber Essentials readiness score mean we are certified?

No. The score and Drivers / Improve Score views are PurpleWASP internal preparation indicators. The authoritative Cyber Essentials or Cyber Essentials Plus certification decision remains with the appropriate Certification Body or Assessor.

What does PurpleWASP support for NIST CSF 2.0?

PurpleWASP supports the complete CSF 2.0 Core, multiple Organizational Profiles, Profile scope, Current and Target outcome assessments, shared organisation-Control assurance, gap analysis, improvement actions, Implementation Tiers and executive reports.

Is the NIST percentage a NIST maturity or compliance score?

No. It is a PurpleWASP internal visualisation of the Current/Target Profile assessment states. Implementation Tiers are recorded separately and are not converted into a percentage.

What does PurpleWASP support for CIS Controls v8.1?

PurpleWASP supports programme setup/scope, IG1/IG2/IG3 targeting, the complete 153-Safeguard catalogue, Safeguard workspaces, shared organisation-Control coverage and assurance, applicability/additional-target decisions, Drivers / Improve Score and current-state integrity checks.

Why does a CIS Safeguard say “Coverage required” instead of “Not implemented”?

Coverage required means the Safeguard is targeted but no effective applicable organisation Control currently provides coverage. Not implemented is used only after Control coverage exists and the authoritative Control state indicates the requirement is not operating. PurpleWASP keeps uncertainty/unmapped coverage separate from an explicit failed implementation conclusion.

Is PurpleWASP CIS readiness an official CIS score?

No. Assessment Coverage, Implementation Progress and PurpleWASP Readiness are internal management indicators. They are not CIS certification, conformance or an official CIS Controls Assessment Specification result.

Why does PurpleWASP show CIS identifiers instead of official Safeguard wording?

PurpleWASP defaults to identifier_only mode so commercial deployments can use the programme/mapping/assurance architecture without automatically redistributing official CIS content. A licensed content mode should be enabled only where the deployment has confirmed rights appropriate to the intended use.

Can the same PurpleWASP Control support several frameworks?

Yes. PurpleWASP keeps the organisation Control implementation and assurance records separate from framework requirements, so the same Control can be mapped across ISO 27001, SOC 2, Cyber Essentials, NIST and CIS where the relationship is appropriate. A mapping still does not prove implementation or effectiveness.