Platform rules explained

Frequently asked questions

Clear answers about document workflow, asset valuation, risk decisions, FAIR analysis and ISO 27001 compliance.

Why do I need an asset before I can assess a risk?

PurpleWASP uses the asset register as the foundation for risk context. The asset supplies classification, ownership and confidentiality, integrity and availability values before the scenario-specific assessment begins.

What is the difference between a policy and another document type?

Policies can be distributed to the entire organisation or a selected group. Other governed documents, such as standards and procedures, are distributed to specific groups according to department, location or role.

What is the difference between Reject and Request Changes?

Reject returns the document with an overall mandatory reason. Request Changes allows the approver to highlight precise passages and attach review comments for revision.

Why can I not publish an approved document?

The document type may require a quiz or other configured condition. Complete the quiz workflow and check the intended audience and publication date.

When should a document become version 1.1 or 2.0?

Use a minor change for limited wording or administrative changes, producing 1.1. Use a major change for material changes to scope, obligations or intent, producing 2.0.

What happens when the CIA scale changes?

Changing the organisation-wide scale between 3×3 and 5×5 recalculates related asset and risk values. Review thresholds, reports and priority records after the change.

Why can my qualitative score increase during assessment?

The initial value comes from the asset. Scenario-specific likelihood, current controls and uncertainty can produce a higher inherent or current score as the assessment becomes more precise.

What is the difference between risk appetite and tolerance?

Appetite is the level the organisation is prepared to operate within. Tolerance is an upper boundary before stronger escalation. A risk can be within tolerance but above appetite, which still requires treatment or an approved exception.

Why am I being asked to raise an exception?

The residual risk remains above appetite after treatment. PurpleWASP requires further reduction or a formal, time-bound exception approved by the designated authority.

What happens when an exception is rejected?

The assessment reopens so the Risk Manager can change treatment and submit a new decision.

Does reassessment overwrite the previous risk assessment?

No. Reassessment creates a new version and preserves the previous assessment. The new version begins from the prior residual position and can carry forward relevant controls.

Why does FAIR require a specific threat?

FAIR estimates frequency and loss magnitude for one defined threat scenario. Different threats have different frequencies, capabilities and consequences, so they should be assessed separately.

What does Expected Annual Loss mean?

It is the average annual financial loss across the simulated periods. It is not a prediction that the organisation will lose exactly that amount in one year.

Why are some simulated years shown with no loss?

Where loss-event frequency is below certainty, the distribution can include years without a successful loss event and years with multiple losses.

Why must I justify a control marked Not Applicable?

The Statement of Applicability must explain why each excluded Annex A control is outside scope or unnecessary for the assessed risks. Generic or blank justification is not sufficient.

Can policies and risk assessments support compliance controls?

Yes. Approved policies and completed risk assessments can be linked to Annex A controls alongside other evidence, creating traceability across modules.

Does the compliance percentage prove certification?

No. It is an operational indicator based on the information and statuses recorded in PurpleWASP. Certification decisions remain with the authorised audit and certification process.

How do I get useful support help quickly?

Include the module, record ID, affected role, timestamp, expected and actual result, steps to reproduce, screenshots and the complete error text. Remove passwords, tokens and unnecessary personal data.