Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideClear answers about Policies and documents, Assets, Risk, Controls, ISO 27001, SOC 2, Cyber Essentials/Plus, NIST CSF 2.0, CIS Controls v8.1, Third-Party Risk and PurpAI.
PurpleWASP uses the Asset as authoritative context for the standard Asset-driven Risk workflow. The Asset supplies ownership, taxonomy and confidentiality, integrity and availability values before scenario-specific Risk assessment begins.
The selected document type carries capabilities such as approval, publication, acknowledgement, quiz support, review cycles, group targeting and external linking. That is more important than assuming every Policy, procedure or standard follows exactly the same lifecycle.
Approval records the governance decision that the content is acceptable. Publication makes an approved document available to its intended audience immediately or on a scheduled date where scheduling is used. An approved document is not automatically the same as a published document.
Reject returns the submission with an overall reason. Request Changes supports a revision cycle with targeted review comments so the owner can address specific issues and resubmit.
The document type or publication workflow may require additional conditions, such as an eligible audience or a quiz. Check the document-type capabilities, quiz state, audience and publication date.
Yes. PurpleWASP tracks reading/acknowledgement and quiz activity against the relevant document version so a later revision does not erase the history of the version that a user actually read or completed.
A catalogue Control is the reusable PurpleWASP control definition. Once adopted, the organisation has its own Control record for scope, implementation, assessment, testing, issues and other operational governance. The two identities should not be treated as interchangeable.
No. Applicability answers whether the Control is required for the selected context. Implementation answers whether it is operating. PurpleWASP can also distinguish organisation-wide implementation from the state of the same Control on an individual Asset.
Not by itself. Evidence supports an assessment or test, while the assurance conclusion records what the reviewer determined. Link evidence to the specific Control, assessment or test run it supports.
A Control exception records a departure from the intended Control implementation and can reference a compensating Control. A Risk exception is the formal decision to accept residual Risk outside normal appetite for a defined period. They can be related, but they are different governance decisions.
Changing the organisation-wide CIA model can recalculate related Asset and Risk values. Treat the change as governed configuration and review thresholds, priorities and reports afterwards.
Appetite is the level of exposure the organisation is prepared to operate within. Tolerance is the upper boundary before stronger escalation. A Risk can be within tolerance while still above appetite and therefore still require treatment or an approved exception.
No. Reassessment preserves prior assessment history and creates the next assessment state/version so reviewers can distinguish earlier decisions from the current position.
FAIR estimates frequency and loss magnitude for one defined threat scenario. Different threats can have different frequencies, capabilities and consequences, so they should be modelled separately.
It is the average annual financial loss across the simulated periods. It is not a prediction that the organisation will lose exactly that amount in a particular year.
The Statement of Applicability should explain why the Annex A Control is outside scope or not necessary for the organisation's ISMS position. Blank or generic justification undermines the traceability of that decision.
No. The SoA is the compliance decision layer for the standard: applicability, justification and implementation status. Control Management owns the organisation Control lifecycle, scope, Asset implementation and assurance such as assessments, tests, issues and exceptions.
No. It is an operational indicator based on the records maintained in PurpleWASP. Certification remains an external assurance decision and should be supported by the full ISMS, evidence and audit process.
No. It creates discovery candidates from vendor references already present in Assets. A user must review each candidate and explicitly accept or dismiss it before it becomes a managed TPRM relationship.
No. TPRM tiering determines the governance intensity required for the relationship, such as due diligence and review frequency. Enterprise current/residual Risk remains owned by Risk Management and is linked explicitly when required.
Not necessarily. Review failed questions and material findings independently of the overall percentage. A high total score can still contain a gap that requires remediation or Risk escalation.
No. A monitoring event is a signal. Review the source, severity, confidence and context, then decide whether it should be dismissed, tracked, escalated to a finding or linked to an incident.
PurpAI can navigate to existing workflows, prepare supported editable drafts and start a small allow-listed set of Third-Party work after explicit confirmation. It does not autonomously approve, accept, close or publish governed decisions, and it does not bypass the owning module's permissions, validation or audit controls.
PurpAI is intended to operate within the user's authorised module context and organisation AI settings. If you cannot access the underlying governed record, PurpAI should not be used as a route around that permission boundary.
Include the module, record ID, affected role, timestamp, expected and actual result, steps to reproduce, screenshots and the complete error text. Remove passwords, tokens and unnecessary personal data.
When the current result contains several records, a phrase such as “open it” is ambiguous. PurpAI intentionally refuses to choose one automatically. Use an ordinal such as “open the first one” or “open the second one”, or select the record directly.
No. Suggested Attention is a bounded triage view of current authorised warning and danger signals. It does not calculate an overall PurpleWASP score, decide Risk appetite or approve management priorities.
Confirmation is required when a supported PurpAI action will create governed work, such as starting a Third-Party periodic review or due-diligence workflow. Cancelling leaves the workflow unchanged; confirming still uses the module's normal permissions and audit path.
PurpleWASP supports SOC 2 readiness management and audit preparation: engagement setup, Trust Services Category selection, system and engagement scope, criteria review, candidate Control intelligence, organisation Control coverage decisions, implementation, assessments, evidence, testing, issues, exceptions, remediation, operational readiness and engagement-level audit readiness.
No. PurpleWASP helps the organisation prepare and manage the evidence, Control and readiness work. The independent SOC 2 examination and service auditor opinion remain with the appropriately qualified independent service auditor.
No. PurpleWASP readiness statuses are internal management indicators based on the records maintained in the platform. They help identify gaps before fieldwork but are not an auditor conclusion or report opinion.
No. Candidate mappings are PurpleWASP intelligence suggestions. Management reviews the actual system and explicitly selects the organisation Controls it intends to rely on for each criterion. A large candidate count is not a requirement to adopt every suggested Control.
Yes. The engagement setup records the examination type. Type I readiness focuses on the scoped system and Control design at the relevant point in time. Type II readiness also evaluates operating evidence and test activity against the defined engagement period.
PurpleWASP supports scope, the Danzell questionnaire, the five Cyber Essentials technical areas, readiness review, remediation, management declaration and submission preparation. Cyber Essentials Plus adds preflight, sampling, technical testing, findings/remediation, outcome review, assessor evidence-pack preparation and certificate/renewal records.
No. The score and Drivers / Improve Score views are PurpleWASP internal preparation indicators. The authoritative Cyber Essentials or Cyber Essentials Plus certification decision remains with the appropriate Certification Body or Assessor.
PurpleWASP supports the complete CSF 2.0 Core, multiple Organizational Profiles, Profile scope, Current and Target outcome assessments, shared organisation-Control assurance, gap analysis, improvement actions, Implementation Tiers and executive reports.
No. It is a PurpleWASP internal visualisation of the Current/Target Profile assessment states. Implementation Tiers are recorded separately and are not converted into a percentage.
PurpleWASP supports programme setup/scope, IG1/IG2/IG3 targeting, the complete 153-Safeguard catalogue, Safeguard workspaces, shared organisation-Control coverage and assurance, applicability/additional-target decisions, Drivers / Improve Score and current-state integrity checks.
Coverage required means the Safeguard is targeted but no effective applicable organisation Control currently provides coverage. Not implemented is used only after Control coverage exists and the authoritative Control state indicates the requirement is not operating. PurpleWASP keeps uncertainty/unmapped coverage separate from an explicit failed implementation conclusion.
No. Assessment Coverage, Implementation Progress and PurpleWASP Readiness are internal management indicators. They are not CIS certification, conformance or an official CIS Controls Assessment Specification result.
PurpleWASP defaults to identifier_only mode so commercial deployments can use the programme/mapping/assurance architecture without automatically redistributing official CIS content. A licensed content mode should be enabled only where the deployment has confirmed rights appropriate to the intended use.
Yes. PurpleWASP keeps the organisation Control implementation and assurance records separate from framework requirements, so the same Control can be mapped across ISO 27001, SOC 2, Cyber Essentials, NIST and CIS where the relationship is appropriate. A mapping still does not prove implementation or effectiveness.
No questions match that search.