Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideOperate framework-specific workspaces for ISO 27001, SOC 2 readiness, Cyber Essentials and Cyber Essentials Plus, NIST CSF 2.0 and CIS Controls v8.1 while reusing shared PurpleWASP Controls and assurance records.
Choose the framework, establish its scope/profile/engagement, make the framework-specific decisions it requires, connect shared Controls and assurance, then use readiness, gap or continual-improvement views to drive the next action.
Choose ISO 27001, SOC 2, Cyber Essentials/Plus, NIST CSF 2.0 or CIS Controls v8.1.
Define the management-system, engagement, assessment or Organizational Profile boundary.
Record framework-specific applicability, criteria, questionnaire or Current/Target decisions.
Reuse organisation Controls and connect implementation, evidence, assessments, testing, issues and exceptions.
Use drivers, readiness, gaps, remediation and improvement actions to focus the next work.
Confirm scope and accountability, work through targeted Safeguards, resolve Control coverage, reuse assurance and prioritise improvements without duplicating organisation-Control state.
Assess the complete CSF 2.0 Core, compare Current and Target Profiles, reuse shared Control assurance and turn gaps into an improvement plan.
Work from scope and questionnaire through technical-area readiness, remediation and the Plus technical-assurance workflow.
Use PurpleWASP for management-side SOC 2 readiness, Control coverage, evidence, testing, remediation and audit preparation.
Maintain Clauses 4–10, the Statement of Applicability, recurring assurance and operational registers in one connected ISMS workspace.
Maintain scope/context, objectives, legal obligations, training, suppliers, incidents, access reviews, BC/DR, internal audit, management review, nonconformities and compliance activity.
Annex ASet Annex A applicability and implementation status, then connect Policies, Risks, Controls and evidence.
Use shared organisation Controls across frameworks while keeping each framework's applicability, assessment and readiness model distinct.
PurpleWASP structures and connects the organisation records needed for compliance, readiness and improvement. External certification or independent attestation decisions remain with the appropriate external assurance provider where the framework uses one.
No guidance matches that search.