Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideSelect an Implementation Group, confirm programme scope, work through targeted Safeguards, reuse shared organisation Controls and assurance, and use Drivers / Improve Score to prioritise the next action.
PurpleWASP treats CIS Controls v8.1 as a programme and Safeguard layer over shared organisation Controls. The current catalogue contains 18 CIS Controls and 153 Safeguards. The programme selects an Implementation Group (IG1, IG2 or IG3), establishes scope and accountability, then derives Safeguard coverage and implementation from the authoritative Control Management records.
| Area | PurpleWASP capability |
|---|---|
| Programme setup | Select baseline IG, whole/partial scope, owner, business context and rationale; save draft and confirm a versioned baseline. |
| Safeguard catalogue | Browse/search all 153 Safeguards and filter by CIS Control, target, minimum IG and derived state. |
| Control reuse | Use PurpleWASP canonical recommendations and adopted organisation Controls without duplicating implementation state. |
| Assurance | Surface governance documents, Risks, evidence, assessments, tests, issues and exceptions from shared Control Management. |
| Improvement | Use internal Drivers / Improve Score and the operational queue to prioritise concrete next work. |
| Integrity | Reconcile programme lifecycle, target counts, Safeguard aggregation and readiness-model consistency. |
Open Setup & Scope, select the baseline Implementation Group, define whether the programme covers the whole organisation or a justified partial scope, assign an accountable user/function and record the IG rationale/business context. Save a draft first, then confirm it when the configuration is ready to become the reporting baseline.
Implementation Groups are cumulative. PurpleWASP currently targets 56 Safeguards for IG1, 130 for IG2 and 153 for IG3. Choose the baseline from the organisation's actual risk, complexity, sensitive data, critical services, threat exposure and security capability rather than from a desired dashboard percentage.
Higher-IG Safeguards can be added explicitly to a lower baseline when the organisation wants a narrower extension.
The Safeguards page separates the full 153-Safeguard catalogue from the current programme target. Use the filters to focus on the selected IG, a particular CIS Control, a minimum IG or a derived implementation state. Open a Safeguard workspace when you need to understand why a status was derived and which organisation Controls support it.
Coverage required means the Safeguard is in target but PurpleWASP does not yet have effective applicable organisation-Control coverage. It is intentionally different from Not implemented, which means coverage exists and the authoritative Control state indicates the requirement is not operating.
The workspace shows the framework-specific target/applicability decision, PurpleWASP canonical Control recommendations and any adopted organisation Controls currently providing coverage. The assurance tabs then reuse the shared records for Policies & Documents, Risks, Evidence, Tests & Assessments, Issues & Exceptions and cross-framework relationships.
If no organisation Control is mapped, use Adopt control or Control Management's mapping workflow. Once the Control is adopted/mapped, CIS derives its state from that authoritative record rather than creating a CIS-only duplicate.
The dashboard and improvement page use a PurpleWASP internal implementation-readiness model across setup/scope, Safeguard Control coverage, Control implementation, governance documents, current evidence, assessment/testing and issue/exception impact. Use the potential gain to prioritise work, then fix the underlying Control/assurance record.
Use the Integrity page before final sign-off. It checks the current catalogue/programme state, target reconciliation, Safeguard aggregation and readiness-model consistency. It complements—not replaces—RBAC and end-to-end workflow testing.
PurpleWASP defaults to identifier_only CIS content mode. In that mode the UI uses identifiers such as “CIS Control 17” and “CIS Safeguard 17.3” plus PurpleWASP-authored implementation context instead of redistributing the official CIS Safeguard wording. Enable a licensed content mode only where the deployment has confirmed rights appropriate to the intended commercial use.
Use the first-time handbook for programme owners and implementation teams, and the technical guide for developers, administrators and implementation partners.
Open the Safeguards page and filter to Coverage required. Adopt/map appropriate organisation Controls first; do not convert unknown coverage into Not implemented merely to remove the gap.
Confirmed programmes should remain immutable. Saving a programme/Safeguard decision after confirmation should create or reuse a successor draft and leave reporting on the current confirmed baseline until the draft is confirmed.
Confirm whether the headline is showing current/actionable records while the tab includes historical records. Use clear labels so different populations are not mistaken for a reconciliation defect.
Check PW_CIS_CONTENT_MODE and the deployment's licensed-content configuration before exposing or distributing official/derivative CIS content.