Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideUnderstand how PurpleWASP reuses organisation Controls across ISO 27001, SOC 2, Cyber Essentials, NIST CSF 2.0 and CIS Controls v8.1, and how framework dashboards turn underlying assurance records into readiness drivers.
PurpleWASP keeps reusable canonical Controls and organisation-adopted Controls separate from framework requirements. A single organisation Control can therefore support ISO 27001, SOC 2, Cyber Essentials, NIST CSF 2.0 and CIS Controls v8.1 without creating separate framework-specific implementations.
Framework requirement → organisation Control → shared assurance records is the core model.
A mapping means the Control can support a requirement. It does not prove the Control is applicable, fully implemented or effective. Keep these facts separate:
Control Management is the authoritative operating record for the organisation Control. The Control workspace can connect governance documents, Risks, evidence, assessments, tests/test runs, issues and exceptions around the same Control. Framework pages consume that context rather than maintaining separate copies.
Where PurpleWASP displays an internal readiness percentage, use the associated drivers to understand the denominator and the records that are reducing the score. The improvement view should point to concrete work—such as an unimplemented Control, missing evidence, an open issue, an incomplete questionnaire item or an unresolved gap—rather than leaving the user with a percentage only.
Framework dashboards are intentionally different because the underlying frameworks ask different questions.
| Framework | Primary PurpleWASP model |
|---|---|
| ISO 27001 | ISMS governance, Clauses 4–10, SoA, operational registers, internal audit, management review and continual improvement. |
| SOC 2 | Engagement readiness and audit preparation: scope, criteria, selected Control coverage, evidence, testing, issues/exceptions and audit-readiness decisions. |
| Cyber Essentials / Plus | Questionnaire/technical-area readiness, remediation and submission preparation; Plus adds technical sampling/testing and assessor evidence preparation. |
| NIST CSF 2.0 | Organizational Profiles, Current/Target outcomes, shared Control assurance, gap analysis, improvement planning and Implementation Tiers. |
| CIS Controls v8.1 | Implementation Group programme, targeted Safeguards, shared Control coverage/implementation, assurance signals, Drivers / Improve Score and integrity checks. |