Help Centre workspace

Control Management

Adopt Controls into the organisation, establish scope and applicability, map framework coverage, link governance documents and Risks, track implementation and maintain manual or integration-generated assessments, evidence, testing, issues and exceptions over time.

Start with the workflow

From control catalogue to operating assurance

Control Management separates the reusable control definition from organisation adoption, Asset-level implementation and assurance activity.

1
Adopt

Adopt catalogue Controls or maintain organisation-specific Controls.

2
Scope

Set organisation scope, applicability and framework relationships.

3
Implement

Track organisation-wide and Asset-specific implementation state.

4
Assure

Record assessments, tests, evidence and required governance-document relationships.

5
Improve

Manage issues, exceptions, verification and compensating Controls.

Control workflows

Move from adoption to assurance

Use these guides to establish the Control population and maintain evidence that Controls are operating as intended.

Important operating rules

Applicability and implementation are different decisions

A Control can be applicable without being fully implemented. PurpleWASP also keeps organisation-level implementation separate from the state of that Control on an individual Asset.

  • Adopted organisation Controls have their own identity; catalogue IDs are not interchangeable with organisation Control IDs.
  • Framework mappings show coverage but do not by themselves prove implementation; the same organisation Control can support several frameworks.
  • Evidence should be linked to the Control, assessment or test it supports; supported integrations can materialise evidence against already-adopted applicable Controls.
  • Integration evidence does not automatically set the organisation Control implementation status.
  • Control exceptions are distinct from Risk exceptions and can use compensating Controls where appropriate.