Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideAdopt Controls into the organisation, establish scope and applicability, map framework coverage, link governance documents and Risks, track implementation and maintain manual or integration-generated assessments, evidence, testing, issues and exceptions over time.
Control Management separates the reusable control definition from organisation adoption, Asset-level implementation and assurance activity.
Adopt catalogue Controls or maintain organisation-specific Controls.
Set organisation scope, applicability and framework relationships.
Track organisation-wide and Asset-specific implementation state.
Record assessments, tests, evidence and required governance-document relationships.
Manage issues, exceptions, verification and compensating Controls.
Use these guides to establish the Control population and maintain evidence that Controls are operating as intended.
A Control can be applicable without being fully implemented. PurpleWASP also keeps organisation-level implementation separate from the state of that Control on an individual Asset.
No guidance matches that search.