Control Management guide

Adopt and scope Controls

Create the organisation Control population from the PurpleWASP catalogue, then establish applicability, framework coverage and Asset context.

Control Manager / Control Owner 10–20 minutes Updated 9 September 2026

Outcome

You will have an organisation-owned Control record with clear applicability and scope, ready for implementation tracking and assurance.

Important: a catalogue Control becomes an organisation Control when it is adopted. Use the organisation Control in operational workflows.

1. Adopt Controls

Open the Control catalogue and choose the Controls that your organisation needs. Where the interface supports multi-select, adopt several Controls in one action rather than opening each record individually.

  • Use catalogue metadata and framework references to decide what should enter your organisation Control set.
  • Do not adopt a Control solely because it appears in a framework; first consider scope and applicability.
  • If a previously retired organisation Control is adopted again, PurpleWASP can restore the existing organisation record instead of creating a duplicate.

2. Set scope and applicability

Applicability is resolved from organisation scope, exclusions and more specific context. Record why the Control applies or why it is excluded where the workflow asks for a rationale.

Applicable does not mean implemented. Applicability answers whether the Control is required for the selected context; implementation records whether it is operating.

3. Use Asset context

Where a Control applies to particular Assets, use the Asset relationship and per-Asset implementation state rather than treating the organisation-level status as proof that every Asset is covered.

  • Confirm the correct Asset before recording implementation.
  • Use the Asset view to understand which Controls are recommended or already adopted.
  • Keep Asset-specific operating status separate from the organisation-wide Control lifecycle.

4. Review framework mappings and connected records

Framework mappings help demonstrate which requirements a Control supports. Review the mapping strength and the underlying requirement rather than treating the mapping as assurance evidence.

Use the Control edit/workspace tabs to keep the implementation connected to its wider governance context, including governance documents, Risks and evidence. Document expectations can identify which current governance documents the Control is expected to have, rather than treating every absent document as a readiness failure.

Verify the result

  • The Control appears in the organisation Control register.
  • Applicability and scope reflect the intended organisation or Asset context.
  • Relevant framework mappings are visible.
  • The implementation state is not being confused with applicability.
  • Owners and review information are assigned where required.

Common problems

A catalogue Control is visible but cannot be managed

Confirm that it has been adopted into the organisation and that you are working with the organisation Control rather than the catalogue reference.

The Control appears applicable to the wrong Asset

Review the Asset taxonomy and the scope/exclusion rules that drive applicability, then refresh the Control context.

A framework mapping is present but the Control is not implemented

This is valid. Framework coverage, applicability and implementation are separate governance facts.