Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideCreate the organisation Control population from the PurpleWASP catalogue, then establish applicability, framework coverage and Asset context.
You will have an organisation-owned Control record with clear applicability and scope, ready for implementation tracking and assurance.
Open the Control catalogue and choose the Controls that your organisation needs. Where the interface supports multi-select, adopt several Controls in one action rather than opening each record individually.
Applicability is resolved from organisation scope, exclusions and more specific context. Record why the Control applies or why it is excluded where the workflow asks for a rationale.
Where a Control applies to particular Assets, use the Asset relationship and per-Asset implementation state rather than treating the organisation-level status as proof that every Asset is covered.
Framework mappings help demonstrate which requirements a Control supports. Review the mapping strength and the underlying requirement rather than treating the mapping as assurance evidence.
Use the Control edit/workspace tabs to keep the implementation connected to its wider governance context, including governance documents, Risks and evidence. Document expectations can identify which current governance documents the Control is expected to have, rather than treating every absent document as a readiness failure.
Confirm that it has been adopted into the organisation and that you are working with the organisation Control rather than the catalogue reference.
Review the Asset taxonomy and the scope/exclusion rules that drive applicability, then refresh the Control context.
This is valid. Framework coverage, applicability and implementation are separate governance facts.