Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideUse module dashboards and cross-module views to understand posture, deadlines, high exposure, assurance gaps and workload.
PurpleWASP analytics surface the state of the underlying operational workspaces; they do not replace the source records or their decisions.
Start with the dashboard relevant to your role.
Confirm scope, period and status before interpreting a number.
Open the underlying records and relationships.
Focus on high, overdue, incomplete or deteriorating work.
Update the record in the workspace that owns the decision.
Use the owning workspace when a metric needs explanation or action.
Review active/high Risks, treatment and exception status.
AssetsReview Asset population, valuation, lifecycle and Risk coverage.
ControlsReview adoption, implementation and assurance activity in Control Management.
ComplianceReview ISO 27001 ISMS progress, SOC 2 readiness, Cyber Essentials/Plus preparation, NIST CSF 2.0 Current/Target signals and CIS Controls v8.1 implementation readiness.
TPRMReview tier distribution, due diligence, findings, reviews and monitoring.
PoliciesReview draft, approval, publication, review and awareness activity.
Use metrics as operational signals. The underlying workspace remains authoritative for applicability, Risk, Control effectiveness, tiering, certification evidence and other governed conclusions.
No guidance matches that search.