Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guidePurpleWASP connects Policy & Document Management, Assets, Risks, Controls, Compliance, external provider evidence and Third-Party Risk so teams can follow ownership, decisions, assurance and change in context.
Each workspace has its own lifecycle and authority. PurpleWASP connects them through explicit relationships rather than collapsing them into one generic register.
Maintain the Assets, services, owners and external dependencies that governance decisions relate to.
Create controlled Policies and other governed documents with approval, publication, review and acknowledgement.
Assess Risk, quantify selected scenarios with FAIR and govern treatment, exceptions and reassessment.
Adopt Controls, establish applicability, track implementation and support assessments, tests, evidence, issues and exceptions.
Operate the ISO 27001 ISMS, manage SOC 2 readiness, run Cyber Essentials/Plus preparation, use NIST CSF 2.0 Profiles and implement CIS Controls v8.1—all on top of shared organisation Controls.
Discover, tier, assess, assure, contract, review and monitor suppliers and services that support the organisation.
Use each workspace for the decisions it owns, then follow links across the platform when a decision depends on another domain.
Manage policies, procedures, standards, guidelines, plans and other governed documents through configurable approval, publication, review, audience and quiz capabilities.
Build a dependable Asset register with ownership, taxonomy, lifecycle, CIA valuation, provider integrations, technical vulnerability exposure and explicit links into Risk, Controls and third-party relationships.
Configure supported external providers once, keep credentials encrypted, run collection through a shared worker/scheduler and route normalized observations into the owning Asset or Control workflows.
Move from identification to qualitative or FAIR assessment, incorporate linked technical evidence, govern treatment and exceptions, and reassess while preserving immutable assessment history.
Adopt canonical Controls into the organisation, map them across frameworks, resolve scope/applicability, track Asset-level implementation and connect documents, Risks, evidence, assessments, tests, issues and exceptions.
Use framework-specific workspaces for ISO 27001, SOC 2 readiness, Cyber Essentials/Plus, NIST CSF 2.0 and CIS Controls v8.1. Reuse organisation Controls and assurance while keeping each framework's scope, assessment and external-assurance boundary distinct.
Turn vendor references into governed relationships, then tier, assess and monitor third parties across services, Assets, Controls, Risks, findings, contracts, data, evidence and periodic reviews.
PurpAI combines product guidance with authorised live context. Ask about posture and relationships, select exact records conversationally, open the relevant workflow, prepare an editable Risk draft from a verified Asset, or start supported Third-Party workflows with explicit confirmation.
Role-based access, approval workflows, review records, version history, activity logs, due dates and explicit relationships help teams understand what changed, why it changed and what needs attention next.
A phased rollout helps teams establish ownership, clean source data and working cadences before increasing scope.
Confirm scope, module owners, roles, access and the first business outcomes.
Clean the initial Assets, Policies, Risks, Controls, Compliance records or third-party data before migration or bulk import.
Prove ownership, lifecycle, reporting and hand-offs with a manageable group before expanding.
Add explicit relationships once the underlying ownership and operating cadence are working.
Administrators manage users, role mappings, module access, groups, account security and organisation settings. AI capabilities can be governed at organisation level, and two-factor authentication can be required according to the configured security policy.
Discuss required workflows, user roles, rollout scope and support expectations.