Governance & accountability
Policies, security leadership, roles, reviews and oversight.
- Responsibility; management review; security objectives
Go beyond a compliance checklist. PurpleWASP's 124-control catalogue connects security and governance requirements to ownership, testing, evidence and framework obligations—so work completed for one relevant control can support multiple mapped requirements.
Illustration of the mapping model, not a claim that every control maps to every framework.
PurpleWASP connects the organisation’s adopted controls to multiple frameworks while retaining the real assessment outcome, applicability and evidence lineage for each control.
Search common topics to understand the breadth of the library. These are explanatory coverage themes—not a fabricated list of official control identifiers or exact per-control mappings.
Showing 14 coverage themes
Policies, security leadership, roles, reviews and oversight.
User lifecycle, access reviews, strong authentication and privileged access.
Asset ownership, inventory, classification and approved configuration.
Information classification, appropriate handling and protection of sensitive data.
Security configuration and oversight of cloud and network resources.
Device security, endpoint policy, management and protection.
Vulnerability visibility, prioritisation and remediation verification.
Code, repository, release and production change safeguards.
Security event logging, monitoring and accountability.
Backups, restoration planning and resilience testing.
Critical services, operational dependencies and continuity preparation.
Suppliers, external dependencies and relevant due diligence.
Security competence, training and acknowledgements.
Risk treatment, control testing, exceptions, evidence and improvement.
No themes match your search. Try a broader security or governance term.
The currently presented framework families use PurpleWASP’s shared control layer. Only the appropriate controls and mappings contribute to a particular requirement.
Information security management system requirements and applicable Annex A control themes.
Trust Services Criteria and assurance evidence for relevant scoped criteria.
Cybersecurity outcomes organised around Govern, Identify, Protect, Detect, Respond and Recover.
Prioritised security safeguards and practical control outcomes.
Foundational UK security technical control themes.
The platform supports manual evidence and selected integration-driven collection from Microsoft, AWS, Google Workspace, GitHub and Qualys.
Choose relevant controls and establish applicability, accountability and assessment ownership.
Attach manual evidence or collect supported technical observations through approved provider connections.
Use narrow control checks and human review. Unavailable provider information must not be treated as a pass.
Connect the reviewed control and its evidence to applicable framework requirements and reporting.
The examples describe supported workflows and assessment themes; they are not an exhaustive or authoritative control-to-clause crosswalk.
Central identity-policy evidence may help assess an adopted access control; the relevant framework mappings reuse that assessment.
Approved branch protection and review settings can support a narrow change-management control test.
Available scanner and code-security observations can help evaluate timely exposure review and treatment.
Supplier assessment and dependency records support governance and risk-review activities alongside technical evidence.
Request a walkthrough of the current PurpleWASP control catalogue, the exact approved mappings, and how evidence is reviewed within your organisation’s scope.