PURPLEWASP CONTROL LIBRARY

One control library.
Five framework views.

Go beyond a compliance checklist. PurpleWASP's 124-control catalogue connects security and governance requirements to ownership, testing, evidence and framework obligations—so work completed for one relevant control can support multiple mapped requirements.

Control-first model Reusable evidence Human + technical assurance
WHAT THE LIBRARY ENABLES

Designed around assurance, not duplicated checklists.

PurpleWASP connects the organisation’s adopted controls to multiple frameworks while retaining the real assessment outcome, applicability and evidence lineage for each control.

124Canonical PurpleWASP controls in the previously established library baseline.
5Framework families presented in the current platform.
1Reusable underlying control/evidence record, with mappings to applicable requirements.
About the 124-control figure: this refers to the established PurpleWASP catalogue baseline, not 124 universal guarantees of compliance. Organisational controls must be adopted and assessed; each mapping and evidence claim depends on scope and current catalogue configuration.
WHAT THE CONTROLS ADDRESS

Coverage across the security and governance programme.

Search common topics to understand the breadth of the library. These are explanatory coverage themes—not a fabricated list of official control identifiers or exact per-control mappings.

Showing 14 coverage themes

Governance & accountability

Policies, security leadership, roles, reviews and oversight.

  • Responsibility; management review; security objectives

Identity & access

User lifecycle, access reviews, strong authentication and privileged access.

  • MFA; joiner/mover/leaver; least privilege

Asset & configuration

Asset ownership, inventory, classification and approved configuration.

  • Asset register; ownership; configuration baselines

Data protection & privacy

Information classification, appropriate handling and protection of sensitive data.

  • Information handling; encryption; retention

Cloud & network security

Security configuration and oversight of cloud and network resources.

  • Cloud accounts; exposed services; segmentation

Endpoint & device security

Device security, endpoint policy, management and protection.

  • Managed devices; endpoint protection

Vulnerability & exposure

Vulnerability visibility, prioritisation and remediation verification.

  • Scans; high-severity findings; treatment

Secure change & development

Code, repository, release and production change safeguards.

  • Review approvals; branch policies; code alerts

Logging & monitoring

Security event logging, monitoring and accountability.

  • Activity records; monitoring coverage

Backup & recovery

Backups, restoration planning and resilience testing.

  • Backup coverage; recovery objectives; restore tests

Continuity & resilience

Critical services, operational dependencies and continuity preparation.

  • Continuity plans; service dependencies

Supplier & third-party assurance

Suppliers, external dependencies and relevant due diligence.

  • Supplier inventory; assessments; follow-up

People & awareness

Security competence, training and acknowledgements.

  • Training; policy acknowledgements

Risk, exceptions & assurance

Risk treatment, control testing, exceptions, evidence and improvement.

  • Risk reviews; assessments; evidence history

No themes match your search. Try a broader security or governance term.

FRAMEWORK MAPPING

Understand more than one standard—without five separate evidence exercises.

The currently presented framework families use PurpleWASP’s shared control layer. Only the appropriate controls and mappings contribute to a particular requirement.

ISO/IEC 27001

Information security management system requirements and applicable Annex A control themes.

SOC 2

Trust Services Criteria and assurance evidence for relevant scoped criteria.

NIST CSF 2.0

Cybersecurity outcomes organised around Govern, Identify, Protect, Detect, Respond and Recover.

CIS Controls v8.1

Prioritised security safeguards and practical control outcomes.

Cyber Essentials

Foundational UK security technical control themes.

An individual control can support more than one framework requirement, but mapping coverage is not the same as certification or a blanket compliance assertion. Framework-specific applicability, implementation and review remain essential.
HOW IT WORKS

Collect once. Assess appropriately. Reuse where mapped.

The platform supports manual evidence and selected integration-driven collection from Microsoft, AWS, Google Workspace, GitHub and Qualys.

01 / ADOPTScope your controls

Choose relevant controls and establish applicability, accountability and assessment ownership.

02 / COLLECTGather supporting facts

Attach manual evidence or collect supported technical observations through approved provider connections.

03 / ASSESSTest what is evaluable

Use narrow control checks and human review. Unavailable provider information must not be treated as a pass.

04 / MAPUnderstand obligations

Connect the reviewed control and its evidence to applicable framework requirements and reporting.

REALISTIC USE CASES

What control assurance looks like in practice.

The examples describe supported workflows and assessment themes; they are not an exhaustive or authoritative control-to-clause crosswalk.

Identity and MFA

Central identity-policy evidence may help assess an adopted access control; the relevant framework mappings reuse that assessment.

Repository change protection

Approved branch protection and review settings can support a narrow change-management control test.

High-risk vulnerabilities

Available scanner and code-security observations can help evaluate timely exposure review and treatment.

Supplier oversight

Supplier assessment and dependency records support governance and risk-review activities alongside technical evidence.

See the controls behind your requirements.

Request a walkthrough of the current PurpleWASP control catalogue, the exact approved mappings, and how evidence is reviewed within your organisation’s scope.

The 124-control catalogue and five-framework presentation reflect the established platform baseline; detailed control-by-control IDs and mappings should be confirmed against the current canonical catalogue before public publication.