Control Management
Adopt Controls into the organisation, establish scope and applicability, map framework coverage, link governance documents and Risks, track implementation and maintain manual or integration-generated assessments, evidence, testing, issues and exceptions over time.
From control catalogue to operating assurance
Control Management separates the reusable control definition from organisation adoption, Asset-level implementation and assurance activity.
Adopt catalogue Controls or maintain organisation-specific Controls.
Set organisation scope, applicability and framework relationships.
Track organisation-wide and Asset-specific implementation state.
Record assessments, tests, evidence and required governance-document relationships.
Manage issues, exceptions, verification and compensating Controls.
Move from adoption to assurance
Use these guides to establish the Control population and maintain evidence that Controls are operating as intended.
Applicability and implementation are different decisions
A Control can be applicable without being fully implemented. PurpleWASP also keeps organisation-level implementation separate from the state of that Control on an individual Asset.
- Adopted organisation Controls have their own identity; catalogue IDs are not interchangeable with organisation Control IDs.
- Framework mappings show coverage but do not by themselves prove implementation; the same organisation Control can support several frameworks.
- Evidence should be linked to the Control, assessment or test it supports; supported integrations can materialise evidence against already-adopted applicable Controls.
- Integration evidence does not automatically set the organisation Control implementation status.
- Control exceptions are distinct from Risk exceptions and can use compensating Controls where appropriate.
No guidance matches that search.