Adopt and scope Controls
Create the organisation Control population from the PurpleWASP catalogue, then establish applicability, framework coverage and Asset context.
Outcome
You will have an organisation-owned Control record with clear applicability and scope, ready for implementation tracking and assurance.
1. Adopt Controls
Open the Control catalogue and choose the Controls that your organisation needs. Where the interface supports multi-select, adopt several Controls in one action rather than opening each record individually.
- Use catalogue metadata and framework references to decide what should enter your organisation Control set.
- Do not adopt a Control solely because it appears in a framework; first consider scope and applicability.
- If a previously retired organisation Control is adopted again, PurpleWASP can restore the existing organisation record instead of creating a duplicate.
2. Set scope and applicability
Applicability is resolved from organisation scope, exclusions and more specific context. Record why the Control applies or why it is excluded where the workflow asks for a rationale.
3. Use Asset context
Where a Control applies to particular Assets, use the Asset relationship and per-Asset implementation state rather than treating the organisation-level status as proof that every Asset is covered.
- Confirm the correct Asset before recording implementation.
- Use the Asset view to understand which Controls are recommended or already adopted.
- Keep Asset-specific operating status separate from the organisation-wide Control lifecycle.
4. Review framework mappings and connected records
Framework mappings help demonstrate which requirements a Control supports. Review the mapping strength and the underlying requirement rather than treating the mapping as assurance evidence.
Use the Control edit/workspace tabs to keep the implementation connected to its wider governance context, including governance documents, Risks and evidence. Document expectations can identify which current governance documents the Control is expected to have, rather than treating every absent document as a readiness failure.
Verify the result
- The Control appears in the organisation Control register.
- Applicability and scope reflect the intended organisation or Asset context.
- Relevant framework mappings are visible.
- The implementation state is not being confused with applicability.
- Owners and review information are assigned where required.
Common problems
A catalogue Control is visible but cannot be managed
Confirm that it has been adopted into the organisation and that you are working with the organisation Control rather than the catalogue reference.
The Control appears applicable to the wrong Asset
Review the Asset taxonomy and the scope/exclusion rules that drive applicability, then refresh the Control context.
A framework mapping is present but the Control is not implemented
This is valid. Framework coverage, applicability and implementation are separate governance facts.