Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guidePurpleWASP brings policies, risks, assets and compliance activity into one operational environment so teams can see ownership, decisions and progress in context.
Each module can support a focused workflow, while shared ownership and records help teams understand the wider operational context.
Create, review, approve, publish and assign policies with version history and accountability.
Record risk scenarios, complete assessments and document controls, treatment decisions and exceptions.
Maintain ownership, classification and lifecycle data for the assets that support business activity.
Coordinate compliance obligations, control ownership, evidence collection, review activity, exceptions and remediation in one traceable workflow.
Each module gives the responsible team a clear place to manage records, actions and decisions.
Manage the lifecycle of policies and governed documents without losing review or publication history.
Move from risk identification to assessment, treatment and formal acceptance with clear accountability.
Build a dependable asset register with the ownership and classification data needed by other GRC workflows.
Coordinate obligations, controls, evidence, reviews and remediation without a separate spreadsheet chase.
Role-based access, approval workflows, notifications, record history and reporting help teams understand what changed, who is responsible and what needs attention next.
A phased rollout helps teams establish ownership and working practices before increasing scope.
Confirm scope, module owners, roles, access and the first business outcomes.
Clean the initial policy, risk, asset or compliance records before importing or creating them.
Prove the lifecycle, reporting and hand-offs with a manageable group before expanding.
Link related records and evidence only after ownership and operating cadence are working.
Administrators can manage users, role mappings, account status, groups, module access and security preferences. Two-factor authentication can be required according to organisation settings.
Discuss required modules, user roles, rollout scope and support expectations.