Skip to content

Reference controls

A reference control is a template, not a thing you operate. It describes a control in the abstract — “multi-factor authentication on remote access”, “annual security awareness training” — so that when the same expectation shows up in four frameworks you create one applied control from the template instead of four near-identical ones with different wording.

Catalog → Reference controls in the sidebar.

The distinction is the one that trips people up most often:

Reference controlApplied control
What it isA catalog templateSomething your organization actually does
Lives inThe catalogYour action plan
Has a status?NoYes — To do through Active
Has an owner, ETA, cost?NoYes
How manyOne per control conceptOne per implementation

You never “implement” a reference control. You derive an applied control from it, and that is what carries the status, owner, deadline and evidence.

Every reference control can declare a Category, which says what kind of thing it is: Policy, Process, Procedure, Technical or Physical. The category is what lets you answer questions like “how much of our posture is documentation and how much is actually enforced by a system” — a control set that is ninety percent policy is a warning sign.

The CSF Function field places the control on the NIST Cybersecurity Framework axis: Govern, Identify, Protect, Detect, Respond or Recover. This is the field behind the radial chart on the Analytics summary tab, and it is the fastest way to spot a lopsided programme — plenty of Protect, almost no Detect or Recover, which is the most common shape in practice.

Reference ID and Name identify the control, Description states what it requires, Provider records who publishes it, Domain scopes it, and Labels let you tag it your own way. Many imported controls also carry typical evidence — the artefacts an assessor would expect to see — which is useful guidance when you are deciding what to attach to the derived applied control.

Two sources, both normal:

  • Libraries. The import shortcut takes you to Libraries filtered to reference-control content. Framework libraries frequently ship with an accompanying control set, already linked to the requirements they satisfy.
  • Your own. Add reference control creates one directly. Use this when your organization has a standard way of doing something that no published catalog describes.

Search covers name, reference ID and category; filters cover provider, domain, category, CSF function and labels.

The payoff comes at audit time. When a framework’s requirements point at reference controls, CyberGuard can propose the applied controls that satisfy each requirement and attach them for you, rather than leaving every assessor to invent a control from scratch. That is what keeps naming consistent across a large programme — the same expectation produces the same control, however many audits reach it.

  • Applied controls — what you derive from these templates.
  • Frameworks — requirements that suggest reference controls.
  • Libraries — where control catalogs are loaded from.
  • Threats — what the controls are there to address.