Applied controls
An applied control is the main building block of your action plan: the actual action your team has implemented or will implement to address a security need — technical, organizational, a process, a policy, a document. A single applied control can satisfy any number of requirements across any number of frameworks, so compliance work, risk scenarios and findings all point at the same control while evidence accumulates on it.
Where to find it
Section titled “Where to find it”Operations → Applied controls in the sidebar.
Key concepts
Section titled “Key concepts”Status lifecycle
Section titled “Status lifecycle”The Status field is the single signal that drives roll-ups across audits, dashboards and action plans:
| Status | Meaning | Counts as “in place”? |
|---|---|---|
| Undefined | Status not yet set | No |
| To do | Planned but not started | No |
| In progress | Being implemented | No |
| On hold | Started then paused | No |
| Active | Implemented and operating as intended | Yes |
| Degraded | Was active, now partially failing | Partial |
| Deprecated | Retired or superseded | No |
The target state is Active, not “Done” — a control is never finished; reaching Active starts the maintenance phase. Prefer Deprecated over deletion: a deprecated control keeps its history, evidence and requirement links for past-audit traceability.
Priority, owner and dates
Section titled “Priority, owner and dates”Each control carries a Priority (P1 to P4) for ranking work, an Owner responsible for it, an ETA (the estimated completion date — when it passes and the control isn’t Active, the control is flagged overdue), a Start date, and an Expiry date for controls with a limited lifetime.
The Cost block models the build-versus-run distinction: a one-shot Build cost amortized over a configurable period, and an annual Run cost. Each side takes a fixed cost and people days, converted to money using the daily rate from General settings, so the platform computes a single annual cost per control that rolls up into budget views.
Controls connect to the rest of the platform: evidences that prove the control operates, the requirement assessments it satisfies in audits, the assets it protects, an optional reference control template, and an external link for follow-up.
Working with applied controls
Section titled “Working with applied controls”Use the add button to create a control, or derive one from a reference control for consistency. The list supports search and filters by status, category, priority, owner or domain.
Analytics, flash and kanban modes
Section titled “Analytics, flash and kanban modes”Three alternative surfaces sit on top of the list:
- Analytics aggregates the portfolio — counts by status, priority and category, overdue controls and cost roll-ups.
- Flash mode deals the controls as one card at a time for rapid triage: update the status, confirm the ETA, move on.
- Kanban mode lays controls out as swim-lane columns by status, so dragging a card is how work progresses through the lifecycle.
