Configure objectives and controls
On the Controls step of the framework builder, build the objective tree and open each control's attributes to set its response type, category, risk, guidelines, and recommendations.
Try it in CybervergentOverview
Set up objectives, sub-objectives, controls, and each control's assessment, risk, and guidance.
Step-by-step
- 1 On the Controls step of the framework builder, click 'Add Objective'. Each objective appears as a tab you can drag to reorder, and you can rename it from its hover menu.
- 2 Inside an objective, click 'New Sub-Objective' to add a sub-objective collapse section.
- 3 Within a sub-objective, click 'Add Control' to add a control row, then type the control text in the 'Control' field. Use 'Import Control' to bring in existing controls.
- 4 In the 'Evidence' column of a control, select one of the artefacts you defined on the Artefacts step.
- 5 Click the control's settings icon to open 'Control attributes'.
- 6 On the 'Assessment' tab, select the category and the response type: 'Pre-defined Options', 'Text', 'Date', 'Number', 'Table' (build columns), or 'Formula'.
- 7 On the 'Guideline' tab, click 'New Guideline' to add guidance the respondent will see.
- 8 On the 'Risk' tab, set the 'Likelihood of control risk' and the 'Impact of control risk'.
- 9 On the 'Assist' tab, click 'New Recommendation' to add audit recommendations.
- 10 Close the drawer and repeat for each control, then continue to the Monitors step.
Related articles
Frameworks & Standards Build a custom framework Create a framework end to end: type, response options, artefacts, categories, controls, and monitors. Frameworks & Standards Add third-party and monitoring objectives Use the ready-made objectives for fourth-party exposure and continuous monitoring. Compliance Posture Read and manage your compliance posture Find your compliance posture score, understand what drives it, and use automation and monitoring to keep it live. Compliance Initiatives Create a compliance initiative Launch a compliance program against a framework, with dates, mapping, owners, and governance.