App navigation: Risk → Control
The Control module maintains your organization’s catalog of security and compliance controls – the mitigations, safeguards, and procedures you have in place to manage risk. Controls are reusable and can be linked to multiple risks, policies, and authority document requirements.
Screen Layout #
Navigate to Risk → Control to open the Control Inventory screen. The Control Summary panel shows total controls by status and a review schedule overview.
[Screenshot: Control Inventory screen]
Creating a Control #
- Select + on the toolbar and choose Create Manually or Upload from File.
- Complete the control wizard:
- Name and Description (required).
- Control Type – Preventive, Detective, Corrective, or Compensating. Note: Compensating is a function type flag, not a separate category.
- Maintenance Frequency – how often this control must be reviewed or tested (e.g., Monthly, Quarterly, Annually).
- Assign Owner, Reviewer(s), and Approver(s).
- Link to Risks, Assets, or Authority Document citations.
[Screenshot: Control creation wizard]
Control Lifecycle #
Controls follow the Draft → Under Review → Awaiting Approval → Active lifecycle. Once active, controls are tested on their configured Maintenance Frequency and the results recorded in the Review Log.
Testing a Control #
See the Test a Control workflow for step-by-step instructions on recording test results and evidence.
Note: Controls that are linked to Risk Register entries via ATVEC Mapping reduce the residual risk score of those risks. Keeping controls up to date and tested is important for accurate risk reporting on the GRC Executive Dashboard.
