Compliance frameworks
Compliance frameworks
A framework pack saves you from typing a standard’s control set into the library by hand. Find them under Settings → Frameworks.
Available packs
- ISO 27001 Annex A — information security controls.
- NIST Cybersecurity Framework 2.0
- SOC 2 Trust Services Criteria
Installing a pack
Installation is a five-step review. Nothing is written until you confirm on the final step.
- Intro — what the framework is and what the pack contains.
- Fields — the custom fields it will add.
- Controls — every control, with its clause mapping. Review this list; it is the bulk of what you are importing.
- Matrix — an optional assessment matrix that comes with the pack.
- Review — the complete summary, and the point of no return.
You are never installing blind. Each step lists exactly what will be created, so you can decide whether the pack fits your organisation before anything touches your library.
After installing
The framework appears as a card. Its menu offers:
| Action | What it does |
|---|---|
| Check for updates | Pull revisions when the standard changes. |
| Manage applicability (SoA) | Mark which controls apply to your organisation and justify exclusions. |
| Crosswalk | Map this framework’s controls to another framework’s, so one control can evidence both. |
| Save as custom | Fork the pack so you can modify it without losing updates to the original. |
| Uninstall | Remove the pack. Controls already attached to risks are retained. |
Statement of Applicability is not yet available. The SoA is a mandatory artefact for ISO 27001 certification, and the menu item is present but the feature is not built. Do not plan a certification timeline around it until it ships.