Skip to content

Control Management

The Control Scoping section is where you select which SCF controls apply to your organization and track their implementation progress. This is the foundation of your compliance program.

Click the Target icon in the sidebar or select Control Scoping from the navigation.

The interface is split into two panels:

The left panel displays all available SCF controls with:

  • Stats header — Shows selected count, implemented count, and gap (unselected controls)
  • Progress bar — Visual indicator of implementation progress
  • Advanced Stats — Expandable gap analysis by domain, theme, and type
  • Bulk actions — Select All / Deselect All buttons
  • Search — Filter by control ID, name, or domain
  • Framework filter — Show only controls mapped to a specific framework
  • Control cards — Each card shows:
    • Checkbox for selection
    • Control ID and implementation status badge
    • Control name
    • Domain and metadata (artifact count, framework count)
    • Theme and type badges

When you select a control, the right panel shows:

  • Control header — ID, name, domain, theme, and type
  • Control Details section — Description, policy standard, implementation guidance, testing procedure
  • Implementation Tracking section — All the fields you can configure
  • Audit Artifacts section — Evidence items required by this control
  • Framework Mappings section — Which frameworks this control satisfies
  • Comments section — Discussion thread for team collaboration
  1. Click the checkbox on any control card to toggle its selection
  2. Or open a control and check “Include this control in scope”

Use the bulk action buttons above the search field:

ButtonAction
✓ Select AllSelects all controls matching current filter
✗ Deselect AllDeselects all controls matching current filter

For each scoped control, you can track:

StatusWhen to Use
Not StartedControl is scoped but no work has begun
In ProgressImplementation work is underway
ImplementedControl is fully operational
At RiskImplementation is delayed or has issues
Not ApplicableControl doesn’t apply to your environment
DeferredIntentionally postponed to a future date

Set the implementation priority:

  • Critical — Must be addressed immediately
  • High — Should be completed soon
  • Medium — Normal priority
  • Low — Can be addressed when resources allow

Assess how mature your control implementation is:

LevelDescription
InitialAd-hoc, inconsistent processes
DevelopingRepeatable but undocumented
DefinedDocumented and standardized
ManagedMonitored and measured
OptimizedContinuously improving
  • Owner Team — Select the responsible team (e.g., Security Operations, DevSecOps, GRC)
  • Assigned To — Specify the individual responsible (email address)
  • Completion Date — Target or actual completion date
  • Selection Reason — Document why this control was selected
  • Implementation Notes — Describe how the control is implemented

Link to policies, procedures, or other documents:

  1. Click + Add Document
  2. Enter a Document ID (e.g., “POL-001”)
  3. Optionally add a URL to the document
  4. Click the button to remove a document

Click ▼ Advanced Stats to expand the gap analysis panel, which shows:

See how many controls are selected vs. total for each control domain (Access Management, Data Security, etc.). A checkmark (✓) means full coverage; a number shows the gap.

Analyze coverage by theme:

  • Protect — Preventive controls
  • Detect — Monitoring and detection
  • Respond — Incident response
  • Recover — Business continuity

Coverage breakdown by control type:

  • Technical — Technology-based controls
  • Administrative — Policy and procedure controls
  • Physical — Physical security controls

The Audit Artifacts section shows evidence items required by the selected control:

  • Tracking status — ✅ (tracked) or ⚪ (not tracked)
  • Artifact ID — Unique identifier
  • Artifact title — Description of the evidence
  • Collecting system — System responsible for collecting this evidence (if tracked)

Artifacts are grouped by domain for easier navigation.

The Framework Mappings section shows which compliance frameworks this control satisfies and the specific requirement references (e.g., “A.9.1.1” for ISO 27001).

This helps you understand the compliance value of each control—controls mapped to many frameworks provide broader coverage.

If the control has been saved to the database, you can assign team members using the Assignment Picker.

Add comments to discuss implementation details, raise questions, or document decisions. Comments support:

  • Threaded discussions
  • @mentions (if configured)
  • Timestamp tracking

All changes are automatically saved as you make them. You’ll see a ”💾 Saving…” indicator briefly appear when changes are being persisted.


  1. Start with a framework — Filter by your primary compliance target
  2. Bulk select — Use “Select All” to include all relevant controls
  3. Review and refine — Deselect controls that don’t apply to your environment
  1. Update status regularly — Keep implementation status current
  2. Document as you go — Add implementation notes when completing work
  3. Use completion dates — Track actual vs. planned completion
  4. Assess maturity — Periodically review and update maturity levels
  1. Assign ownership — Every scoped control should have an owner team
  2. Use comments — Discuss implementation approaches in the comments
  3. Link documentation — Connect controls to policies and procedures