Control Library
The Control Library is a workspace-wide catalogue of security controls. Open it from Risk Manager → Libraries → Control Library. Each control records what the mitigation is, how much effort it requires, which lifecycle phases it applies to, and where to find training or implementation guidance. Controls can carry one or more Requirements — structured references to external standards, regulations, or internal tracking systems.
Control Fields
| Field | Description |
|---|---|
| Reference | Auto-generated identifier (e.g. C-001) |
| Control | Descriptive name of the control (required) |
| Category | Grouping category from the workspace catalog (required) |
| Effort/Cost | Relative effort to implement: Very Low, Low, Medium, High, or Very High |
| Applicable Lifecycle | One or more phases: Concept, Development, Production, Operations, Decommission |
| Link to Training | Optional label and URL pointing to training material or implementation guidance |
List View
The list table shows each control’s ID (its reference), Control name, Applicable Lifecycle, Effort/Cost, and Products in Use. The Products in Use column is not yet populated in this release. Only the ID cell is a link — click it to open the control’s detail page.
- Create — click New in the toolbar. The New Control dialog requires the control name and a category; fill in any optional fields, then click Create Control. You are taken straight to the new control’s detail page.
- Delete — click the delete icon on a row; a confirmation dialog appears before permanent removal.
Detail Page
The detail page header shows the control’s reference and name alongside an Edit button, which opens the control in a modal form dialog (Save Changes / Cancel), and a Delete button with a confirmation dialog. A Return to Control Library link navigates back to the list.
An always-visible Details card lists all control fields. Next to it are three tabs:
Requirements
Lists structured requirements attached to this control. Each requirement has:
| Field | Description |
|---|---|
| ID | External identifier — e.g. CS.00095, a regulation clause, or a DOORS ID |
| Requirement | Human-readable description of the requirement (required) |
| Link | Optional label and URL to the requirement in an external system (e.g. DOORS, Jira, Confluence) |
Use Add to open the Add Requirement dialog and the delete icon to remove a requirement.
The Requirements tab also contains a Test Cases card, which is not yet populated in this release.
Implemented By
Lists the workspace items that implement this control. Not yet populated in this release.
Effectiveness
Effectiveness metrics are not yet populated in this release.
Permissions
Any signed-in member of the workspace can view library entries. Creating, editing, or deleting a control (or its requirements) requires a permission granted by your workspace administrator; without it, the action is denied. The New, Edit, and delete controls are not hidden based on permissions, so they remain visible even if your role lacks access to use them.