A control is the treatment used to lower a risk. It carries status, priority,
category, an owner, and a due date, and can be linked to risks, compliance
objectives, and documents. The same control can lower a risk and satisfy a
regulation’s objective at the same time — the list carries its own Risks
and Objectives columns with the respective relation counts.
Create a control
Priority offers Low, Medium, High, and Critical.
Recurrence decides whether Docusnap365 sets a next due date after each piece
of evidence. Every control carries the Evidence tab, one-time controls
included. For details, see
Documenting Evidence for Controls.
Unlike threats and vulnerabilities, the create dialog captures no description
— you add one later on the detail page.
A control can also be created directly from within a risk: it is created
independently and is then linked to the risk.
KPIs and filters
The list carries four KPIs: Total, In Progress, Completed, and
Overdue. Five buttons filter by Planned, In Progress, Implemented,
Overdue, and Without Responsible Person — there is no dedicated button for the
Open status.
Overdue filters on a due date before today and a status other than
Implemented. An already-implemented control past its due date does not
count as overdue.
Overdue and Without Responsible Person work well for a regular review: one shows
due dates that have already passed, the other controls with no one
accountable.
Bulk editing
The bulk selection offers Set Status, Assign Responsible, and Delete.
The first two open bulk editing in the sidebar and are limited to that one
field each.
Delete removes the selected controls directly, without going through the
sidebar. The page’s KPIs recalculate afterward.
Documenting Evidence for Controls covers a
control’s recurrence and evidence. For compliance, the control carries an
Objectives tab with reference, name, category, and regulation; an objective
has no detail page of its own; its regulation opens instead. Objectives
are assessed in
Activate and Assess Regulations.