Use the Controls overview to see how well your controls are working and how much of the estate is tested, drill from standard down to evidence, and check which clauses of a standard have controls behind them.
Two pages answer the question an auditor or management review asks first: are the controls working, and do they cover the standard? The Controls overview summarises the whole control library. Framework coverage takes one standard and shows, clause by clause, which clauses have controls behind them and which do not.
Product location: /qms/controls/dashboard. Open Overview in Controls.
Anyone with View controls (controls:view_controls) can open both pages and drill through the overview. Suggest mappings from the catalogue on Framework coverage creates requirement links, so it also needs the QMS permission Manage Requirements (qms:manage_requirements). The button is shown only to people who hold it.
Product location: /qms/controls/dashboard. Open Overview in Controls.
Open Overview in Controls; see finding your way around Controls. The page, Controls overview, shows four tiles, any warnings, and Explore the estate. Every figure is calculated when you open the page.
Product location: /qms/controls/dashboard. Open Overview in Controls.
Tile | What it shows | Choose it to |
|---|---|---|
Overall effectiveness | The average effectiveness score of your active, in-scope controls as a percentage, or Cannot say yet. Beneath: how many controls it covers, for example Across 48 control(s), and how many have slipped because their testing is overdue. | Open the drill at the Control level. |
Tested coverage | The share of applicable estate targets that have been tested, for example 31 of 40 applicable targets tested, and how many controls apply to nothing yet and so are not counted. | Open the drill at the Control level. |
Open exceptions | Deficiencies that are open, being fixed or awaiting retest, with how many were raised in the last 30 days and how many have been open for more than 180. When any are that old, the tile also names the age of the oldest. | Open the Deficiency register. |
Tests due | How many implementations are on a schedule, and how many are already past their date. | Open the Due board. |
A control's rating follows its score: Working from 85%, Partly working from 40%, and Not working below that. Not yet known means there is no score, because the control has never been tested or its last test was not assessed.
Tested coverage depends on scoping each control to the estate targets it applies to. A control scoped to nothing is not counted as untested; it is left out and counted in the note beneath. See where a control operates.
Product location: /qms/controls/dashboard. Open Overview in Controls.
The overall figure covers active controls that are in scope; draft, retired and excluded controls are left out. It is shown only when every control it covers has a known rating. If even one control is Not yet known, the tile shows Cannot say yet and the panel The overall figure cannot be stated yet explains how many controls are untested and how many of those are key controls. An average of only the tested controls would look better than the evidence supports, so none is shown.
Ratings also age when testing falls behind. By default:
Next test overdue by | Effect on the control's rating |
|---|---|
Up to 14 days | None. |
More than 14 days | Drops one step: Working becomes Partly working. Lateness alone never makes a control Not working. |
180 days or more | Becomes Not yet known. |
Test the controls named in the panel and the figure appears.
Product location: /qms/controls/dashboard. Open Overview in Controls.
The overall figure cannot be stated yet: plan tests for the untested controls, starting with key controls. Use the Due board to see who holds each one.
Some exclusions have no reason recorded: one or more controls are marked Not in scope or Partly applicable without a reason. Open each control and give the reason on its Scope and handling tab. A Statement of Applicability cannot be submitted while any row lacks a reason; see the Statement of Applicability.
Product location: /qms/controls/dashboard. Open Overview in Controls.
Explore the estate walks from a standard down to an individual evidence file without leaving the page.
Choose Explore the estate. The list starts at the Standard level, showing the standards whose control packs you have adopted.
On a row, choose the button for the next level, for example Pack. The list narrows to that row.
Continue down through Control, Implementation, Test and Evidence.
To go back up, choose an earlier level in the breadcrumb. Choices made below that level are dropped.
Choose Close to close the drill.
Level | Rows | Badge |
|---|---|---|
Standard | Standards with adopted control packs | None |
Pack | Adopted packs under the standard | None |
Control | Controls that are not retired | Effective, Partly effective, Not effective or Not tested |
Implementation | Implementations that are not retired, with their target | The target kind, for example AWS |
Test | Test results, excluding results replaced by a correction | Operated effectively, Operated with exceptions, Did not operate or Not assessed |
Evidence | Evidence items, excluding replaced items | The evidence type, for example Form submission |
Showing 12 of 12 tells you how many rows exist at the current level. Controls you authored yourself belong to no pack, so reach them through the Overall effectiveness or Tested coverage tile, which open the drill at the Control level for all controls.
Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open the standard's framework coverage, or open Library in Controls, choose the standard in the Standard filter and choose Framework coverage.
Open the standard in QMS and go to its framework coverage, or from Controls:
Open Library in Controls.
Choose the standard in the Standard: any filter.
Choose Framework coverage in the filter row.
Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open Framework coverage for the standard.
Tile | What it counts |
|---|---|
Clauses with no control | Clauses in scope with no control linked. This is what an auditor looks for first. |
Awaiting review | Clauses in scope covered only by suggestions nobody has confirmed. Not a gap, but not yet evidence either. |
Clauses in this standard | Every active clause, whether in scope or excluded. |
Scope comes from the standard's Scope Management. A clause you have marked Out of Scope there, with a justification, is a decision rather than a gap. A clause marked Partially Applicable is shown as partial coverage. See setting the standard's scope. Retired controls never count as coverage.
Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open Framework coverage for the standard and use Show.
Use Show to choose the rows: Clauses with no control (the default), Awaiting review or Every clause. Rows are sorted with gaps first, then clauses awaiting review, then covered clauses, then excluded ones.
Column | What it shows |
|---|---|
Clause | The clause code and text. |
Scope | In scope, Excluded or Partly applicable, from the standard's scope. |
Controls | How many controls are linked to the clause. |
Reviewed | How many of those links someone has confirmed. |
Working | How many linked controls are rated Working, with the number not yet tested, for example 2 (1 not yet tested). |
Coverage | The clause's state, as below. |
Coverage | Meaning |
|---|---|
No control | In scope and nothing linked. |
Awaiting review | Linked only through suggestions nobody has confirmed. |
No primary control | At least one link is confirmed, but no link says a control is the primary way the clause is met. |
Covered | At least one link is confirmed and at least one is marked Primary. |
Excluded | The clause is out of scope, so it is not assessed as a gap. |
When Clauses with no control is empty, the page reads Every clause in scope has a control.
Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open Framework coverage for the standard and choose Suggest mappings from the catalogue.
Suggest mappings from the catalogue adds the mappings that ComplyTrain's control catalogue defines for the controls you adopted from packs. It never changes a link that already exists, so you can run it again safely.
Choose Suggest mappings from the catalogue.
Read the result, for example 4 new suggestions added. Zero means everything the catalogue proposes is already linked.
Switch Show to Awaiting review.
For each clause, open the control and confirm or remove the suggestion on its Requirements tab, choosing Primary, Supporting or Partial coverage first. See mapping controls to requirements.
A suggestion counts under Awaiting review until it is confirmed. Controls you authored yourself get no catalogue suggestions; map them by hand.
Product location: /qms/controls/dashboard. Open Overview in Controls.
Six weeks before the ISO 27001 surveillance audit, the information security manager checks where the organisation stands.
On the Controls overview, Overall effectiveness reads Cannot say yet. The panel says 6 of 48 controls have never been tested, 2 of them key controls. The manager asks the owners to test those two first.
Open exceptions shows 3, one open for more than 180 days. The manager opens the Deficiency register and escalates it.
The manager opens Framework coverage for ISO 27001. Clauses with no control shows 2: A.5.7 and A.5.30.
The manager chooses Suggest mappings from the catalogue and reads 3 new suggestions added. A.5.30 moves to Awaiting review, and the manager confirms its link as Primary on the control's Requirements tab.
A.5.7 still has no control. The manager creates a threat-intelligence control, maps it to A.5.7 and reopens the page: Clauses with no control now reads 0.
Product location: /qms/{standardCode}/scope (fallback: /qms/standards). Open the standard in QMS and choose Scope Management.
In QMS, the standard's Scope Management list shows the controls linked to each clause, and each links to the control.
The Statement of Applicability is built from the same links once they are confirmed.
The deficiencies behind Open exceptions are worked in the register; see deficiencies and exceptions.