Help center

Help center

All collectionsControlsAssuranceRead framework coverage and the Controls overview

Read framework coverage and the Controls overview

Use the Controls overview to see how well your controls are working and how much of the estate is tested, drill from standard down to evidence, and check which clauses of a standard have controls behind them.

Use the Controls overview to see how well your controls are working and how much of the estate is tested, drill from standard down to evidence, and check which clauses of a standard have controls behind them.

Two pages answer the question an auditor or management review asks first: are the controls working, and do they cover the standard? The Controls overview summarises the whole control library. Framework coverage takes one standard and shows, clause by clause, which clauses have controls behind them and which do not.

Who can use these pages

Product location: /qms/controls/dashboard. Open Overview in Controls.

Anyone with View controls (controls:view_controls) can open both pages and drill through the overview. Suggest mappings from the catalogue on Framework coverage creates requirement links, so it also needs the QMS permission Manage Requirements (qms:manage_requirements). The button is shown only to people who hold it.

Open the Controls overview

Product location: /qms/controls/dashboard. Open Overview in Controls.

Open Overview in Controls; see finding your way around Controls. The page, Controls overview, shows four tiles, any warnings, and Explore the estate. Every figure is calculated when you open the page.

Read the four tiles

Product location: /qms/controls/dashboard. Open Overview in Controls.

Tile

What it shows

Choose it to

Overall effectiveness

The average effectiveness score of your active, in-scope controls as a percentage, or Cannot say yet. Beneath: how many controls it covers, for example Across 48 control(s), and how many have slipped because their testing is overdue.

Open the drill at the Control level.

Tested coverage

The share of applicable estate targets that have been tested, for example 31 of 40 applicable targets tested, and how many controls apply to nothing yet and so are not counted.

Open the drill at the Control level.

Open exceptions

Deficiencies that are open, being fixed or awaiting retest, with how many were raised in the last 30 days and how many have been open for more than 180. When any are that old, the tile also names the age of the oldest.

Open the Deficiency register.

Tests due

How many implementations are on a schedule, and how many are already past their date.

Open the Due board.

A control's rating follows its score: Working from 85%, Partly working from 40%, and Not working below that. Not yet known means there is no score, because the control has never been tested or its last test was not assessed.

Tested coverage depends on scoping each control to the estate targets it applies to. A control scoped to nothing is not counted as untested; it is left out and counted in the note beneath. See where a control operates.

Why it says Cannot say yet

Product location: /qms/controls/dashboard. Open Overview in Controls.

The overall figure covers active controls that are in scope; draft, retired and excluded controls are left out. It is shown only when every control it covers has a known rating. If even one control is Not yet known, the tile shows Cannot say yet and the panel The overall figure cannot be stated yet explains how many controls are untested and how many of those are key controls. An average of only the tested controls would look better than the evidence supports, so none is shown.

Ratings also age when testing falls behind. By default:

Next test overdue by

Effect on the control's rating

Up to 14 days

None.

More than 14 days

Drops one step: Working becomes Partly working. Lateness alone never makes a control Not working.

180 days or more

Becomes Not yet known.

Test the controls named in the panel and the figure appears.

Act on the warning panels

Product location: /qms/controls/dashboard. Open Overview in Controls.

  • The overall figure cannot be stated yet: plan tests for the untested controls, starting with key controls. Use the Due board to see who holds each one.

  • Some exclusions have no reason recorded: one or more controls are marked Not in scope or Partly applicable without a reason. Open each control and give the reason on its Scope and handling tab. A Statement of Applicability cannot be submitted while any row lacks a reason; see the Statement of Applicability.

Explore the estate

Product location: /qms/controls/dashboard. Open Overview in Controls.

Explore the estate walks from a standard down to an individual evidence file without leaving the page.

  1. Choose Explore the estate. The list starts at the Standard level, showing the standards whose control packs you have adopted.

  2. On a row, choose the button for the next level, for example Pack. The list narrows to that row.

  3. Continue down through Control, Implementation, Test and Evidence.

  4. To go back up, choose an earlier level in the breadcrumb. Choices made below that level are dropped.

  5. Choose Close to close the drill.

Level

Rows

Badge

Standard

Standards with adopted control packs

None

Pack

Adopted packs under the standard

None

Control

Controls that are not retired

Effective, Partly effective, Not effective or Not tested

Implementation

Implementations that are not retired, with their target

The target kind, for example AWS

Test

Test results, excluding results replaced by a correction

Operated effectively, Operated with exceptions, Did not operate or Not assessed

Evidence

Evidence items, excluding replaced items

The evidence type, for example Form submission

Showing 12 of 12 tells you how many rows exist at the current level. Controls you authored yourself belong to no pack, so reach them through the Overall effectiveness or Tested coverage tile, which open the drill at the Control level for all controls.

Open framework coverage

Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open the standard's framework coverage, or open Library in Controls, choose the standard in the Standard filter and choose Framework coverage.

Open the standard in QMS and go to its framework coverage, or from Controls:

  1. Open Library in Controls.

  2. Choose the standard in the Standard: any filter.

  3. Choose Framework coverage in the filter row.

Read the coverage tiles

Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open Framework coverage for the standard.

Tile

What it counts

Clauses with no control

Clauses in scope with no control linked. This is what an auditor looks for first.

Awaiting review

Clauses in scope covered only by suggestions nobody has confirmed. Not a gap, but not yet evidence either.

Clauses in this standard

Every active clause, whether in scope or excluded.

Scope comes from the standard's Scope Management. A clause you have marked Out of Scope there, with a justification, is a decision rather than a gap. A clause marked Partially Applicable is shown as partial coverage. See setting the standard's scope. Retired controls never count as coverage.

Filter and read the clauses

Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open Framework coverage for the standard and use Show.

Use Show to choose the rows: Clauses with no control (the default), Awaiting review or Every clause. Rows are sorted with gaps first, then clauses awaiting review, then covered clauses, then excluded ones.

Column

What it shows

Clause

The clause code and text.

Scope

In scope, Excluded or Partly applicable, from the standard's scope.

Controls

How many controls are linked to the clause.

Reviewed

How many of those links someone has confirmed.

Working

How many linked controls are rated Working, with the number not yet tested, for example 2 (1 not yet tested).

Coverage

The clause's state, as below.

Coverage

Meaning

No control

In scope and nothing linked.

Awaiting review

Linked only through suggestions nobody has confirmed.

No primary control

At least one link is confirmed, but no link says a control is the primary way the clause is met.

Covered

At least one link is confirmed and at least one is marked Primary.

Excluded

The clause is out of scope, so it is not assessed as a gap.

When Clauses with no control is empty, the page reads Every clause in scope has a control.

Suggest mappings from the catalogue

Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open Framework coverage for the standard and choose Suggest mappings from the catalogue.

Suggest mappings from the catalogue adds the mappings that ComplyTrain's control catalogue defines for the controls you adopted from packs. It never changes a link that already exists, so you can run it again safely.

  1. Choose Suggest mappings from the catalogue.

  2. Read the result, for example 4 new suggestions added. Zero means everything the catalogue proposes is already linked.

  3. Switch Show to Awaiting review.

  4. For each clause, open the control and confirm or remove the suggestion on its Requirements tab, choosing Primary, Supporting or Partial coverage first. See mapping controls to requirements.

A suggestion counts under Awaiting review until it is confirmed. Controls you authored yourself get no catalogue suggestions; map them by hand.

Example: prepare a surveillance audit

Product location: /qms/controls/dashboard. Open Overview in Controls.

Six weeks before the ISO 27001 surveillance audit, the information security manager checks where the organisation stands.

  1. On the Controls overview, Overall effectiveness reads Cannot say yet. The panel says 6 of 48 controls have never been tested, 2 of them key controls. The manager asks the owners to test those two first.

  2. Open exceptions shows 3, one open for more than 180 days. The manager opens the Deficiency register and escalates it.

  3. The manager opens Framework coverage for ISO 27001. Clauses with no control shows 2: A.5.7 and A.5.30.

  4. The manager chooses Suggest mappings from the catalogue and reads 3 new suggestions added. A.5.30 moves to Awaiting review, and the manager confirms its link as Primary on the control's Requirements tab.

  5. A.5.7 still has no control. The manager creates a threat-intelligence control, maps it to A.5.7 and reopens the page: Clauses with no control now reads 0.

Where coverage appears elsewhere

Product location: /qms/{standardCode}/scope (fallback: /qms/standards). Open the standard in QMS and choose Scope Management.

  • In QMS, the standard's Scope Management list shows the controls linked to each clause, and each links to the control.

  • The Statement of Applicability is built from the same links once they are confirmed.

  • The deficiencies behind Open exceptions are worked in the register; see deficiencies and exceptions.

Did this answer your question?
😞
😐
😁