Controls

Controls

Search, filter, bulk-update, and export the control directory.

RolesViewerEditorAdminRoute/controlsShown toCompliance organizations

What it is

Controls are the individual requirements your enabled frameworks expect you to meet. Each control has a status, an owner, and a coverage percentage that says how much of its required evidence is in place. The controls page is the directory: search and filter it, change statuses for many controls at once, export it as a spreadsheet or a Statement of Applicability, and open any control for the detail work described in Control detail.

Where to find it

Controls
The controls table with the filter sidebar, insight strip, and status columnThe controls table with the filter sidebar, insight strip, and status column
The controls page. The insight strip at the top summarises coverage and statuses.

The insight strip shows a Coverage meter and counts for Controls, Implemented, In progress, and Pending review.

Key actions

Search and filter

The search box reads "Search controls by name, ID, or framework…". The filter sidebar has sections for Framework, Framework Reference, Status, Domain, and Owner. Filters live in the URL, so the browser's back button restores them and a filtered view can be shared as a link.

Choose columns

Open the Columns menu ("Toggle columns") to show or hide Control ID, Name, Domain, Framework References, Status, Owner, Coverage, and Last Updated.

Change status in bulk

Select controls with the row checkboxes.
In the bulk bar, click Implemented, In progress, N/A, or Pending review.
Read the toast. Controls that could not change are reported, not silently skipped.

Two guards apply. A control can only be set to implemented when its coverage is 100%; the inline Implemented button on a row explains "Control must have 100% coverage to be implemented". Archived controls cannot be changed in bulk. Viewers see the text Read-only access instead of the buttons.

Export controls or the SoA

Open the export action in the header to get the Export controls dialog.
Choose Controls spreadsheet and tick the frameworks to include, or All frameworks.
Or choose Statement of Applicability (SoA). The dialog notes it "Generates the applicability statement for all 93 ISO 27001:2022 Annex A controls. Framework selection doesn't apply." It needs ISO 27001 enabled.
Click Download .xlsx or Download .csv.
The Export controls dialog with Controls spreadsheet and Statement of Applicability optionsThe Export controls dialog with Controls spreadsheet and Statement of Applicability options
The export dialog. The SoA option is available only with ISO 27001 enabled.

Open a control

Click a row to open /controls/[id], where you set status and owner, link evidence, write notes, and read guidance and history. See Control detail.

Statuses and fields

StatusMeaningSet by
Not Implementednot_implementedNothing is in place yetDefault, or you
In Progressin_progressSomeone is working on itYou
ImplementedimplementedThe control operates and all required evidence is linkedYou at 100% coverage, or the coverage engine
Pending Reviewpending_reviewCoverage dropped below 100% on an implemented control, or you asked for a reviewCoverage engine, or you
Not Applicablenot_applicableExcluded from scope with a justification; the SoA records itYou

Archived controls exist but cannot be bulk-updated and are never changed by the coverage engine.

ColumnMeaning
Control IDNoru's identifier for the control
Framework ReferencesThe clause or criterion in each framework that maps to it
CoverageShare of required evidence items that are satisfied
OwnerThe member accountable for it

Tips and gotchas

Coverage decides Implemented

When coverage reaches 100% the control becomes implemented on its own, and when it later drops the control moves to pending review. Setting a status by hand does not exempt a control from this rule; only archived and not applicable are left alone. See Control status and coverage.

Filter by Status pending review after each sync. Those are the controls whose evidence expired or whose source changed.

N/A in bulk applies to every selected control. Use it for a filtered set you have reviewed, not for a whole framework.

With no framework enabled the page shows No controls found, "Controls are added when you enable a compliance framework…", and Add a framework, which opens Settings → Frameworks.

What Noru does not do

Noru does not decide applicability for you; Not Applicable is your statement and the SoA repeats it. Bulk Implemented does not link evidence, and an export is a snapshot with no link back to the live records.

Last updated on