Controls

Control detail

Own a control: set status, link evidence and policies, add notes, and read guidance and history.

RolesViewerEditorAdminRoute/controls/[id]Shown toCompliance organizations

What it is

The control page is where one control gets done. It holds the status and owner, the evidence slots the control requires and what fills them, notes for the auditor, implementation and testing guidance, and the history of every status change. Coverage, the number that decides whether a control can be implemented, is computed from what you link here.

Where to find it

Controlsany row

The breadcrumb reads Controls followed by the control's name. The page has three sections: Control Details, Evidence, and Notes, plus two accordions, Guidance & testing and Audit history.

A control page with the property rows, evidence slots, notes, and the guidance accordionA control page with the property rows, evidence slots, notes, and the guidance accordion
A control with one evidence slot filled and one required policy outstanding.

Key actions

Set the status

In Control Details, open the Status row. It shows Set status while empty.
Pick Not Implemented, In Progress, Implemented, Pending Review, or Not Applicable.
Implemented is accepted only when coverage is 100%. Link the missing evidence first, or the option is refused.
StatusUse it when
Not ImplementedNothing is in place; the default for a new framework
In ProgressSomeone owns it and work has started
ImplementedThe control operates and every required evidence item is linked and valid
Pending ReviewEvidence lapsed or changed; also set by the coverage engine when coverage drops
Not ApplicableThe control is out of scope; record the justification in Notes, it feeds the SoA

Assign an owner

Open the Owner row and pick a member. Owners see the control in Tasks and are the default recipient of review reminders. The Control reference and Last updated rows are read-only.

The link evidence dialog with Link Existing and Upload New tabs and the target selectorThe link evidence dialog with Link Existing and Upload New tabs and the target selector
The link dialog. The selector decides which requirement the evidence satisfies.

The Evidence section lists the control's required items. Each slot says what it expects; a "Required policy" slot is satisfied by an approved policy linked to the control.

Click the link action on the slot or on the section.
On the Link Existing tab, use "Search evidence or policies..." to find something already in the vault or the policy list.
Or switch to Upload New to add a file, link, or note in place.
Under "Link this evidence to", pick the specific requirement, or The control generally for supporting evidence that does not fill a slot.
Click Upload & link (or the link button on the existing tab). Coverage recalculates.

Evidence linked as The control generally appears under "General supporting evidence". It is visible to an auditor but does not count toward coverage.

Write notes

The Notes textarea is free text saved with Save. Use it for implementation detail, the applicability justification, or pointers an auditor will want.

Read guidance and history

Guidance & testing holds implementation guidance, testing guidance, and an applicability note for the control. Audit history lists the review log: who changed the status, when, and from what.

Statuses and fields

RowMeaning
StatusThe five values above; Set status until chosen
Control referenceThe framework clause or criterion this control maps to
Last updatedTime of the last change to the control or its links
OwnerThe accountable member
CoverageSatisfied required items divided by required items; a control with no requirements counts as 100%

The coverage rule

Coverage counts only qualified evidence. Uploaded files, links, and notes qualify. Evidence synced from data sources qualifies. Platform register rows, such as the personnel directory appearing as evidence, do not, with one exception: the assets register satisfies the asset inventory control once at least one asset exists. Links from other modules never qualify. When coverage hits 100% the control becomes Implemented on its own; when an implemented control's coverage drops, it becomes Pending Review. Archived and not applicable controls are never changed automatically.

Tips and gotchas

Approve the policy before chasing the rest. One approved policy can fill the "Required policy" slot on every control that expects it.

Deleting evidence from the vault removes it from every control it was linked to, and coverage drops on each of them. Check Linked controls in the evidence drawer first.

Viewers can open the page, read notes, and expand the accordions, but every control is disabled for them.

What Noru does not do

Noru does not judge whether linked evidence actually demonstrates the control; it checks that a slot is filled with evidence of the expected kind and that the evidence is valid. A control at 100% coverage is complete in Noru's terms, not necessarily in an auditor's. Notes are not versioned.

Last updated on