Getting started

Choose frameworks

Pick the standards and regulations in scope and understand what enabling a framework loads.

RolesAdminRoute/settings?tab=frameworksShown toAll organizations

What it is

Frameworks are the requirement sets your program is measured against: ISO 27001, SOC 2, GDPR, the EU AI Act, and so on. Enabling one links its controls and requirements to the organization, adds a plan tab to the dashboard, and offers to generate the policies it expects. You choose the first framework in the organization wizard; everything after that happens under Settings → Frameworks, which is admin-only.

Where to find it

SettingsFrameworks

The card is titled Frameworks and lists every framework Noru ships, each with a switch.

The Frameworks card with grouped framework rows, each with a switchThe Frameworks card with grouped framework rows, each with a switch
Frameworks are grouped by kind. Each row has a switch.

Frameworks appear in six groups: Security & Trust, Privacy, AI Governance, Financial & Industry, Government & Regional, and Other. Each row shows the logo, name, an optional Free badge, a description, and a switch. ISO 27001's row notes "Includes ISO 27002".

Key actions

Pick the first framework in the wizard

Step 1 of Create your organization asks for one starting framework. If you are unsure, take the one an auditor or customer has already asked you about. ISO 27001 is the usual starting point for security programs; GDPR is the usual one for privacy programs.

Enable a framework in Settings

Turn on the framework's switch.
A dialog offers policy generation: "New policies can be generated to meet" the framework's "requirements." It lists "New policies to generate" and, when you already have policies, "Policies to update", noting that "Approved policies will have a new draft version created." Click Generate Policies (or Regenerate Policies), or Skip for Now.

The toast "Policy regeneration has been queued successfully" confirms the job. Generated policies appear under Policies as drafts; the framework's controls appear at once under Controls.

Disable a framework

Turn the switch off and confirm. Controls and requirements leave scope; policies and evidence stay. For ISO 27001 the dialog adds "ISO 27002 will also be disabled." The full dialog text is on the Settings → Frameworks page.

Statuses and fields

Regulatory and auditable frameworks

KindFrameworksDashboard difference
RegulatoryGDPR, CCPA, EU AI ActNo Phase 03 Verification; readiness is the Implementation phase alone
AuditableEverything elseThree phases, plus a Certification row on the getting-started tab

CIS v8 is treated as auditable but also skips the Verification phase.

Tips and gotchas

ISO 27001 and 27002 travel together

ISO 27002 is never listed on its own. Enabling ISO 27001 links it; disabling ISO 27001 disables it too, and the disable dialog says so.

Enable one framework, finish its policies, and connect data sources before adding the next. Controls from a second framework map to much of the same evidence, so a second framework is far less work once the first is running.

What Noru does not do

Enabling a framework does not make you compliant with it and does not certify anything. Evidence is mapped to the new controls as data sources sync, not at the moment you flip the switch. Disabling a framework deletes nothing.

Last updated on