Settings

Frameworks

Enable and disable the frameworks in scope for your organization.

RolesAdminRoute/settings?tab=frameworksShown toAll organizations

What it is

The Frameworks tab decides which requirement sets are in scope. Turning a framework on links its controls and requirements to the organization so they are tracked, and offers to generate the policies it expects. Turning one off removes it from scope but keeps the policies and evidence you already have.

Where to find it

SettingsFrameworks
Frameworks card with a grouped list of frameworks, each with a switchFrameworks card with a grouped list of frameworks, each with a switch
Frameworks are grouped by kind. Each row has a switch.

Key actions

Enable a framework

Turn on the framework's switch.
A dialog, Generate Policies for the framework, lists "New policies to generate" and, where you already have policies, "Policies to update". Click Generate Policies to queue the job, or Skip for Now.

Generation runs in the background; the toast "Policy regeneration has been queued successfully" confirms it, and the result appears under Policies. If you skip, the toast says the framework is enabled and "You can generate policies later."

Disable a framework

Turn off the switch.
Read the Disable dialog. It says the framework "will be removed from your compliance scope and its controls and requirements will no longer be tracked. Generated policies and collected evidence are kept. You can re-enable it at any time."
Click Disable framework.

Statuses and fields

ElementMeaning
"Includes ISO 27002"ISO 27001 and ISO 27002 are enabled and disabled together
Generate Policies for dialogOffered after enabling; lists the policies the framework expects

When enabling updates existing policies, the dialog is titled Update Policies for the framework and notes that "Approved policies will have a new draft version created." Its confirm button reads Regenerate Policies.

Tips and gotchas

Regenerating policies never overwrites an approved policy in place. Approved policies get a new draft version, so you can diff and reject it in the policy editor.

Disabling and re-enabling is cheap. Controls come back into scope with their previous status, and existing policies are matched rather than duplicated.

What Noru does not do

Enabling a framework does not make you compliant with it and does not map existing evidence to the new controls by itself; automatic mapping happens as data sources sync. Noru also does not delete anything when you disable a framework.

Last updated on