Shared catalogs make control classification consistent across policies. Configure their values in Databases, then select the applicable values on each control's Attributes tab in Policies.
Choose the classification vocabulary
The current attribute groups are business units, control categories, control functions, control types, functional domains, information security properties, operational capabilities, privacy control functions, security control baselines and security domains.
Use these groups for distinct purposes. For example, a control type can describe whether a measure is preventive or detective, while a business unit identifies the organisational scope to which it applies. Avoid using an unrelated group simply because it already contains a convenient label.
Maintain shared values
Open the relevant catalog in Databases, review the existing values and make authorised changes. Catalog edits affect the choices used across the workspace. Check existing usage before removing or renaming a value.
Control weighting is configured separately in the shared weighting configuration. Its available scale and labels determine the choices shown during control evaluation.
Apply the values
Open a control under Policies → Attributes, expand a group and select every value that applies. Save the attribute changes. The selections also support catalog filters in the Controls register; merely adding a catalog value does not assign it to any control.