CSFaaS encourages you to classify each control against international standards. All of a control's properties are edited from one panel, organised in three tabs: Definition, Evaluation and Attributes.
1. Open the Control
Select the control in the Policies tree, or open it from the Controls page. The control panel shows its display code, name and description, with the three tabs above. Remember to click Save Changes after editing.
2. Definition
- Display Code: the user-facing code (for example ISP-001); the registered code underneath is a fixed reference that never changes.
- Control Name: a name that reflects the control's purpose.
- Description: a detailed rich-text definition of the control.
3. Evaluation
- Control Weighting: pick a weight from your workspace Weighting Levels scale, and explain the rationale in the Weighting Description.
- Maturity Levels: set the current and target maturity levels (Level 0 to Level 5) with a description of each: where the control stands today, and what reaching the target requires.
- Completion Progress: the implementation percentage with its justification (see the previous section).
4. Attributes
Classify the control using the workspace catalogues (all customisable in Databases, Configuration Catalogs):
- Business Units and Functional Domains: who owns the control operationally and which parts of the business it protects.
- Control Function: Govern, Identify, Protect, Detect, Respond or Recover.
- Privacy Control Function: Identify-P, Govern-P, Control-P, Communicate-P or Protect-P.
- Control Type: Preventive, Detective or Corrective.
- Security Domains: Governance and Ecosystem, Protection, Defence, Resilience.
- Information Security Properties: confidentiality, integrity and availability attributes.
- Operational Capabilities, Security Control Baseline and Control Category (Organisational, People, Physical, Technical).
5. Reviews, Owners and Evidence
- Periodicity Review: from the control's review action, choose how often it must be reviewed: Weekly, Bi-Weekly, Monthly, Quarterly, Bi-Annual, Annual or Custom. Assigned owners are notified each period, validations are recorded with their history, and controls that need no review can be marked as not requiring one. This continuous monitoring approach follows NIST SP 800-37.
- Owners: assign the accountable members through the control's Owners action.
- Evidences: attach the files or links that prove implementation (see section 9).