Recommended controls are the measures, policies or practices proposed to mitigate the identified risk and bring the current risk down to your target. They are captured in the Recommended Controls tab of the risk, in three complementary ways.
1. Link existing policies and controls
Mitigating a risk often means enforcing controls your organisation already owns. Under From Policies:
- Click the '+' button to open the link drawer.
- Select the relevant Policies, Categories, Subcategories and Controls from your Policies module, then click Link.
- The linked items appear on the risk's Recommended Controls card for reference and follow-up.
This keeps the recommendation traceable to the exact governance documents that implement it.
2. Link controls from your Controls Database
Under From Database, use Link Controls to attach controls from your workspace's Controls Database (the vendor catalogues and custom controls managed in the Databases module). This is useful when the appropriate safeguard exists as a standard control but is not yet written into a policy.
3. Propose additional recommended controls
When existing controls are insufficient, describe the additional measures in the Additional Recommended Controls text box, in collaboration with the key stakeholders.
Tip: Keep the description structured and actionable, so it can be split into separate remediation plans later, and framed so it can be integrated into your security policies or standards for long-term improvement.
By recommending controls this way, either leveraging existing measures or proposing new ones, you address risks proactively, efficiently and in alignment with your broader security objectives.