Once you have created or imported a framework, you can begin managing your domains. Domains are the top level of the Framework Structure, organising requirements into manageable sections.
For example:
- In ISO 27001:2022, domains include Organisational Controls, People Controls, Physical Controls and Technological Controls.
- In NIST CSF 2.0, domains include Govern, Identify, Protect, Detect, Respond and Recover.
1. Add, Edit and Organise Domains
- Add New Domain: use the add button in the Framework Structure panel; a display code is suggested automatically and you provide the name and description.
- Edit: select a domain and update its display code, name and description from the details panel.
- Delete: remove a domain from its More options menu; a confirmation dialog warns you that all child elements are deleted too.
- Reorder: drag and drop domains in the tree. Structure moves are gathered in the save bar; click Save to confirm them or Discard to revert.
2. Define Applicability
The applicability status records whether an element is relevant to your scope and where its implementation stands. The options are:
- Unknown: the default status; the applicability of this element has not been assessed yet.
- Implemented: the element is fully in place and operational. Elements marked Implemented are the ones that can flow into your policies through Framework Updates.
- Not Implemented: the element applies but is not yet implemented. Explain why (for example organisational immaturity, pending implementation, or alternative measures in place) and the plan to address it.
- Not Applicable: the element does not apply to your scope. Explain why in the justification.
Each status change can carry a Justification, and you can apply the status recursively to all child elements.
3. Set Maturity Levels
Define a current and a target maturity level for each domain, on a scale from Not defined through Initial, Developing, Defined and Managed up to Optimized. Each level can carry a description, and the levels can be applied recursively to the domain's categories and subcategories.
4. Set Weighting
Use the Weighting action to define how much the domain weighs in the overall assessment, with an optional justification. The weighting scale (number of levels and their labels) is configured for the whole workspace in Databases, Configuration Catalogs, under Weighting Levels.
5. Assign Owners
- Click the Owners icon on the domain.
- In the drawer, select one or several workspace members as owners.
- Tick Apply recursively to propagate ownership to the underlying categories and subcategories.
- Click Save Changes.
You can also mark a domain as not requiring an owner.
6. Reviews, Evidence and Collaboration
- Periodicity Review: schedule how often the domain must be reviewed (Weekly, Bi-Weekly, Monthly, Quarterly, Bi-Annual, Annual or Custom); assigned owners are reminded automatically each period, and a validation history is kept.
- Evidences: attach supporting files or links (policies, procedures, audit reports) to substantiate the domain.
- Comments: discuss changes and keep a record of decisions directly on the element.
- Share: generate an expiring share link for the element when you need to show it to someone outside the workspace.
Note: each domain carries a permanent registered code (e.g. FD_00001) that never changes, alongside the display code you can edit. The registered code guarantees traceability inside your framework.