Controls
Controls and tests are elements of a compliance framework, a structured set of requirements to help organizations achieve compliance with relevant laws, regulations, and standards.
Note: If a control shows Not tested, open it and check mapped tests, framework scope, and whether tests are enabled. See the FAQ below and Using the Controls View for control health statuses.
SOC2, ISO 27001, and GDPR are examples of external security and privacy frameworks, but larger organizations often define their own frameworks for their own unique business objectives or custom compliance needs.
A Control defines an activity, process, procedure or configuration that minimizes risks when followed. Controls are defined by an organization in response to the risks that organization has identified with respect to external or internal compliance frameworks. One control may be mapped to multiple frameworks and may be supported by multiple tests.
When you bulk delete controls with Select All, the action applies to every page of the current filtered set, not only the first 100 rows.
Tests
Tests are the small units of work that Secureframe has created to demonstrate that certain controls are functioning as intended.
It is important to perform these tests or monitor them continually as part of your ongoing compliance program to avoid any surprises from your auditor performing the same or similar tests as part of their audit procedures. One test may support multiple controls across frameworks.
Marking or unmarking a comment as a finding re-runs the affected test so the result reflects the change without waiting for a later refresh.
Common Control Abbreviations
AC - Access Controls
AVA - Availability
C - Confidentiality
CCPA - CCPA
CM - Configuration/Change Management
COM - Communications
CP - Contingency Planning
DORA - EU DORA
GDPR - GDPR
GOV - Governance
I - Integrity
IR - Incident Response
MP - Media protection
MSFT - Microsoft
NET - Network Security
ORG - Organizational
P - Privacy
PCI - Payment Card Industry
PHYS - Physical security
PI - Processing Integrity
RA - Risk assessment
SR - Supply chain risk management
VM - Vulnerability management
ZT - Zero Trust
Frequently Asked Questions (FAQ)
Can Controls and Tests be active without being mapped to a Framework Requirement?
No, Controls will show up as unmapped in the inactive tab of the Controls page if not mapped to an active (applicable) Framework Requirement.
Why do I not have a status on my enabled Test?
Tests must be mapped to a Control that is mapped to an active Framework Requirement in order for a status to be generated on the test.
Does Controls bulk delete with Select All only delete the first page?
No. Bulk delete with Select All applies to every page of the current filtered set, not only the first 100 rows.
If I mark or unmark a comment as a finding, when does the related test update?
Marking or unmarking a comment as a finding re-runs the affected test so the result reflects the change without waiting for a later refresh.
What does "Not tested" mean on a control, and how do I fix it?
Not tested usually means no enabled, applicable test is currently evaluating that control. It does not always mean the control failed.
Common causes: mapped tests are disabled, out of framework or Trust Service Criteria scope, unmapped, marked N/A, or filtered out of the active engagement.
Open the control, review mapped tests, and confirm the correct framework and Trust Service Criteria are enabled for your SOC 2 scope.
Enable or remap tests that apply. If the control does not apply to your environment (for example a physical facility control for a fully cloud company), mark it N/A with a clear justification.
Refresh tests after changes. If the control still shows Not tested with enabled mapped tests, contact [email protected] with the control name and screenshots.
