Controls
Controls and tests are elements of a compliance framework, a structured set of requirements to help organizations achieve compliance with relevant laws, regulations, and standards.
When you export controls or requirements, or include them in a digest or SSP, health is computed on demand and can differ from stored health shown on the page.
Note: If a control shows Not tested, open it and check mapped tests, framework scope, and whether tests are enabled. See the FAQ below and Using the Controls View for control health statuses.
SOC2, ISO 27001, and GDPR are examples of external security and privacy frameworks, but larger organizations often define their own frameworks for their own unique business objectives or custom compliance needs.
A Control defines an activity, process, procedure or configuration that minimizes risks when followed. Controls are defined by an organization in response to the risks that organization has identified with respect to external or internal compliance frameworks. One control may be mapped to multiple frameworks and may be supported by multiple tests.
When you bulk delete controls with Select All, the action applies to every page of the current filtered set, not only the first 100 rows.
Tests
Tests are the small units of work that Secureframe has created to demonstrate that certain controls are functioning as intended.
It is important to perform these tests or monitor them continually as part of your ongoing compliance program to avoid any surprises from your auditor performing the same or similar tests as part of their audit procedures. One test may support multiple controls across frameworks.
Marking or unmarking a comment as a finding re-runs the affected test so the result reflects the change without waiting for a later refresh.
FedRAMP evidence export includes assets from in-scope regions only. Assets in out-of-scope regions are not included in the FedRAMP 20x evidence package.
Evidence needs a framework scope row for tests and exports to treat it the same way. When a framework is added, Secureframe writes scope rows for archived evidence so test results and exports agree.
Common Control Abbreviations
AC - Access Controls
AVA - Availability
C - Confidentiality
CCPA - CCPA
CM - Configuration/Change Management
COM - Communications
CP - Contingency Planning
DORA - EU DORA
GDPR - GDPR
GOV - Governance
I - Integrity
IR - Incident Response
MP - Media protection
MSFT - Microsoft
NET - Network Security
ORG - Organizational
P - Privacy
PCI - Payment Card Industry
PHYS - Physical security
PI - Processing Integrity
RA - Risk assessment
SR - Supply chain risk management
VM - Vulnerability management
ZT - Zero Trust
Frequently Asked Questions (FAQ)
Can Controls and Tests be active without being mapped to a Framework Requirement?
No, Controls will show up as unmapped in the inactive tab of the Controls page if not mapped to an active (applicable) Framework Requirement.
Why do I not have a status on my enabled Test?
Tests must be mapped to a Control that is mapped to an active Framework Requirement in order for a status to be generated on the test.
Does Controls bulk delete with Select All only delete the first page?
No. Bulk delete with Select All applies to every page of the current filtered set, not only the first 100 rows.
If I mark or unmark a comment as a finding, when does the related test update?
Marking or unmarking a comment as a finding re-runs the affected test so the result reflects the change without waiting for a later refresh.
What does "Not tested" mean on a control, and how do I fix it?
Not tested usually means no enabled, applicable test is currently evaluating that control. It does not always mean the control failed.
Common causes: mapped tests are disabled, out of framework or Trust Service Criteria scope, unmapped, marked N/A, or filtered out of the active engagement.
Open the control, review mapped tests, and confirm the correct framework and Trust Service Criteria are enabled for your SOC 2 scope.
Enable or remap tests that apply. If the control does not apply to your environment (for example a physical facility control for a fully cloud company), mark it N/A with a clear justification.
Refresh tests after changes. If the control still shows Not tested with enabled mapped tests, contact [email protected] with the control name and screenshots.
Why might FedRAMP evidence export exclude assets from some regions?
FedRAMP evidence export is limited to in-scope regions.
Assets in out-of-scope regions are not pulled into the FedRAMP 20x evidence package.
Why can control or requirement health look different in an export, digest, or SSP than on the page?
Health for controls and requirements is computed on demand for exports, digests, and SSP responses.
Those values can differ from previously stored health shown elsewhere in the product.
Why might evidence look in-scope in an export but out-of-scope for a test (or the reverse)?
Evidence needs a framework scope row for tests and exports to treat it the same way.
When a framework is added, Secureframe writes scope rows for archived evidence so test results and exports agree.
Why does a Secureframe-authored control show "not tested" after its implementation date is removed?
If the implementation date is removed from a Secureframe-authored control, health shows not tested instead of unhealthy.
Can I bulk-import tests if the assertion-data cell is blank?
Yes. CSV bulk test import accepts a blank assertion-data cell for assertions that do not need configuration.
