What is a Control?
Controls are where the day-to-day management of your compliance program takes place. Where policies lay out, at a high-level, what your organization should be doing, your controls and procedures lay out the specific actionable "how" of compliance.
More generally, a control can be thought of as a set of processes that your organization follows in order to mitigate some form of business risk.
Controls in Thoropass
You can view controls in Thoropass by going to My Compliance > Roadmap.
There are a few core concepts to understand related to controls β Action Items, control status, and the connection to monitors.
Generally, you'll follow the same standard flow for all controls as you prepare for audit:
Use the Roadmap to see a list of all controls that need to be addressed for a specific framework or across all frameworks.
Complete each of the Action Items on the control.
Maintain the control's healthy status by remediating any associated flagged monitors and by completing recurring action items on time.