The program is the heart of the workspace: a structured list of every control or requirement for your framework, grouped by domain. You work it one control at a time, and your progress is saved to your account server-side — there's no file to lose and nothing to sync.
The status of every control
Each control carries a status. Set it honestly — the value of the program is that it reflects reality:
- Not started — you haven't addressed this yet. (Everything begins here.)
- In progress — you're implementing it or gathering evidence.
- Implemented — the control is in place and you've attached evidence that proves it.
- N/A — the control doesn't apply to you. You must add a justification explaining why; an auditor will read it.
Tip: Don't mark a control Implemented until the evidence is attached. "Implemented with no evidence" is the single most common thing that falls apart in an audit.
Notes and structured fields
For each control, add:
- Notes — a short description of how you meet the control (the policy, the tool, the process). Write for an auditor who has never seen your environment.
- Structured fields — where the framework expects specifics (a review frequency, an owner, a system name), fill them in so the exported pack reads cleanly.
A repeatable loop
Work the program in passes rather than trying to perfect one control at a time:
- First pass — triage. Go through every control and set N/A (with justification) or Not started / In progress. Now your readiness score and gap list reflect reality.
- Second pass — the easy wins. Close the controls you already satisfy — attach the existing policy or config and mark them Implemented.
- Third pass — the gaps. Assign the remaining controls to owners with due dates and work them down.
Everything is saved
Changes save as you make them. You can close the tab and come back; your program, notes, statuses, and evidence are exactly where you left them, tied to your account. Multiple people on the same account can work different controls.
Next: attach proof in the Evidence vault.
