🎉 VSEC Test v4.0.1 is now live! Release Notes ↗

Control Library

The Control Library is a workspace-wide catalogue of security controls. Open it from Risk Manager → LibrariesControl Library. Each control records what the mitigation is, how much effort it requires, which lifecycle phases it applies to, and where to find training or implementation guidance. Controls can carry one or more Requirements — structured references to external standards, regulations, or internal tracking systems.

The Control Library holds reusable control definitions. Individual risks link controls from the Risk tab on Risk Details — linked controls mitigate the risk’s residual score under the evidence model. Each control carries per-factor mitigation values that reduce a linked risk’s residual feasibility, and individual risk links can override those values per risk.

Control Fields

FieldDescription
ReferenceAuto-generated identifier (e.g. C-001)
ControlDescriptive name of the control (required)
CategoryGrouping category from the workspace catalog (required)
Effort/CostRelative effort to implement: Very Low, Low, Medium, High, or Very High
Applicable LifecycleOne or more phases: Concept, Development, Production, Operations, Decommission
Link to TrainingOptional label and URL pointing to training material or implementation guidance

List View

The list table shows each control’s ID (its reference), Control name, Applicable Lifecycle, Effort/Cost, and Products in Use. The Products in Use column is not yet populated in this release. Only the ID cell is a link — click it to open the control’s detail page.

  • Create — click New in the toolbar. The New Control dialog requires the control name and a category; fill in any optional fields, then click Create Control. You are taken straight to the new control’s detail page.
  • Delete — click the delete icon on a row; a confirmation dialog appears before permanent removal.

Detail Page

The detail page header shows the control’s reference and name alongside an Edit button, which opens the control in a modal form dialog (Save Changes / Cancel), and a Delete button with a confirmation dialog. A Return to Control Library link navigates back to the list.

An always-visible Details card lists all control fields. Next to it are three tabs:

Requirements

Lists structured requirements attached to this control. Each requirement has:

FieldDescription
IDExternal identifier — e.g. CS.00095, a regulation clause, or a DOORS ID
RequirementHuman-readable description of the requirement (required)
LinkOptional label and URL to the requirement in an external system (e.g. DOORS, Jira, Confluence)

Use Add to open the Add Requirement dialog and the delete icon to remove a requirement.

The Requirements tab also contains a Test Cases card, which is not yet populated in this release.

Implemented By

Lists the workspace items that implement this control. Not yet populated in this release.

Effectiveness

Effectiveness metrics are not yet populated in this release.

Permissions

Any signed-in member of the workspace can view library entries. Creating, editing, or deleting a control (or its requirements) requires a permission granted by your workspace administrator; without it, the action is denied. The New, Edit, and delete controls are not hidden based on permissions, so they remain visible even if your role lacks access to use them.

Last updated on