Frameworks
The Frameworks module holds the control libraries that compliance work is measured against. A framework is a structured set of domains and controls — for example a regulator's cybersecurity controls or an international standard — that assessments, the Statement of Applicability, and reporting all build on.
1. Background and Business Purpose
Every assessment scores an organization against a framework. Keeping frameworks as governed, reusable libraries means a control only has to be defined once and can then drive many assessments, evidence requests, and gap reports over time.
The platform ships a curated set of global frameworks and lets each tenant maintain its own custom frameworks alongside them.
Main business outcomes:
- maintain authoritative control libraries with bilingual (Arabic/English) content
- reuse the same framework across repeated assessment cycles
- tailor or extend a standard library to fit the organization
- keep framework versions and status visible so assessments use the right baseline
2. Core Records and Actors
| Item | Meaning |
|---|---|
| Framework | A control library with a code, bilingual name, version, effective date, type, status, and a flag indicating whether it is global or tenant-owned. |
| Domain | A grouping of controls within a framework. Domains can be nested and carry a weight used in scoring. |
| Control | An individual requirement that an assessment evaluates and that evidence is mapped to. |
A framework has a type — Regulatory, Standard, or Custom — and a status — Draft, Active, or Deprecated. Only Active frameworks should be used to start new assessments.
| Actor | Responsibility |
|---|---|
| Platform administrator | Curates the global framework catalogue (import, version, deprecate, reset). |
| Tenant administrator | Clones or creates the frameworks the organization assesses against and maintains custom content. |
| Assessor | Uses a framework's controls during an assessment; does not change the library. |
3. Seeded Frameworks
The platform seeds the following frameworks ready for assessment:
- NCA ECC-1:2018 — Essential Cybersecurity Controls
- NCA ECC-2:2024 — Essential Cybersecurity Controls (2024 edition)
- SAMA Cybersecurity Framework
- PDPL — Personal Data Protection Law
- ISO/IEC 27001:2022
- NDMO Data Governance Framework
Additional frameworks can be added by importing a framework file or by building one in the tenant.
4. Working with Frameworks
The framework catalogue is available at Frameworks, and the platform-curated global catalogue is managed at Admin → Frameworks.
| Action | What it does |
|---|---|
| Browse the catalogue | See all frameworks available to the tenant with their version, status, type, and control count. |
| Open a framework | View the full domain-and-control tree, with bilingual names and weights. |
| Create a custom framework | Build a new tenant framework from scratch and add its domains and controls. |
| Clone a framework | Copy a global framework into the tenant so it can be tailored without affecting the shared original. |
| Edit | Update framework details, domains, weights, and controls. |
| Import structure | Load a framework's domains and controls from a prepared import file. |
| Export | Download the framework as an Excel workbook that preserves the domain/control structure. |
| Reset | Restore a global framework to its seeded state (platform administrators only). |
| Delete | Remove a tenant framework that is no longer needed. |
Cloning is the recommended way to customize a regulator framework: clone it into the tenant, then adjust applicability, weights, or wording while leaving the global copy intact for other tenants.
5. Related Modules
- Compliance and Assessments — assessments score the controls defined here, and the Statement of Applicability declares which controls apply.
- Controls — the control library and control testing.
- Evidence — proof mapped to framework controls during an assessment.