Skip to main content
Version: 1.0.0

Frameworks

The Frameworks module holds the control libraries that compliance work is measured against. A framework is a structured set of domains and controls — for example a regulator's cybersecurity controls or an international standard — that assessments, the Statement of Applicability, and reporting all build on.

1. Background and Business Purpose

Every assessment scores an organization against a framework. Keeping frameworks as governed, reusable libraries means a control only has to be defined once and can then drive many assessments, evidence requests, and gap reports over time.

The platform ships a curated set of global frameworks and lets each tenant maintain its own custom frameworks alongside them.

Main business outcomes:

  • maintain authoritative control libraries with bilingual (Arabic/English) content
  • reuse the same framework across repeated assessment cycles
  • tailor or extend a standard library to fit the organization
  • keep framework versions and status visible so assessments use the right baseline

2. Core Records and Actors

ItemMeaning
FrameworkA control library with a code, bilingual name, version, effective date, type, status, and a flag indicating whether it is global or tenant-owned.
DomainA grouping of controls within a framework. Domains can be nested and carry a weight used in scoring.
ControlAn individual requirement that an assessment evaluates and that evidence is mapped to.

A framework has a type — Regulatory, Standard, or Custom — and a status — Draft, Active, or Deprecated. Only Active frameworks should be used to start new assessments.

ActorResponsibility
Platform administratorCurates the global framework catalogue (import, version, deprecate, reset).
Tenant administratorClones or creates the frameworks the organization assesses against and maintains custom content.
AssessorUses a framework's controls during an assessment; does not change the library.

3. Seeded Frameworks

The platform seeds the following frameworks ready for assessment:

  • NCA ECC-1:2018 — Essential Cybersecurity Controls
  • NCA ECC-2:2024 — Essential Cybersecurity Controls (2024 edition)
  • SAMA Cybersecurity Framework
  • PDPL — Personal Data Protection Law
  • ISO/IEC 27001:2022
  • NDMO Data Governance Framework

Additional frameworks can be added by importing a framework file or by building one in the tenant.

4. Working with Frameworks

The framework catalogue is available at Frameworks, and the platform-curated global catalogue is managed at Admin → Frameworks.

ActionWhat it does
Browse the catalogueSee all frameworks available to the tenant with their version, status, type, and control count.
Open a frameworkView the full domain-and-control tree, with bilingual names and weights.
Create a custom frameworkBuild a new tenant framework from scratch and add its domains and controls.
Clone a frameworkCopy a global framework into the tenant so it can be tailored without affecting the shared original.
EditUpdate framework details, domains, weights, and controls.
Import structureLoad a framework's domains and controls from a prepared import file.
ExportDownload the framework as an Excel workbook that preserves the domain/control structure.
ResetRestore a global framework to its seeded state (platform administrators only).
DeleteRemove a tenant framework that is no longer needed.

Cloning is the recommended way to customize a regulator framework: clone it into the tenant, then adjust applicability, weights, or wording while leaving the global copy intact for other tenants.

  • Compliance and Assessments — assessments score the controls defined here, and the Statement of Applicability declares which controls apply.
  • Controls — the control library and control testing.
  • Evidence — proof mapped to framework controls during an assessment.