Controls are the foundational building blocks of your compliance program. Each control represents a specific security or privacy requirement defined by a compliance framework. LowerPlane maintains a unified library of 400+ controls across all 50+ supported frameworks.

What Are Controls?

A control is a specific requirement or safeguard that your organization must implement to achieve compliance. Examples include:
  • Requiring multi-factor authentication for all users
  • Encrypting data at rest and in transit
  • Conducting regular access reviews
  • Maintaining an incident response plan
  • Performing background checks on employees
Each control in LowerPlane is mapped to one or more frameworks and linked to the evidence and policies that demonstrate its implementation.

Control Statuses

Every control in your library has one of four implementation statuses:
StatusDescriptionDashboard Impact
ImplementedThe control is fully in place with supporting evidence and policiesCounts toward your readiness score
Partially ImplementedSome aspects are in place but the control is not fully satisfiedCounts at 50% toward readiness
Not ImplementedThe control has not been addressed yetIdentified as a gap
Not ApplicableThe control does not apply to your organization’s scopeExcluded from scoring
Use the Not Applicable status carefully. Auditors will expect justification for any control marked as not applicable. Add a note explaining why the control does not apply to your organization.

Browsing Controls

Navigate to Compliance > Controls to view your full control library. The control list provides:
  • Search and filter - Find controls by keyword, framework, status, category, or assigned owner
  • Framework filter - View controls for a specific framework or across all frameworks
  • Status filter - Focus on gaps by filtering for “Not Implemented” controls
  • Sorting - Sort by priority, framework, category, or status
  • Pagination - Controls are paginated for performance with large lists

Control Detail View

Click on any control to view its full details:
  • Description - What the control requires
  • Framework mappings - Which frameworks this control satisfies and the confidence score for each mapping
  • Linked evidence - Evidence artifacts attached to this control
  • Linked policies - Policies that support this control
  • Linked tests - Automated or manual tests that verify this control
  • Owner - The person responsible for this control’s implementation
  • Notes - Internal notes and implementation details

Linking Controls to Evidence

Evidence demonstrates that a control is implemented. Each control may require one or more types of evidence.
1

View Requirements

Open a control and check the Evidence Requirements section. This lists the types of evidence needed to satisfy the control (screenshots, configuration exports, policy documents, logs, etc.).
2

Attach Evidence

Click Link Evidence to associate existing evidence from your evidence vault, or upload new evidence directly. You can also connect integrations to collect evidence automatically.
3

Multi-Framework Coverage

When you attach evidence to a control, it automatically applies to all frameworks that control maps to. You do not need to attach the same evidence separately for each framework.

Linking Controls to Policies

Policies provide the documented procedures and rules that support your controls. To link a policy to a control:
  1. Open the control detail view
  2. Navigate to the Policies tab
  3. Click Link Policy and select the relevant policy from your policy library
Policies created from LowerPlane templates are automatically linked to the appropriate controls. You only need to manually link policies that were uploaded or created outside of templates.

Linking Controls to Tests

Tests verify that a control is operating effectively on an ongoing basis. Tests can be:
  • Automated - Run by LowerPlane using data from connected integrations (e.g., verifying MFA is enabled for all users)
  • Manual - Require a person to verify and record the result (e.g., confirming physical access controls are in place)
See Tests for more information on setting up and managing tests.

Cross-Framework Control Mapping

One of LowerPlane’s most powerful features is cross-framework control mapping. When a control maps to multiple frameworks:
  • Implementing the control once satisfies requirements in all mapped frameworks
  • Evidence attached to the control covers all mapped frameworks
  • The readiness score updates across all applicable frameworks simultaneously

Viewing Mappings

On any control’s detail page, the Framework Mappings section shows:
  • Each framework the control applies to
  • The specific requirement ID in each framework (e.g., ISO A.9.2.1, SOC 2 CC6.2)
  • The confidence score indicating alignment strength
  • Whether the framework-specific requirement has any additional nuances
Controls with a confidence score below 80% may require additional framework-specific evidence or documentation. Review the mapping details to understand what additional steps might be needed.

Bulk Operations

LowerPlane supports bulk operations to help you manage controls efficiently:
  • Bulk status update - Select multiple controls and change their status simultaneously
  • Bulk assign owner - Assign a team member as the owner of multiple controls at once
  • Bulk mark as not applicable - Mark multiple controls as N/A with a shared justification
  • Export - Export your control list to CSV for offline review or reporting
To use bulk operations:
  1. Navigate to Compliance > Controls
  2. Use the checkboxes to select the controls you want to update
  3. Choose the desired action from the bulk action toolbar that appears
Bulk status changes update all selected controls immediately. This also triggers readiness score recalculation across all affected frameworks. Review your selections carefully before confirming.

Control Ownership

Assigning owners to controls ensures accountability and helps distribute compliance work across your team. Control owners are responsible for:
  • Maintaining the control’s implementation
  • Ensuring evidence is current and not expired
  • Responding to audit inquiries about their assigned controls
  • Completing any linked tests on schedule
To assign an owner, open the control detail view and select a team member from the Owner dropdown. You can also use bulk assignment to set owners for multiple controls at once.

Best Practices

Prioritize controls that map to the most frameworks. Implementing these first maximizes your coverage across all enabled frameworks with the least effort.
Only mark controls as N/A when you have a clear, documentable justification. Auditors will question N/A designations, so keep notes explaining your reasoning.
Distribute control ownership across your team from the beginning. This prevents bottlenecks and ensures subject matter experts are responsible for relevant controls.
Set a cadence for reviewing control statuses, evidence freshness, and test results. Compliance is not a one-time event; it requires continuous maintenance.