Controls

Editing and managing controls

Once a control exists, everything else happens on its detail page: editing its fields, mapping it to framework requirements, adding attributes and owners, linking it to assets, risks, and plans, and eventually archiving it.

Editing control information

The Details tab holds the control's own fields, its framework references, its attributes, and its owners.

Opening control details

  1. Click on a control title in the overview
  2. The control details tab opens with various sections
  3. Details section contains all basic information and settings

Control details tab

Editing basic information

Once created, a control's name, validity period, type, and description can all still be changed.

Editable fields in Details tab:

  • Name - Adjust control name
  • Custom ID - Change for better reference
  • Valid from / Valid to - Set validity period. Plans only create tasks for valid controls.
  • Control Type - Change between Manual/Automated/IT-Dependent Manual. This is an optional control label.
  • Description - For adding or adjusting the Control description

Buttons in Details tab:

  • Archive - For archiving controls
  • Delete - For permanently deleting controls

How to edit information:

  1. Click in the relevant field
  2. Adjust the text or selection
  3. Click the Update button bottom left or top right of the screen to save changes
Info

Activate Controls to automatically create Tasks: Plans can only create automatic tasks for active controls.

A Control is "Active" when:

  • The "Valid from" date is in the past and "Valid to" in the future or empty.
  • At least one Asset is linked to the Control
  • At least one Plan is linked to the Control

Framework References

What are Framework References? Framework References link your control to compliance standards like ISO27001, NIS2, or GDPR.

Benefits of framework mapping:

  • Compliance tracking - Automatic progress for compliance standards
  • Audit support - Clear traceability to requirements
  • Reporting - Structured compliance overviews

Creating control attributes

Attributes let you tag a control with a category or label for filtering.

Adding attributes:

  1. Scroll to "Attributes" section
  2. Click "Add attribute"
  3. Fill in a title and select 'Add item' or press 'Enter' to save it.
  4. Fill in a value and select 'Add item' or press 'Enter' to save it.
  5. Click 'Add' to definitively add the attribute.

Adding control attributes

Removing attributes:

  1. Scroll to "Attributes" section
  2. Move mouse over attribute a trash can icon appears
  3. Click trash can to remove the attribute

Editing attributes: Create a new attribute with the correct information and then delete the 'old' attribute.

Tip

Reduce error-proneness and typos by selecting existing titles and values from the dropdown list (if used before) instead of typing yourself.

Assigning control owners

The owner is the person accountable for the control's effectiveness.

Assigning Owners:

  1. Find "Owners" section on the right side
  2. Click the user icon
  3. Type username and select from dropdown
  4. Multiple owners possible for shared responsibility

Setting Executors:

  • People who perform execution tasks
  • Automatically assigned to new manual tasks
  • Often IT teams or operational staff

Assigning Assessors:

  • People who perform assessment tasks
  • Automatically assigned to assessment tasks
  • Usually auditors or compliance officers
Tip

Role clarity: Owners are responsible for control effectiveness, Executors perform tasks, and Assessors evaluate whether controls work. One person can have multiple roles.

Relationships with other objects

Controls can be linked to other objects like assets, risks, and plans using the chip component interface. This provides a visual and intuitive way to manage relationships.

Chip Component Interface

How the chip component works:

  • Click to add - Click on empty chip areas to add new links
  • Visual indicators - Linked objects appear as removable chips
  • Quick removal - Click the X on any chip to remove the link
  • Auto-save - Changes are saved automatically

Linking assets

Why link assets? By linking assets you establish which business resources this control applies to.

Tip

When using Plans, one task per linked Asset will be created by the Plan. By adding multiple Assets you can also subdivide tasks to Asset owners.

Linking assets:

  1. Go to "Assets" tab in control details
  2. Select relevant assets from the available list
  3. Links are automatically saved

Asset selection criteria:

  • Relevance - Asset must actually be protected by control
  • Proportionality - Critical assets require more/stricter controls
  • Practical feasibility - Control must be realistically implementable on asset

Linking risks

Why link risks? By linking risks you establish which risks this control helps mitigate.

Risk-control mapping:

  1. Open "Risks" tab of the control
  2. Select relevant risks that this control helps mitigate
  3. Links help with risk management and impact analysis

Mapping strategies:

  • Direct mitigation - Control directly reduces this specific risk
  • Preventive effect - Control prevents this risk type
  • Detective function - Control detects when this risk occurs
  • Corrective measure - Control repairs damage from this risk
Info

The controls you link to risks will reappear during risk assessment.

Determine during this risk assessment whether the linked measures still sufficiently mitigate the risk, or whether additional control links are needed.

Linking and unlinking tests

Why link tests? A test only counts towards compliance once it is linked to a control. Linking makes the test "In scope": its result feeds the control's effectiveness and the test statistics. Unlinking makes it "Out of scope" again.

Linking tests:

  1. Go to "Tests" tab of the control
  2. Select the text field to see the available tests, grouped per integration
  3. Search by test name or pick one from the list
  4. Links are automatically saved - the test is immediately "In scope"

Unlinking tests:

  1. Go to "Tests" tab of the control
  2. Click the X on the chip of the test you want to remove
  3. The link disappears automatically - the test becomes "Out of scope" and stops counting towards scoring
Info

The same link can be made from the other side: open the test and use the Controls selector on the test detail page. Both routes produce the same result.

Read more about this in Executing and monitoring tests.

Warning

Unlinking a test removes it from your compliance scoring. Historical results stay on the test itself, but the test no longer contributes to any control's effectiveness.

Policy tests work the same way: unlinking a policy test puts the corresponding policy or required document out of scope.

Linking plans

Why link plans? Plans ensure that new Control tasks are created periodically (e.g. monthly, annually).

  1. Go to "Plans" tab of the control
  2. Select relevant plan from available schedules
  3. Automatic task creation starts according to plan frequency and schedule

Most common Plan types:

  • Monthly Monitoring - Monthly checks
  • Quarterly Testing - Quarterly validation
  • Annual Review / Audit - Annual control assessments
Warning

Plan overload: Avoid assigning multiple plans to one control. This leads to excessive tasks and confusion about deadlines.

Control lifecycle management

A control becomes active only when its validity dates, a plan, and at least one asset are all in place. When it stops applying, archive it to keep the history, or delete it to remove it entirely.

Control activation and deactivation

Miss any one of the three and the control stays Inactive, whatever else you fill in.

Activating control:

  • Set the "Valid from" date (today or earlier)
  • Set the "Valid to" date (future)
  • Link to a Plan
  • Link to at least one asset
  • Status automatically changes to "Active"

Deactivating control:

  • Set "Valid to" date (today or earlier)
  • Completed tasks remain visible for audit
  • Planned future tasks are cancelled
  • Status changes to "Inactive"

Archiving controls

Archive a control once it genuinely stops applying, rather than deleting it, so the history survives.

When to archive:

  • Control is permanently no longer applicable
  • Framework requirement has expired
  • Control is replaced by new version
  • Organisational change makes control irrelevant

Archiving process:

  1. Select one or more controls with checkboxes in overview
  2. Click "Archive" button at top of table
  3. Confirm archiving - controls disappear from daily overview
  4. Historical data remains available for audit and reporting

Effect of archiving:

  • Control appears in "Archived" tab
  • All links are hidden but preserved
  • No new tasks are created for this control anymore
  • Compliance calculations and statuses don't account for archived controls.
Activating vs. Archiving

There are several differences between activating and archiving:

  1. Activation (and Deactivation) happens automatically when the validity period starts or expires. Archiving is always manual.
  2. A control can be deactivated because necessary links with Assets and/or Plans are missing. Archiving is always manual.
  3. When a control is deactivated, links with assets, risks and tasks remain visible throughout the application. With Archiving these links are hidden.

Deleting controls

Delete a control only when it should never have existed: sensitive test data, a duplicate, or an incorrect setup.

When to delete:

  • Control contains sensitive information that may not be preserved
  • Test setup with incorrect configuration that needs to be completely redone
  • Duplicate controls that were accidentally created
  • Organisation requires permanent deletion of certain data

Deletion process:

  • Select one or more controls with checkboxes in overview
  • Click "Delete" button at top of table
  • Make choice between automatically closing linked tasks or not
  • Confirm deletion - definitive action that cannot be undone

Effect of deletion:

  • Control is permanently removed from the entire application
  • All linked tasks, tests and historical data are closed (if chosen)
  • Links with assets, risks and plans are broken
  • Audit trail and reporting history is lost
Deleting vs archiving

With deletion, the control can only be restored via a restore request to the helpdesk.

With archiving, restoration is possible via the 'Archived' tab, and then the 'Unarchive' option

Control templates

Start from Tidal's templates for the standard frameworks and adapt them, rather than writing each control from scratch.

Using control templates

Each template already comes pre-mapped to the framework requirements it satisfies.

Predefined controls: Tidal offers templates for standard compliance frameworks:

ISO27001 controls:

  • A.01 Context of the organization established
  • A.02 Legal and contractual requirements identified
  • A.03 Scope of the ISMS determined
  • [...etc. complete set available]

Template benefits:

  • Pre-filled descriptions - Professional control descriptions
  • Framework mappings - Automatic compliance references to all applicable frameworks
  • Recommended attributes - additional information that can be used for filtering and reporting
  • Auditor tested - Proven effective control setup

Best practices for control management

Controls stay manageable when their names say what they achieve and someone reviews them on a fixed schedule rather than only when something breaks.

Control naming

  • Descriptive names - What exactly does the control achieve?
  • Consistent IDs - Group related controls
  • Avoid acronyms - Unless universally understood

Control monitoring

Reviewing a control on a fixed rhythm, not just when something breaks, is what keeps it actually effective.

Regular reviews:

  • Quarterly reviews - Control performance and relevance
  • Annual assessments - Thorough effectiveness evaluation
  • Incident triggers - Extra review after security incidents
  • Framework updates - Adjustments after standard changes

Monitor the following performance indicators:

  • Task completion rates - Percentage of timely completed tasks
  • Test success rates - Percentage of successful automated tests
  • Issue resolution time - Speed of problem solving
  • Stakeholder satisfaction - Feedback from control testers

Continuous improvement

Look for controls that could be automated or better scoped before their next review.

Control optimisation:

  • Automation opportunities - Which manual tasks can be automated?
  • Frequency fine-tuning - Is current test frequency optimal?
  • Risk-based scoping - Right asset coverage without overload?
  • Regularly review available integrations - Better tool connections possible?

Change management:

  • Impact assessment - Assess the effect of changes in controls on compliance (control-risk links)
  • Communicate to stakeholders - Communicate changes timely
  • Training updates - New procedures adequately trained
  • Rollback planning - Use archiving and validity periods to be able to return to previous version if needed
Tip

Start small, build out: Begin with core controls for your most important assets and frameworks. Gradually add controls as your team gains experience and processes mature.

Next steps

Now that you can create and manage controls:

  • Implement your first controls for critical business processes
  • Set up automatic planning for regular validation
  • Monitor control effectiveness via dashboards and reports
  • Optimise configurations based on practical experience

For operational guidance on tasks and testing, see Implementing and testing controls