Control Domains
A control domain is a grouping of related security controls — for example, Access Control, Incident Response, Data Protection, or Vendor Management. The domains in scope for a given assessment are determined by the business cases selected for that relationship. VISO TRUST’s default framework covers seven primary dimensions:
You can further tailor the controls in scope through Custom Frameworks.
How Controls Come In Scope
Controls are brought into scope by the business cases selected during relationship context configuration. Each business case maps to a set of control domains — the combination of selected business cases determines the full set of controls that must be assessed. Example: A vendor selected with the business cases “Stores customer data” and “Has privileged system access” will have a broader set of controls in scope than a vendor selected only as a “Provides software as a service.” Changing a relationship’s business cases immediately updates which controls are in scope. Controls that fall out of scope are marked as Out of Scope. New in-scope controls begin as Unvalidated until evidence is collected.Control Status
Each in-scope control has a status that reflects the current state of evidence:
Controls marked Not Present or No Info represent gaps — these drive the residual risk score upward and are the primary targets for remediation requests and follow-up questionnaires.