> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Control Domains & Artifact Types

> How control domains define the security categories assessed in VISO TRUST, and how artifact types like SOC 2 and ISO 27001 reports map evidence to controls.

**Control domains** are the categories of security requirements that VISO TRUST assesses vendors against. **Artifact types** are the documents and evidence that validate whether those requirements are met. Together, they form the evidence-to-controls mapping that drives every risk score.

## Control Domains

A control domain is a grouping of related security controls — for example, Access Control, Incident Response, Data Protection, or Vendor Management. The domains in scope for a given assessment are determined by the **business cases** selected for that relationship.

VISO TRUST's default framework covers seven primary dimensions:

| Dimension                   | What it covers                                                                                                                         |
| --------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| **Security**                | Core information security controls — access management, encryption, vulnerability management, incident response, etc.                  |
| **Privacy**                 | Data handling, consent, sub-processor management, and compliance with privacy regulations (GDPR, CCPA, HIPAA)                          |
| **Artificial Intelligence** | Risk controls specific to vendors that develop or deploy AI — model governance, bias, transparency, and AI-specific security practices |
| **Resilience**              | Business continuity, disaster recovery, and operational stability                                                                      |
| **Product Security**        | Secure software development, dependency management, and vulnerability disclosure programs                                              |
| **Cyber Insurance**         | Coverage and limits of the vendor's cyber insurance policy                                                                             |
| **Service Locations**       | Where the vendor stores data and operates, for data residency and geopolitical exposure                                                |

You can further tailor the controls in scope through [Custom Frameworks](/third-parties/advanced/custom-frameworks).

## How Controls Come In Scope

Controls are brought into scope by the business cases selected during relationship context configuration. Each business case maps to a set of control domains — the combination of selected business cases determines the full set of controls that must be assessed.

Example: A vendor selected with the business cases **"Stores customer data"** and **"Has privileged system access"** will have a broader set of controls in scope than a vendor selected only as a **"Provides software as a service."**

Changing a relationship's business cases immediately updates which controls are in scope. Controls that fall out of scope are marked as **Out of Scope**. New in-scope controls begin as **Unvalidated** until evidence is collected.

## Control Status

Each in-scope control has a status that reflects the current state of evidence:

| Status             | Meaning                                                                                                                               |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------- |
| **Present**        | The control is described as implemented — evidence confirms it's in place                                                             |
| **Not Present**    | The control is described as not implemented, or the audit includes a qualified opinion or exception against it                        |
| **Unvalidated**    | No evidence yet, and an assessment is in progress                                                                                     |
| **No Info**        | No evidence available and no active assessment — control could not be verified                                                        |
| **Out of Scope**   | The control domain is enabled in your org, but this control doesn't apply to this specific relationship based on its business context |
| **Not Applicable** | Confirmed by the vendor (or your team) that this control doesn't apply to their environment                                           |

Controls marked **Not Present** or **No Info** represent gaps — these drive the residual risk score upward and are the primary targets for remediation requests and follow-up questionnaires.

## Artifact Types and Control Mapping

Every artifact type recognized by VISO TRUST maps to a defined set of controls it can validate. When an artifact is uploaded and analyzed, Artifact Intelligence extracts evidence from the document and credits the controls it satisfies.

Higher-assurance artifact types validate controls with greater confidence:

| Artifact Type             | Assurance | Controls typically validated                                  |
| ------------------------- | --------- | ------------------------------------------------------------- |
| SOC 2 Type II             | High      | Security, availability, confidentiality, processing integrity |
| ISO 27001                 | High      | Information security management across all domains            |
| HITRUST CSF               | High      | Security, privacy, compliance (especially healthcare)         |
| PCI DSS ROC/AOC           | High      | Payment card data security controls                           |
| Penetration Test          | High      | Vulnerability management, application security                |
| Data Processing Agreement | Moderate  | Privacy, sub-processor management, data handling              |
| Cyber Insurance Policy    | Moderate  | Cyber insurance coverage and limits                           |
| Security Policy           | Moderate  | Policy-level coverage across security domains                 |
| SOC 2 Type I              | Moderate  | Design of controls (no operating effectiveness testing)       |
| Vendor Questionnaire      | Moderate  | Self-attested coverage across any domain                      |

## The Assurance Hierarchy

When multiple artifacts of different assurance levels address the same control, VISO TRUST uses the highest-assurance artifact to determine the control's status. A validated SOC 2 report supersedes a self-attested security policy for the same control.

When a high-assurance artifact is available, it also supersedes expired lower-assurance artifacts of the same type, and older versions of the same artifact type.

## Compliance Certifications vs. Validated Artifacts

When VISO TRUST detects a publicly claimed certification (a SOC 2 badge on a vendor's website) but doesn't have the actual report, it grants **partial credit** — a lower-confidence signal that the vendor likely meets those controls.

To upgrade from partial to full credit, request the actual certification document through a collection request. Submitting and analyzing the full report replaces the partial credit with validated evidence.
