Frameworks and the control library
The shipped frameworks, the 321 common controls they map to, building your own framework with versions, and the template packs.
Every framework in Tenvara is built on one library of common controls. A control such as "MFA-01 Multi-factor authentication for online services" is checked or attested once for a customer, and counts for every requirement, in every framework, that it satisfies. So a customer working towards ISO 27001 who already meets Cyber Essentials starts well along the way.
Open it from Security > Compliance > Library (also Library on the Compliance page).

The frameworks
| Framework | What it holds |
|---|---|
| ISO/IEC 27001:2022 | Clauses 4 to 10 and the 93 Annex A controls. Annex A controls are met by live checks where Tenvara has the data, by attestation and evidence where it does not |
| ISO 9001:2015 | Clauses 4 to 10, met mostly by attestation and evidence, with customer satisfaction, service levels, complaints and supplier figures from the service desk |
| UK GDPR and Data Protection Act 2018 | An accountability checklist: governance, lawful basis, rights, records, security, breaches, processors, transfers, design, retention and marketing |
| Cyber Essentials (v3.3) | The five technical controls, with their own readiness pages |
| Essential Eight, NIST CSF 2.0, CIS Controls v8.1, NIS2 | As described in Compliance frameworks |
Every requirement is in Tenvara's own words with the standard's clause and control numbers, so you can follow it without a copy of the standard to hand. The UK GDPR checklist is guidance, not legal advice. Read the standards themselves for their exact wording.
Common controls
The Common controls tab lists the 321 controls in 24 domains (governance, risk, assets, identity, MFA, privileged access, vulnerabilities, logging, malware, email, network, backup, continuity, awareness, suppliers, incidents, quality, privacy and more). Each shows its checks (where Tenvara can judge it live), how it is met, and which requirements it satisfies across every framework. Open one to see every requirement it covers.
You can add common controls of your own; they are numbered apart (for example M-BCK-1) so they never clash with the shipped ones.
Building your own framework
Use your own framework for an insurer's questionnaire, a customer's contract requirements or an industry checklist.
- On the Frameworks tab press New framework, or Duplicate any framework (shipped or yours) to start from a copy.
- Add groups and requirements. Each requirement has a reference, a title, guidance, a level if you use levels, and whether it is met automatically, by attestation or both.
- Map each requirement to common controls: exactly one primary control that fully satisfies it, and others that fully or partly do. This is what lets live checks and attestations count.
- Press Publish. Tenvara lists any problems first (a requirement without a primary control, for example). The published version becomes current.
To change a published framework, start a new version: it begins as a copy of the current one, and only one draft exists at a time. Compare versions shows what was added, removed and changed, field by field. A framework that customers or programmes use cannot be deleted; make it inactive instead.
Export downloads a version as a file and Import reads one back (it checks the file first and lists anything wrong), so a framework can move between installs. An import never overwrites anything: it always becomes your own framework or a new draft version of one.
Note: Shipped frameworks never change in the builder: they are updated with Tenvara's releases. If you have changed a shipped control or requirement, an update never writes over your change; the new wording waits for you to accept or keep yours.
Template packs
The Template packs tab holds starting points for the documents a programme needs, in Tenvara's own words:

- ISO 27001 mandatory documents: scope, policy, risk method, Statement of Applicability, treatment plan, objectives, competence, internal audit, management review and corrective action.
- ISO 27001 topic policies: about twenty, from acceptable use to information transfer, each linked to the Annex A controls it supports.
- ISO 9001 quality documents, the Cyber Essentials policy set and UK GDPR documents (data protection policy, record of processing, DPIA, privacy notice, breach procedure, data subject requests and retention schedule).
Open a pack to preview each document, its placeholders and the requirements and controls it supports. Placeholders such as {customer}, {isms_owner}, {review_period} and {scope} are filled from the programme when the document is adopted for a customer. Each template starts with a "template, adapt before use" notice. Turn templates into your masters from Policy documents: see Policy documents under control.
Was this page helpful?
Thanks for the feedback.