Skip to content
  • There are no suggestions because the search field is empty.

Vendor Risk Security Profile: Control Templates

Overview

Control templates define which controls (and checks) a vendor is assessed against on Security Profile. UpGuard has created a set of pre-built templates. Pre-built templates can’t be edited, however you can:

  • duplicate a template and then make edits on the duplicate

  • create a new template from scratch using the existing check library

  • update a tier's assigned template

See Control Template Library for the list of available templates and the frameworks and standards they cover.


Default template assignment

Four of UpGuard's pre-built templates are mapped to vendor tiers by default. Each template is designed for a vendor tier (e.g. the higher the vendor tier, the more comprehensive the default control template).

Pre-built default template Tier default
Elevated controls Tier 1
Core controls Tier 2
Lite controls Tier 3
Attack surface controls  Tier 4, 5

Duplicate an existing template

You can duplicate, and then customize, all pre-built and custom templates. 

  1. Click the Settings icon in UpGuard's top-right corner.
  2. Click Control Templates from the left navigation.
  3. Click the three dot menu on the row corresponding with the template you want to duplicate.
  4. Click Duplicate template.
  5. Update the template's name and description.
  6. Select a tier default (optional). Vendors in the specified tier will automatically switch to the new template when it's published.
  7. Click Next.
  8. Use the checkboxes to update the domains, controls, or checks you want included on this template. You can also filter checks by framework, to see checks associated with a specific one.
  9. Click Next.
  10. Review your template configuration.
  11. Click Save and Publish.

Your template is now available. If tiers are assigned to the template, any vendors in those tiers are automatically switched to this template (unless excluded from automatic template updates). The template can now also be manually applied to vendors.

Create a new control template from scratch

Create a control template from scratch when you want to build a template from the ground up. Choose checks from one framework or combine checks from multiple frameworks to choose the exact criteria you want to evaluate vendors against.  

  1. Click the Settings icon in UpGuard's top-right corner.
  2. Click Control Templates from the left navigation.
  3. Click + Create new template.
  4. Add a name and description for your template.
  5. Select a tier default (optional). Vendors in the specified tier will automatically switch to the new template when its published.
  6. Click Next.
  7. Use checkboxes to update the domains, controls, and checks you want included on this template. You’ll see pills next to each check showing which external framework(s) they map to, and you can filter checks by framework. 
  8. Click Next.
  9. Review your template configuration.
  10. Click Save Template.
  11. Click Publish Template.

Your template is now available. If tiers are assigned to the template, any vendors in those tiers are automatically switched to this template (unless excluded from automatic template updates). The template can now also be manually applied to vendors.

Update a tier's default template

  1. Click the Settings icon in UpGuard's top-right corner.
  2. Click Control Templates from the left navigation.
  3. Find the template you want to assign as a tier's default.
  4. Click the View template arrow on the corresponding row.
  5. Click Edit.
  6. Check the box next to the appropriate tier.
  7. Click Save.
All vendors in the corresponding tier now use the new template and vendors assigned the tier going forward will have it automatically assigned. 

Disable (or enable) a template

  1. Click the Settings icon in UpGuard's top-right corner.
  2. Click Control Templates from the left navigation.
  3. Click the enabled toggle on the row corresponding with the template you want to disable (or enable).

If disabling a template: Click Disable. Your template is now disabled and no longer available to apply to any vendor. Any vendors that were previously using this control template will switch to the Attack surface controls template. 

If enabling a template: Your template is now available. If tiers are assigned to the template, any vendors in those tiers are automatically switched to this template (unless excluded from automatic template updates). The template can now also be manually applied to vendors.

Delete a template

You can only delete custom templates. Word of caution: deleted templates cannot be restored, we strongly recommend being sure you want to delete before proceeding. 

  1. Click the Settings icon in UpGuard's top-right corner.
  2. Click Control Templates from the left navigation.
  3. Click the three vertical dots on the row corresponding with the template you want to delete.
  4. Click Delete.
  5. Select Delete again to confirm your choice.
The template is now deleted and no longer available to apply to any vendor. Any vendors that were previously using this control template will switch to the Attack surface controls template.