Skip to content
Question Bank & Templates

Start from real controls, then make them yours.

Start from 100+ ready controls, then shape them into your own standard.

100+
Controls ready to use
16
Sections of physical security
Version & lock
So audits stay comparable

100+

Controls

Physical security assessment, ready to use

16

Sections

From insider risk to emergency procedures

2

Templates ship ready

GFSA and GTSA, Level 1

3

Criticality levels

Critical, high and standard controls

Coverage

What the control set asks about.

A sample of the sections. These are facility questions, the kind an auditor walks a site to answer rather than a form about policy documents.

Insider Risk ManagementSecurity Awareness & TrainingTraveller SecurityCyber & Information Security ControlsPhysical Security Controls – AlarmsPhysical Security Controls – Access Control SystemCCTV & Surveillance ControlsPhysical Security Controls – Lighting+ 8 more sections

Every control carries its context

A question isn't just text. It comes with its category, its control id, whether it's critical, whether evidence is mandatory, and which external standard it corresponds to.

  • 1Category and control id on every entry
  • 2Criticality and mandatory-evidence flags
  • 3Which evidence types are acceptable for that control
  • 4The documentation an auditor should expect to see
Question Bank
Question bank listing security controls with their category and criticality
Template builder

Build the standard you audit against.

Most security teams already have a control set, in a spreadsheet or a document or someone's head. This is where it becomes something you can run.

  1. 1

    Start

    From a ready control set, from the question bank, or from an empty template.

  2. 2

    Shape

    Add sections and questions. Set criticality and evidence requirements.

  3. 3

    Weight

    Assign section and question weights. The platform validates they sum to 100.

  4. 4

    Version

    Publish a version. Clone it later when the standard changes.

  5. 5

    Lock

    Lock the version you audit against, so it can't shift mid-cycle.

References, not mapping

Each control cites the external standard it corresponds to: C-TPAT MSC, TAPA FSR, ISO. That's a citation you can read, and it's how you assemble a framework-shaped assessment. It is not an engine that answers one control and fills in others for you.

C-TPAT MSCTAPA FSRAEO

Weighting that's validated

Section and question weights must sum to 100. The platform enforces it, so you can't publish a template that quietly produces a score nobody can interpret.

ValidatedPer section & question

Versioning and cloning

Standards change. Clone the current template, revise it and publish a new version, keeping the old one intact so historical audits still make sense against what they were scored on.

CloneVersion history

Locking

Lock a template so it can't be edited. An audit cycle running against a moving control set produces results you can't compare year on year.

Immutable once locked
Everything in this module

The full list.

  • 100+ controls across 16 sections, ready to use
  • Every control cites its C-TPAT, TAPA FSR and AEO reference
  • Criticality and mandatory-evidence rules per control
  • Build custom templates section by section, with weighting
  • Version and clone templates; lock the ones that shouldn't change
  • Import an existing question set rather than retyping it

See it against your own sites

Thirty minutes with the people who build it, walked through the modules that matter to your programme rather than a scripted tour.