Skip to main content
CONTROL LIBRARY

The real data model. Not a smaller lookalike.

The same living control library described in the platform section — controls modeled independently of frameworks, with citation links to whichever framework packs you've installed. This is not a subset: Community Edition's control library is the real data model.

Why "independently of frameworks" is the point

A control like "privileged access requires multi-factor authentication" is one thing. NIS2 cites it, ISO 27001 cites it, SOC 2 cites it, and your own internal standard cites it. Model the control once and let each framework's pack cite it, and satisfying it once satisfies every citation. Model a separate control per framework, and your team implements the same requirement four times under four names — the tax the library exists to abolish.

Because the library ships with Community Edition, that structure is not a claim you take on faith — self-host it and inspect it. The schema, the controls, and the citation links are on your infrastructure, in your datastore, reviewable line by line.

What stays identical

The control data model, the citation schema, and the pack format are the same artifacts TruSecure GRC runs on. A control model built in Community Edition describes the same reality as one built in TruSecure GRC — which is also why the path from one to the other is not a migration so much as a change of operating model.

What differs by edition is the update service around the library, not the library's substance — the framework-packs page covers that split in detail.

See the control architecture