Overview
The Living Control Set (LCS) represents the operational control set for an organization within the Cyturus CRT (Cyber Resilience Tracker).
It constitutes the subset of controls selected from the Secure Controls Framework (SCF), the platform’s Master Control Library, that reflects the organization’s regulatory obligations, risk posture, and security practices.
The LCS defines the actual controls an organization implements, operates, and monitors over time.
Because organizations evolve, the LCS is designed to be living and can be updated as regulatory requirements, risks, and operational capabilities change over time.
How the Living Control Set Is Created
Organizations build their LCS by selecting controls from the SCF based on two categories of requirements:
Minimum Compliance Requirements (MCR)
Discretionary Security Requirements (DSR)
Together, these requirements determine the set of controls that form the organization’s operational baseline.
Minimum Compliance Requirements (MCR)
Minimum Compliance Requirements (MCR) represent the controls necessary to meet the organization’s mandatory external obligations. These obligations may come from:
laws and regulations
contractual requirements
regulatory frameworks
industry standards
MCR defines the minimum set of controls required for the organization to demonstrate compliance with applicable frameworks.
Discretionary Security Requirements (DSR)
Discretionary Security Requirements (DSR) represent additional controls an organization chooses to implement based on its risk tolerance, threat environment, and operational directives. These controls extend security capabilities beyond minimum compliance obligations and refocus the organization on establishing resilience.
DSR allows organizations to align their security practices with risk management objectives rather than compliance requirements alone.
Minimum Security Requirements (MSR)
The combination of MCR and DSR forms the organization’s Minimum Security Requirements (MSR).
The MSR represents the defensible baseline of controls that the organization operates to protect its systems, data, and operations.
Why the Control Set Is “Living”
Unlike static compliance programs, the Living Control Set is designed to evolve.
The LCS may change when:
new regulatory requirements apply
the organization adopts new frameworks
risks and threat conditions change
control implementations mature
new systems or business operations are introduced
This allows the organization’s control system to remain aligned with ever-changing real-world operational conditions.
How the LCS Is Used in CRT
Within the CRT platform, the Living Control Set acts as the operational foundation for Security, Compliance, and Resilience Management (SCRM).
Once the LCS is established, organizations can:
assess control implementation
collect and manage evidence
track remediation activities
track conformity assessments
monitor control maturity
The LCS becomes the single source of truth for how security controls operate within the organization.
Relationship to Conformity Engagements
The Living Control Set is also used to evaluate the organization against specific compliance frameworks through Conformity Engagements.
A Conformity Engagement compares the organization’s LCS against a selected framework, such as CMMC 2.0 Level 2. Rather than creating separate control systems for each framework, the CRT evaluates multiple frameworks against the same LCS. This allows frameworks to function as evaluation lenses applied to the organization’s operational control system.
LCS in the CRT Control Architecture
The Living Control Set is the central layer in the CRT architecture.
[Need a visual that shows Secure Controls Framework (SCF) = Master Control Library, which points to the Living Control Set (LCS), a combo of MCR + DSR. Then shows the Conformity Engagements (ideally CMMC 2.0 Level 2) and finishes by showing the maturity tracking for the SCR level.]
This structure allows organizations to operate under a single control system while demonstrating compliance across multiple frameworks.




