Visual element used in the Header & Footer/Header component

Operations

What is the Living Control Set?

Manage one control, not four. The Living Control Set (LCS) makes each control the unit of work. Every framework it satisfies, every risk it carries, and every piece of evidence attached to it becomes an attribute of that single control. Compliance, risk, and evidence stop running as separate programs.

Author portrait of Dani Woolf

Dani Woolf

Chief Marketing Officer

7 min read

Table of contents

Overview 

The Living Control Set (LCS) represents the operational control set for an organization within the Cyturus CRT (Cyber Resilience Tracker). 

It constitutes the subset of controls selected from the Secure Controls Framework (SCF), the platform’s Master Control Library, that reflects the organization’s regulatory obligations, risk posture, and security practices. 

The LCS defines the actual controls an organization implements, operates, and monitors over time. 

Because organizations evolve, the LCS is designed to be living and can be updated as regulatory requirements, risks, and operational capabilities change over time. 

How the Living Control Set Is Created 

Organizations build their LCS by selecting controls from the SCF based on two categories of requirements: 

  • Minimum Compliance Requirements (MCR) 

  • Discretionary Security Requirements (DSR) 

Together, these requirements determine the set of controls that form the organization’s operational baseline. 

Minimum Compliance Requirements (MCR) 

Minimum Compliance Requirements (MCR) represent the controls necessary to meet the organization’s mandatory external obligations. These obligations may come from: 

  • laws and regulations 

  • contractual requirements 

  • regulatory frameworks 

  • industry standards 

MCR defines the minimum set of controls required for the organization to demonstrate compliance with applicable frameworks. 

Discretionary Security Requirements (DSR) 

Discretionary Security Requirements (DSR) represent additional controls an organization chooses to implement based on its risk tolerance, threat environment, and operational directives. These controls extend security capabilities beyond minimum compliance obligations and refocus the organization on establishing resilience. 

DSR allows organizations to align their security practices with risk management objectives rather than compliance requirements alone. 

Minimum Security Requirements (MSR)

The combination of MCR and DSR forms the organization’s Minimum Security Requirements (MSR). 

The MSR represents the defensible baseline of controls that the organization operates to protect its systems, data, and operations. 

Why the Control Set Is “Living” 

Unlike static compliance programs, the Living Control Set is designed to evolve. 

The LCS may change when: 

  • new regulatory requirements apply 

  • the organization adopts new frameworks 

  • risks and threat conditions change 

  • control implementations mature 

  • new systems or business operations are introduced 

This allows the organization’s control system to remain aligned with ever-changing real-world operational conditions. 

How the LCS Is Used in CRT 

Within the CRT platform, the Living Control Set acts as the operational foundation for Security, Compliance, and Resilience Management (SCRM).  

Once the LCS is established, organizations can: 

  • assess control implementation 

  • collect and manage evidence 

  • track remediation activities 

  • track conformity assessments  

  • monitor control maturity 

The LCS becomes the single source of truth for how security controls operate within the organization. 

Relationship to Conformity Engagements 

The Living Control Set is also used to evaluate the organization against specific compliance frameworks through Conformity Engagements. 

A Conformity Engagement compares the organization’s LCS against a selected framework, such as CMMC 2.0 Level 2. Rather than creating separate control systems for each framework, the CRT evaluates multiple frameworks against the same LCS. This allows frameworks to function as evaluation lenses applied to the organization’s operational control system. 

LCS in the CRT Control Architecture 

The Living Control Set is the central layer in the CRT architecture. 

[Need a visual that shows Secure Controls Framework (SCF) = Master Control Library, which points to the Living Control Set (LCS), a combo of MCR + DSR. Then shows the Conformity Engagements (ideally CMMC 2.0 Level 2) and finishes by showing the maturity tracking for the SCR level.] 

This structure allows organizations to operate under a single control system while demonstrating compliance across multiple frameworks. 

More from the blog

Keep reading there's more worth your time

More ideas on workflows, alignment, strategy, and what it actually takes to build teams that stay focused and move forward together.

See Cyturus Cyber Resilience Tracker in Action

Bring your frameworks. We'll show you how a single control answer maps everywhere and where your real maturity stands today.

No rip-and-replace · Works alongside your existing program · Built by practitioners