Appearance
Status Definitions
This reference table outlines the authoritative status states used across OrviQ entities.
1. Requirement Determination States
- unassessed: Baseline state; no compliance assessment has been performed.
- compliant: Requirement verified as satisfied by effective controls and valid evidence.
- partially_compliant: Minor compliance gaps or partial evidence coverage.
- non_compliant: Substantial deficiencies or lack of mitigating controls.
- not_applicable: Formally scoped out with documented justification.
2. Control Operational States
- active: Control is actively implemented and maintained.
- draft: Control is being authored or revised.
- deprecated: Control is being phased out.
- inactive: Control is decommissioned.
3. Control Effectiveness States
- effective: Passed operational testing with valid evidence.
- partially_effective: Minor exceptions noted during testing.
- ineffective: Failed testing or substantial operational breakdown.
- not_assessed: No operational testing record exists.
4. Crosswalk Mapping Governance States
- proposed: Draft mapping suggested by AI or author, awaiting review.
- approved: Formally approved by a compliance officer.
- rejected: Rejected during maker-checker review.
- superseded: Replaced by an updated mapping revision.
5. Evidence Freshness States
- fresh: Valid and within active period window.
- expiring_soon: Within 30 days of validity expiration.
- expired: Past expiration date; requires renewed proof.
6. Risk Statuses
- open: Active risk being monitored or treated.
- mitigated: Residual risk brought within risk appetite.
- accepted: Formally approved under a Governed Exception.
- closed: Inactive risk or retired threat vector.
7. Policy Governance States
- draft: Under creation or editing.
- in_review: Under stakeholder or legal review.
- published: Active official organizational policy.
- archived: Retired policy revision.