The Guidelines page is where you manage and assign the technical work instructions (technical controls) that must be implemented across your assets.
Go to app.maplegrc.com.
Log in with your account credentials.
From the homepage, navigate to the Detection Guideline page under Detect, or the Protection Guideline page under Protect.
The technical controls on this page are automatically generated based on your organization’s software asset list and the requirements outlined in the ISO 27001.
Before working with the Guidelines page, make sure to follow these steps:
Verify your Asset Inventory
Ensure that all assets are added to your Asset Inventory. When you open the Guidelines page, you will see a list of assets already pulled from your inventory.
1. Generate procedure
If you don’t see newly added assets, click Generate Procedures. This action re-analyzes your inventory and generates the relevant guidelines so they appear on the page.
2. Refresh and review
After refreshing, your updated list of assets will appear.
3. View applicable controls
Under each asset, Expand any asset to reveal its applicable technical controls (e.g., Least Privilege, System Backup, Multi-Factor Authentication).
At the top of the page you can filter when you need focus:
By criticality — focus only on critical systems.
By regulation — for example, select ISO 27001 to see each control’s mapped control ID from that framework.
When ISO 27001 filter is applied, each technical control displays a control ID directly from ISO 27001 framework.
Open the control
Click the control ID (when filtering by ISO 27001) or the control name to open its step-by-step implementation guide tailored to that control and the specific asset.
2. Review the guide contents
Inside the guide you’ll find:
Description of the control
How to audit it
Exact steps to implement it
3. Set status & due date
Update the control’s status: Not Started, In Progress, On Hold, or Implemented.
Assign a due date for implementation.
4. Assign an owner
Assign the control to a team member (e.g., IT) or an external vendor.
Click Save. The status updates automatically and the assignee’s name appears in the members list.
5. Upload evidence (after implementation), Click the “Evidence” button
Click Add new File to upload a file from your computer.
From the Tag dropdown, choose one of: Policy, Procedure, Record, Checklist, or Other (specify).
Then, Click Upload Files
The Guidelines page helps you implement the technical controls required by ISO 27001
By completing all the steps on this page, you ensure that your organization is meeting all the applicable requirements from ISO 27001 and staying on track for certification.