> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md).

# Use a built-in or custom control

When using custom standards, you can use built-in controls or create custom controls and then associate them with detection rules.

## Add a built-in control to a custom standard

Cortex XDR provides built-in controls that cannot be edited or deleted. When you edit or create a custom standard you can add the built-in control.

## Create a custom control to use in a custom standard

You can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard.

1. In the **Controls** catalog, click **+ Create Control**.
2. Define control metadata, including:
   * Control name
   * Description (optional)
   * Category
   * Sub category (optional)
   * A single custom standard to associate the control with
3. Click **Create**.
4. Assign a custom detection rule to the control as follows.

## Associate a custom control to a detection rule

You can associate custom compliance controls with workload security and cloud security rules to tailor compliance checks to your organization's needs. This can be done during rule creation (custom rules only) and edit (for both custom and out-of-the-box rules).

{% hint style="info" %}
**NOTE**

Custom rules can only be associated with custom compliance controls.
{% endhint %}

The following table summarizes which rule types can be associated with custom compliance controls:

|                                                                                                                                                                                                                                                                                        | OOTB rules                                                                                                    | Custom rules                                                                                                        |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- |
| **Cloud workload rules**                                                                                                                                                                                                                                                               | N/A                                                                                                           | When creating or editing custom cloud workload rules, you can associate custom compliance controls with them.       |
| <p><strong>Cloud security rules</strong></p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE</strong></p><p>You can only associate custom compliance controls to the following cloud security rule types: ConfigIdentityAI</p></div> | You can edit existing out-of-the-box cloud security rules and associate custom compliance controls with them. | When creating or editing custom cloud cloud security rules, you can associate custom compliance controls with them. |

When creating or editing a cloud workload or cloud security rule you can associate a custom compliance control with it.

1. Navigate to **Posture Management → Rules & Policies → Rules → Cloud Workload** or **Cloud Security**.
2. From here, you can do the following:
   1. Click **Create Policy** to create a new policy.
   2. Search for an existing rule, click it, and then select **Edit** from the menu.
3. In the **Overview → Compliance Controls** field, click **Add** to add compliance controls to the rule:\
   ![](/files/o2TLAJTM5ItR0r0CqknO)
4. Click **Add**, select one or more custom compliance controls from the list, and then click **Assign**.
5. After you have saved the changes, the custom detection rule is assigned to the custom control.

## Edit a custom control

You can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control.

1. In the **Controls** catalog, click [![cortex-cloud-compliance-three-dots.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAA8AAAAgCAYAAADNLCKpAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAAEnQAABJ0Ad5mH3gAAADhSURBVEhL7ZQ9CoNAFIQnKW0Ua29hb2thoxewFew8gmcQPICVnSfRyiNYCza2Jk8GkgdZSAIhQvLBssMswz7e/py2K3iTM+e3+Idf5IDhtm0RBAHiOMYwDHQ1xnBd11jXFdM0oWkauhpj2HVdKsC2bSqN8W5LqbKjBIuigOM4XLnxvYfxmbLliKTTQhRFKMty1/cYy57nmQpYloVKYwzneQ7LsuB5HtI0pas54DckV1O63XUdnQdI2Y/IsmzzfX8fVVXR1Rh37vueChjHkUpjDCdJQgWEYUilOWC3n+H3wsAFdcOHmDnAN1gAAAAASUVORK5CYII=)](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the built-in control you want to edit and click **Save as new**.\
   To edit a custom control, click [![cortex-cloud-compliance-three-dots.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAA8AAAAgCAYAAADNLCKpAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAAEnQAABJ0Ad5mH3gAAADhSURBVEhL7ZQ9CoNAFIQnKW0Ua29hb2thoxewFew8gmcQPICVnSfRyiNYCza2Jk8GkgdZSAIhQvLBssMswz7e/py2K3iTM+e3+Idf5IDhtm0RBAHiOMYwDHQ1xnBd11jXFdM0oWkauhpj2HVdKsC2bSqN8W5LqbKjBIuigOM4XLnxvYfxmbLliKTTQhRFKMty1/cYy57nmQpYloVKYwzneQ7LsuB5HtI0pas54DckV1O63XUdnQdI2Y/IsmzzfX8fVVXR1Rh37vueChjHkUpjDCdJQgWEYUilOWC3n+H3wsAFdcOHmDnAN1gAAAAASUVORK5CYII=)](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the custom control and click **Edit**.
2. Click **Next**.
3. Define control metadata, including:
   * Control name
   * Description
   * Category
   * Sub category
   * A single custom standard to associate the control with
4. Click **Save**.
5. If the control does not already contain a rule, assign a custom detection rule to the control.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
