> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md).

# Use a built-in or custom control

When using custom standards, you can use built-in controls or create custom controls and then associate them with detection rules.

## Add a built-in control to a custom standard

Cortex XSIAM provides built-in controls that cannot be edited or deleted. When you edit or create a custom standard you can add the built-in control.

## Create a custom control to use in a custom standard

You can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard.

1. In the **Controls** catalog, click **+ Create Control**.
2. Define control metadata, including:
   * Control name
   * Description (optional)
   * Category
   * Sub category (optional)
   * A single custom standard to associate the control with
3. Click **Create**.
4. Assign a custom detection rule to the control as follows.

## Associate a custom control to a detection rule

You can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules.

{% hint style="info" %}
**NOTE**

Custom rules can only be associated with custom compliance controls.
{% endhint %}

The following table summarizes supported rule associations.

| Rule type                | Built-in rules                                                                    | Custom rules                                                                                |
| ------------------------ | --------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| **Cloud workload rules** | Not applicable.                                                                   | Associate custom compliance controls while creating or editing custom cloud workload rules. |
| **Cloud security rules** | Associate custom compliance controls while editing built-in cloud security rules. | Associate custom compliance controls while creating or editing custom cloud security rules. |

{% hint style="info" %}
**NOTE**

You can associate custom compliance controls only with `ConfigIdentityAI` cloud security rules.
{% endhint %}

To associate a custom compliance control:

1. Go to **Posture Management → Rules & Policies → Rules → Cloud Workload** or **Cloud Security**.
2. Create a custom policy, or edit an existing rule.
3. In **Overview → Compliance Controls**, click **Add**.
4. Select one or more custom compliance controls.
5. Click **Assign**.
6. Save your changes.

## Edit a custom control

You can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control.

1. In the **Controls** catalog, click [![cortex-cloud-compliance-three-dots.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAA8AAAAgCAYAAADNLCKpAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAAEnQAABJ0Ad5mH3gAAADhSURBVEhL7ZQ9CoNAFIQnKW0Ua29hb2thoxewFew8gmcQPICVnSfRyiNYCza2Jk8GkgdZSAIhQvLBssMswz7e/py2K3iTM+e3+Idf5IDhtm0RBAHiOMYwDHQ1xnBd11jXFdM0oWkauhpj2HVdKsC2bSqN8W5LqbKjBIuigOM4XLnxvYfxmbLliKTTQhRFKMty1/cYy57nmQpYloVKYwzneQ7LsuB5HtI0pas54DckV1O63XUdnQdI2Y/IsmzzfX8fVVXR1Rh37vueChjHkUpjDCdJQgWEYUilOWC3n+H3wsAFdcOHmDnAN1gAAAAASUVORK5CYII=)](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the built-in control you want to edit and click **Save as new**.\
   To edit a custom control, click [![cortex-cloud-compliance-three-dots.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAA8AAAAgCAYAAADNLCKpAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAAEnQAABJ0Ad5mH3gAAADhSURBVEhL7ZQ9CoNAFIQnKW0Ua29hb2thoxewFew8gmcQPICVnSfRyiNYCza2Jk8GkgdZSAIhQvLBssMswz7e/py2K3iTM+e3+Idf5IDhtm0RBAHiOMYwDHQ1xnBd11jXFdM0oWkauhpj2HVdKsC2bSqN8W5LqbKjBIuigOM4XLnxvYfxmbLliKTTQhRFKMty1/cYy57nmQpYloVKYwzneQ7LsuB5HtI0pas54DckV1O63XUdnQdI2Y/IsmzzfX8fVVXR1Rh37vueChjHkUpjDCdJQgWEYUilOWC3n+H3wsAFdcOHmDnAN1gAAAAASUVORK5CYII=)](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the custom control and click **Edit**.
2. Click **Next**.
3. Define control metadata, including:
   * Control name
   * Description
   * Category
   * Sub category
   * A single custom standard to associate the control with
4. Click **Save**.
5. If the control does not already contain a rule, assign a custom detection rule to the control.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
