Some PDIs are currently unavailable, and PDI actions are paused. View the latest updates here. Read More

Control Indicators with one sided data

adamcupp
Tera Contributor

What is the best way to have #IRM with OOB function handle a situation where we don't have all the data (or high confidence in some data). 

 

For example, if we have a control: "Don't use this list of Prohibited Software Products", and our if software inventory scanning solution doesn't currently support MacOS scanning, we know that for those system that a lack of an indicator doesn't mean that it IS compliant.  We do know if one of those SW items is found it's "Non-Compliant", but we don't know for sure that they are all "Compliant".  How can we use #IRM OOB functions to handle this case?

1 REPLY 1

pratikjagtap
Giga Guru

Hi @adamcupp ,

 

The recommended out-of-the-box IRM approach is not to mark assets as Compliant when evidence is missing. Instead:

  • Mark the result as Not Evaluated, Unknown, or Requires Manual Review (depending on your IRM configuration).
  • Only mark assets as Compliant or Non-Compliant when sufficient evidence is available.
  • If the missing evidence itself is a risk (for example, macOS devices cannot be scanned), create an IRM Issue or remediation task to track the coverage gap.
  • Keep compliance status separate from evidence coverage to ensure accurate reporting and audit compliance.

If my response helped, please hit the 👍Thumb Icon and accept the solution so that it benefits future readers.

 

Regards,
Pratik