Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

Control Indicators with one sided data

adamcupp
Tera Contributor

What is the best way to have #IRM with OOB function handle a situation where we don't have all the data (or high confidence in some data). 

 

For example, if we have a control: "Don't use this list of Prohibited Software Products", and our if software inventory scanning solution doesn't currently support MacOS scanning, we know that for those system that a lack of an indicator doesn't mean that it IS compliant.  We do know if one of those SW items is found it's "Non-Compliant", but we don't know for sure that they are all "Compliant".  How can we use #IRM OOB functions to handle this case?

1 REPLY 1

pratikjagtap
Giga Guru

Hi @adamcupp ,

 

The recommended out-of-the-box IRM approach is not to mark assets as Compliant when evidence is missing. Instead:

  • Mark the result as Not Evaluated, Unknown, or Requires Manual Review (depending on your IRM configuration).
  • Only mark assets as Compliant or Non-Compliant when sufficient evidence is available.
  • If the missing evidence itself is a risk (for example, macOS devices cannot be scanned), create an IRM Issue or remediation task to track the coverage gap.
  • Keep compliance status separate from evidence coverage to ensure accurate reporting and audit compliance.

If my response helped, please hit the 👍Thumb Icon and accept the solution so that it benefits future readers.

 

Regards,
Pratik