Control Indicators with one sided data
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
13 hours ago
What is the best way to have #IRM with OOB function handle a situation where we don't have all the data (or high confidence in some data).
For example, if we have a control: "Don't use this list of Prohibited Software Products", and our if software inventory scanning solution doesn't currently support MacOS scanning, we know that for those system that a lack of an indicator doesn't mean that it IS compliant. We do know if one of those SW items is found it's "Non-Compliant", but we don't know for sure that they are all "Compliant". How can we use #IRM OOB functions to handle this case?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
an hour ago
Hi @adamcupp ,
The recommended out-of-the-box IRM approach is not to mark assets as Compliant when evidence is missing. Instead:
- Mark the result as Not Evaluated, Unknown, or Requires Manual Review (depending on your IRM configuration).
- Only mark assets as Compliant or Non-Compliant when sufficient evidence is available.
- If the missing evidence itself is a risk (for example, macOS devices cannot be scanned), create an IRM Issue or remediation task to track the coverage gap.
- Keep compliance status separate from evidence coverage to ensure accurate reporting and audit compliance.
If my response helped, please hit the 👍Thumb Icon and accept the solution so that it benefits future readers.
Regards,
Pratik