Governance, Risk, and Compliance - Data segregation

Brad Fleming
Tera Contributor

We are planning to use GRC for IT and non-IT (i.e., environmental) risk and compliance.  We are a single service provider with a dedicated instance, & no domain separation.  Within GRC do we have the ability to restrict visibility to data that mimics domain separation?  For example, Users within ABC department/groups only see IT related risk and compliance dashboards/reports/data, and Users withing XYZ department/groups only see non-IT related risk and compliance data?

1 ACCEPTED SOLUTION

the question related to implementing something similar to domain separation for the different teams. Using the confidentiality tags achieve the same as that: you cannot see the records if you do not belong to the correct group 🙂

View solution in original post

6 REPLIES 6

the question related to implementing something similar to domain separation for the different teams. Using the confidentiality tags achieve the same as that: you cannot see the records if you do not belong to the correct group 🙂

Tom Shek
Tera Contributor

@Sebastien Fix  If using the confidentiality tags, will it mean that if I have 4 Business Units and I dont want them to see each other risk assessment results, I will have to create 4 grc users groups and tag it to the Business Units separately.