- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-06-2019 07:07 AM
Does each policy statement have an indicator template? Also when the indicators are generated, what would be the next step?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-07-2019 10:38 AM
Indicator templates are applied to policy statements and the indicators are associated with the controls generated from respective policy statements.
Indicator templates are used when you've data collected in SNOW tables or through manual tasks assigned to an user that'd determine control compliance.
Controls are used to determine the compliance status of policy statement by means of attestation or indicators.
Once the controls are generated, compliance manager or GRC admin defines control attributes(fields) and hence owning group as well. I couldn't find out any functionality around "Owning group" except that it's used to define which group would be owning the control. The context for owning group or owner is, OOB control owner is the user who is responsible for sharing the necessary evidence, attestation or perform tasks to ensure control compliance. For eg. if there is a control for BGV check for newly-onboarded employee, HR executive would be the control owner and HR group would be owning group.
Based on the attestation values, control moves to compliant state or remains in non-compliant state. If it's in non-compliant state, indicator tasks that could ensure the control compliance could be created and make the control as compliant. This happens in "Review" state of control.
OOB frequency of control is set at profile level through a scheduled job. However, you could tweak to set the control frequency at control level. Controls which are not in "Draft" and "Attest" could be perioedically defined to move to "Attest" state. For eg. For the same BGV control, you could set the frequency as "Monthly" through a schedule job and check the compliance status through attestation or indicators.
Hope this helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-07-2019 10:38 AM
Indicator templates are applied to policy statements and the indicators are associated with the controls generated from respective policy statements.
Indicator templates are used when you've data collected in SNOW tables or through manual tasks assigned to an user that'd determine control compliance.
Controls are used to determine the compliance status of policy statement by means of attestation or indicators.
Once the controls are generated, compliance manager or GRC admin defines control attributes(fields) and hence owning group as well. I couldn't find out any functionality around "Owning group" except that it's used to define which group would be owning the control. The context for owning group or owner is, OOB control owner is the user who is responsible for sharing the necessary evidence, attestation or perform tasks to ensure control compliance. For eg. if there is a control for BGV check for newly-onboarded employee, HR executive would be the control owner and HR group would be owning group.
Based on the attestation values, control moves to compliant state or remains in non-compliant state. If it's in non-compliant state, indicator tasks that could ensure the control compliance could be created and make the control as compliant. This happens in "Review" state of control.
OOB frequency of control is set at profile level through a scheduled job. However, you could tweak to set the control frequency at control level. Controls which are not in "Draft" and "Attest" could be perioedically defined to move to "Attest" state. For eg. For the same BGV control, you could set the frequency as "Monthly" through a schedule job and check the compliance status through attestation or indicators.
Hope this helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-07-2019 11:41 AM
OOB Attestation frequency used to be at the Profile level; in Madrid, it's at the Control level, which makes much more sense. Non-compliance, whether from a failed indicator or a non-compliant attestation, always creates an Issue, which should be used to resolve compliance issues.
Many of my clients have judged the use of manual indicators to be duplicative of attestations, since you're asking someone to provide evidence that they comply with the control, and less objective, since the indicator owner has to provide the response, and have elected not to use them.