My control is exempt - should an isssue be created ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 weeks ago
I have an exempt control through an active Policy Exception.
So, I know that my Control should remain in a compliant state if a scripted control indicator fails.
I run my scripted indicator which fails.
My control remains compliant, so that's great 🙂
However, an Issue is still created from the indicator failure, and the issue is in the NEW state - therefore requiring work and attention from the issue management team.
Isn't this a mismatch ?
Is this OOB behavior ?
I would like to suppress Issue creation when the control is exempt.
Please can you help with your advice/experience on this subject ?
Colin.
- Labels:
-
Policy and Compliance Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Thanks Conner,
That's also a good idea (flow to auto close issues), however it's still not the right solution for us.
To give some context. we have a control objective with 650 controls, of which 300 are exempt.
When the scripted indicator runs, 300 "Issue" email notifications will be sent to exempted control owners.
We want to avoid those emails as well. Because they will generate confusion.
I think the best solution will be the flow to deactivate the indicators whilst the control is exempt....
