Performing a single advanced risk assessment for a bunch of entities or entity class
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2022 06:34 AM
Hello community,
I might have asked this prior but wanted to rehash this topic.
I have a requirement from a client asking me if they could ONE Advanced Risk Assessment against a bunch of entities or entity types.
Is this an existing capability of GRC - Advanced Risk Assessment? I can't find anything on the docs website that addresses this particularity.
Thanks in advanced.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2022 07:09 AM
Hi,
Advanced Risk offer RAM capability where you can create Risk Assessment Methodology for one entity class.
The RAM is a configuration or a record in the new risk assessment engine. It is part of the Advanced Risk application.
The RAM is used for assessing either the risks or objects in your organization. A RAM is configured to specify the types of risk assessments and the entities on which risk assessment is performed. A configured RAM is an object with associated assessment types that have associated factors. This allows an organization to have different methodologies for assessing risk.
After a RAM moves to the Retired state, you can also move it back to the Draft state if you want to make some changes to the RAM. You can only move a RAM to Draft state if it does not have any assessments in Monitor state or Closed state. When you move a RAM back to Draft, the on-going assessments and the associated scopes are deleted.
You can find more here:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2022 07:15 AM
@ServiceNow SA thank you for the info and for responding.
I'm aware of the RAM but my question is actually a bit different than what you provided (or maybe I misread - if I did, please accept my apology).
The RAM is configured for a specific entity class.
But what my client wants is to generate risk assessments for several entities and then do ONE risk assessment, and have the assessment reflected onto the several entities. Kind of a 'one assessment for several entities'.
Is that possible with ARA?
I know with the Classic Risk, you can group Risk Assessments but I can't seem to find a similar function for ARA.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-31-2024 12:55 AM
One entity will have one assessment. It is not possible to to have single assessment for multiple entities