- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-02-2019 11:17 PM
Hi Everyone,
What is the significance of creating Entity Type? I can create Entity directly and can complete the entire process. Trying to understand the need for creating Entity type?
Solved! Go to Solution.
- Labels:
-
Policy and Compliance Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-07-2019 09:55 AM
Hi Prashant,
Yes, In New York release we definitely can create stand alone entities and complete the process.
But one of the important use of Entity Types comes into picture when you want to generate multiple controls or risks for one type of service/department/locations etc.
For example, if you want to generate a risk of earthquake to all the data centers listed in your table then might just want to associate an entity type called "Data Center" and all the entities will automatically be assigned a risk based on the risk statement your assigning that entity type to.
Risk Statement + Entity Type = Risks (auto generated)
Control Objectives + Entity Type = Controls (auto generated if checkbox "create controls automatically" is checked")
Hope this helps!
Thanks,
PJ

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-25-2019 04:27 AM
Here is the details about Target

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-25-2019 05:12 AM
I know this one has been marked complete, but I would like to add one thought regarding the value of entity types.
Entity Types are a way to clearly define the scope, or conditions for a set of records, that you want to manage the controls and/or risks. Then automate the creation of new entities systematically (or retire old). For example; you may say, "all windows servers must do X". The entity type's filter would point at the cmdb windows server table, returning all windows server. You'd relate the 'X' control to the entity type and save. Months later, when another team adds new servers, the scheduled job, identifies the new records, creates the new entities, and assigns the 'X' control automatically. This automation eliminates servers slipping through the cracks and later becoming a audit finding.
Hope that makes sense.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-25-2022 04:51 AM
I know this may be closed - but what happens when an Entity is REMOVED from an Entity Type -why does that feature (remove) require elevated privileges? For example we have an Entity Type called Business Critical Apps and Entity ABC is assigned to that Entity Type and gets a superset of controls. A few months later that application is reclassified as a Business App (no longer considered critical) and therefore REMOVED from the Business Critical APp entity type and added to the Business App entity type. What happens to the controls that are mapped to BOTH entity types for entity ABC? It seems like Entity Types are very stringent and you shouldn't be moving Entities across different entity types... Is that correct?