- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-20-2019 01:29 PM
What's the purpose of the new "Content Reference" feature/Related List on the Authority Document form? Where can I find documentation on this?
Solved! Go to Solution.
- Labels:
-
Policy and Compliance Management

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-23-2019 08:29 PM
Hi Mike and Jing,
We have added this new related list to all the GRC tables for tagging the content to various frameworks/regulations. For e.g. NIST RMF and NIST CSF related content (controls, policies, policy statements/ control objectives can be tagged as NIST RMF/CSF and you can also tag them to other frameworks/regulations like SOX). Thanks for pointing out that its not documented. We will update it. I hope this helps!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-22-2019 08:22 AM
It looks like it is used by the content packages, such as NIST CSF, and NIST RMF. This might be used if a company have its own Authority Document content.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-22-2019 06:41 PM
Thank you Jing. That's interesting. However, those content packs aren't installed.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-23-2019 10:39 AM
Hi Mike, Thanks for point it out. I checked you are correct, it looks like it is introduced via GRC: Profiles 7.1.4 upgrade. On the other hand, this update is required by NIST CSF and NIST RMF. Looks like this table, along with others, enables NIST CSF and NIST RMF. I agree with you, no documentation makes it confusing. In another posting, one was trying to use "Content Reference" field to put a given risk statement into different risk frameworks.
How to have a Risk be connected to multiple Frameworks?
I

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-23-2019 08:29 PM
Hi Mike and Jing,
We have added this new related list to all the GRC tables for tagging the content to various frameworks/regulations. For e.g. NIST RMF and NIST CSF related content (controls, policies, policy statements/ control objectives can be tagged as NIST RMF/CSF and you can also tag them to other frameworks/regulations like SOX). Thanks for pointing out that its not documented. We will update it. I hope this helps!