Create a control tailoring request
Create a control tailoring request to modify baseline controls for an authorization package after the Select step without reverting the package or disrupting ongoing assessments.
Before you begin
Ensure you have the following:
- An authorization package in the Categorize step or later
- Authorizing Official (AO) or AO Delegate configured for the package
Role required: sn_grc_cam.manager or sn_grc_cam.admin
About this task
Control tailoring requests allow you to propose changes to baseline controls without reverting the package to the Select step. You can add new controls, change control applicability (Applicable to Not Applicable or vice versa), or modify hybrid and inherited control configurations. All changes require AO approval before taking effect.
When you submit the request, the system generates an approval task for the AO. After approval, an item generation job applies the changes to baseline controls and updates related controls accordingly. Controls not affected by the request remain in their current state.
Procedure
Result
The request state changes to In Review, and the system assigns the request to the AO or AO Delegate for approval. The control tailoring request appears in the Pending state. The authorization package displays an indicator showing that baseline changes are under review. You can view the request status in the My Items view under the CAM Workspace task page, which shows all control tailoring requests you have created.