An entity in the workspace view

  • Release version: Washingtondc
  • Updated November 4, 2024
  • 3 minutes to read
  • The Entity form in the workspace provides a complete view of an entity across your organization. The Entity form is listed under the Library menu of the List view in the workspace. Select an entity in the list view so that you can display its overview, details, hierarchy, entity types, or downstream risks.

    Overview details on the Entity form

    The Entity form displays the details on the entity such as Compliance status, Risk status, and Tracking. The information about an entity is organized in different tabs such as Overview, Details, and Hierarchy as shown in the following example.

    Figure 1. Overview tab on the Entity form
    Entities overview page
    The related lists on the Entity form display the dependencies that are related to the entities as explained in the following table:
    Table 1. Tabs and Highlighted details on the Entity form
    Tab Description
    Details tab Information about the entity such as Name, Active condition that shows whether the entity is active, Owned by, Class, Description, and Location information in the Entity section. The Compliance section displays the Attestation frequency such as Annually.
    Hierarchy tab Information about the upstream entities and downstream entities, entity class, owner information.
    Highlighted details Downstream hierarchy for the selected entity, related entity types, regulatory bodies applicable to the entity, and related policies.
    The Entities section displays the following related lists:
    Table 2. Related lists in the Entities section
    Related list Description
    Entity types Details of the entity type, description, condition if the entity type was created manually and the Compliance score in percentage.
    Downstream risks Details of the downstream risk for the selected entity such as Number, Name, Entity, Class, Risk statement, Risk assessment methodology, Owning group, and Owner.
    Downstream controls Details of the downstream controls such as Name, Number, Entity, Control objective, State, Status, Exempt, Owner, and Description.
    Downstream inherited controls Details of downstream inherited controls such as Control, Number, Entity, Reliant entity, Function, State, Status, Exempt, Owner, Description, and Control objective.
    Downstream engagements Details of the downstream engagements such as Name, Number, Type, Parent plan, State, Engagement lead, Remaining expense budget (%), Remaining resource budget (%), and engagement planned start.
    Downstream issues Details of the downstream issues such as Issue, Number, Entity, Priority, Assigned to, and Issue manager. You can add existing Issues, create new issue, or remove an existing issue.
    Downstream tasks Details of the downstream tasks such as Name, Number, Parent, State, Assigned to, and Planned end date.
    Policy exceptions Details of the policy exceptions such as Name, Number, State, Substate, Policy, Control objective, Issue, Reason, Requester, Valid from, Valid to, and Risk rating.
    Risk events Details of the risk events such as Risk event, Primary entity, Event type, Sub type, State, Date of discovery, Net loss, Expected loss, and Non-financial impact.
    Content references Details of the content reference such as Content reference, Description, and version. You can click Add to add the content references.
    Risk assessments Details of the risk assessments such as Number, Risk assessment methodology, Assessable entity, Risk, Applies to record, Inherent risk, Control effectiveness, Residual risk, Response, Assessor, and End date.
    Aggregated risks Details of the aggregated risks such as Risk assessment methodology, Residual rating, Inherent rating, Control effectiveness, Residual ALE, Inherent ALE, Contributing risk assessments, and Risk rollup status.
    Privacy assessments Details of the Privacy assessments such as Number, Metric type, Classification, Due date, State, and Assigned to.
    CRI Tiering assessments Details of tiering assessment of an entity such as the Assessment template, State, Users, and Due date.
    CRI assessments Details of control assessment such as the Assessment template, State, Users, and Due date.
    Stakeholders Stakeholders with customizable roles relevant to single and composite entities, enabling effective team involvement in risk assessments and projects. You can add persona, group, and users in the stakeholder list.
    The 360° view displays an entire relationship view for the selected entity the upstream entities, downstream entities, entity class and entity type associated with the entity, and the relationships that the entity includes.
    Figure 2. 360 degree view of the entity
    360 degree view of the entity