Create a control tailoring request
Create a control tailoring request to modify baseline controls for an authorization package after the Select step without reverting the package to earlier workflow steps.
Vorbereitungen
- An authorization package in the Implement step or later
Roles required: sn_irm_cont_auth.admin, sn_irm_cont_auth.info_system_sec_manager, sn_irm_cont_auth.info_system_sec_officer, sn_irm_cont_auth.authorization_official
Warum und wann dieser Vorgang ausgeführt wird
Control tailoring requests allow you to propose changes to baseline controls without reverting the package to the Select step. You can add new controls, change control applicability (Applicable to Not Applicable or vice versa), or modify hybrid and inherited control configurations. All changes require AO approval before taking effect.
When you submit the request, the AO receives an email notification. After approval, an item generation job applies the changes to baseline controls and updates related controls accordingly. Controls not affected by the request remain in their current state.
Prozedur
Ergebnisse
The request state changes to In Review, and the system assigns the request to the AO or AO Delegate for approval. The AO receives an email notification. The authorization package displays an indicator showing that baseline changes are under review. You can view the request status in the My Items view under the CAM Workspace task page, which shows all control tailoring requests you have created.
After approval, the system triggers an asynchronous item generation job that applies changes to the package. Only modified controls are affected - unchanged controls retain their current state, implementation statements, test results, and approval history. The authorization package work notes record all control tailoring activities including who requested changes, what was changed, approval date, and approver.