Manage controls using the Compliance Workspace
Summarize
Summary of Manage controls using the Compliance Workspace
The Compliance Workspace allows organizations to manage controls effectively, which are specific implementations of control objectives. It is essential to rationalize, consolidate, and define controls to ensure they align with business objectives and mitigate risks efficiently.
Show less
Key Features
- Rationalization of Controls: Before defining controls, assess their relevance to business objectives, their effectiveness in risk management, and opportunities to simplify processes.
- Consolidation of Controls: Identify overlapping controls across regulatory frameworks to create a streamlined control framework, reducing redundancy and enhancing audit readiness.
- Defining Controls and Business Rules: Establish foundational business rules that guide future Governance, Risk, and Compliance (GRC) configurations, including control tests, risk assessments, and necessary documentation.
- Entity Based Access (EBA): This feature offers a granular approach to manage data access, allowing administrators to configure user access based on entity associations, ensuring security and compliance.
Key Outcomes
By effectively managing controls within the Compliance Workspace, organizations can expect to enhance risk management, improve IT performance, and ensure compliance with various regulations. The streamlined process not only optimizes control definitions but also establishes a solid framework for ongoing audits and assessments.
Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.
Rationalize your controls
- How does this control affect my business objective?
- Is this control actually preventing or detecting risk?
- Is there a different control you can place that better protects your business?
- Is there a control you can put in place that reduces process overhead and improves IT performance while also mitigating risk?
- Can a complicated control be replaced with a simpler more effective control?
Consolidate your controls
Define controls and business rules
- Identify controls and control owners
- Define control tests and expected results
- Establish test and control frequencies
- Identify risks: impact and likelihood
- Prepare attestations, assessments, questionnaires, and required evidence
- Compose likely use-cases (who needs to interact with or view the contents of the GRC system and for what purposes)
- Map authoritative sources to policies, to procedures, to controls, and to risks
Entity Based Access (EBA)
The Entity Based Access feature provides a framework for more granular approach to management of data access to objects associated with an entity. Administrators can grant access to an entity's related records by adding users or user groups, or by using entity user fields for entity-based access configuration. For more information, see Entity Based Access.
- Control
- Attestation
- Policy exception to control
Entity Based Access (EBA) rules
When entity based record access rules are enabled on the Entity Based Access Configuration Properties page, any newly created controls, control attestations, indicators, and indicator tasks associated with a configured entity will automatically inherit the entity-based access (EBA) value from that entity. Previously, users had to run bulk access updates to apply EBA restrictions whenever new objects were created.
For more information, see Entity based record access rules to secure new records.