The
Take
attestation at requirement level option enables administrators to perform
compliance attestation at a granular level for individual control requirements within a
control.
Before you begin
Role required: sn_compliance.admin, sn_compliance.manager, sn_compliance.user
Procedure
-
Navigate to .
-
Select the List icon.
-
Under Compliance library, select Controls.
-
Select the control that contains the control requirements you want to
attest.
-
In the Details tab, select Take Attestation
at Requirement Level.
The Attestation field will default
to GRC CR Attestation.
-
In the
Assign
Respondent field, specify the user or role responsible for
attestation (for example, System Administrator).
-
Select Attest.
-
Navigate to
the
Control requirements tab, and
select each control requirement.
Attestation tasks are generated for each control requirement under
Assessment Instances.
-
For each assessment instance, select Take
assessment.
-
Select
either
Yes (implemented) or No (not implemented).
- If yes, attach evidence and provide an explanation.
- If no, provide a reason in the Explain
field.
-
Select Submit.
-
Review the following information for any failed assessment.
- Generates an issue for that control requirement.
- Marks the parent control as non-compliant.
- Rolls up the same status to the entity and control objective level.