Creating and editing mitigating controls
To create or edit mitigating controls
-
In the Manager, select the Risk index functions > Mitigating controls category.
-
Select a mitigating control in the result list and run the Change main data task.
- OR -
Click in the result list.
-
Edit the mitigating control main data.
- Save the changes.
Enter the following main data of mitigating controls.
Table 9: General main data of a mitigating control
Measure |
Unique identifier for the mitigating control. |
Significance reduction |
When the mitigating control is implemented, this value is used to reduce the risk of denied attestation cases. Enter a number between 0 and 1. |
Description |
Detailed description of the mitigating control. |
Functional area |
Functional area in which the mitigating control may be applied. |
Department |
Department in which the mitigating control may be applied. |
Assigning mitigating controls to compliance rules
NOTE: This function is only available if the Compliance Rules Module is installed.
Use this task to specify for which compliance rules a mitigating control is valid. You can only assign original rules on the assignment form.
To assign compliance rules to mitigating controls
-
In the Manager, select the Risk index functions > Mitigating controls category.
-
Select the mitigating control in the result list.
-
Select the Assign rules task.
-
In the Add assignments pane, assign the compliance rules.
TIP: In the Remove assignments pane, you can remove assigned compliance rules.
To remove an assignment
- Save the changes.
Assigning mitigating controls to attestation policies
NOTE: This function is only available if the Attestation Module is installed.
Use this task to specify for which attestation policies the mitigating control is valid.
To assign attestation policies to mitigating controls
-
In the Manager, select the Risk index functions > Mitigating controls category.
-
Select the mitigating control in the result list.
-
Select the Assign attestation polices task.
Assign the attestation policies in Add assignments.
TIP: In Remove assignments, you can remove the assignment of attestation policies.
To remove an assignment
- Save the changes.
Assigning mitigating controls to company policies
NOTE: This function is only available if the Company Policies Module is installed.
Use this task to specify for which company policies the mitigating control is valid. You can only assign company policy working copies on the assignment form.
To assign company policies to mitigating controls
-
In the Manager, select the Risk index functions > Mitigating controls category.
-
Select the mitigating control in the result list.
-
Select the Assign company policies task.
In the Add assignments pane, assign company policies.
TIP: In the Remove assignments pane, you can remove company policies.
To remove an assignment
- Save the changes.