Issues Management Use Case Design
This topic explains the Issues Management use case design.
On this page
Architecture Diagrams
The following diagram shows the relationships between the applications in the Issues Management use case.
Download the source file of the diagram here: Issues Management Architecture Diagram
Note: Findings is linked to various applications and questionnaires. These applications and questionnaires can serve as the source of the Finding.
Applications
Applications/Questionnaires |
Description |
---|---|
Findings Folder |
The Findings Folder application allows you to group findings that all come from the same base issue or that a user wants to group. |
Findings |
The Findings application allows you to document issues, deficiencies, or gaps found through assessments and control testing. Findings are either auto-generated from questionnaires, including links back to the questionnaire, target, and any applicable control standards and authoritative sources, or are manually generated by users. Findings can be resolved through remediation tasks and/or exception requests. Through the Findings application, you can:
|
Remediation Plans |
The Remediation Plans application allows you to document the specific actions management plans to take to address identified gaps and issues. You can capture key details about remediation efforts, including estimated and actual costs, timelines, owners and detailed actions. You can associate multiple remediation plans with a single finding and track each effort individually. You can also relate a single remediation plan with multiple findings in the event that an action is designed to address multiple issues. |
Exception Requests |
The Exception Requests application allows you to manage the process of granting, denying, and expiring exceptions to the remediation required in a finding. Through built-in workflow, the application ensures that all exceptions are properly reviewed. The tool can also report on exceptions across the enterprise, monitoring them by control, department, or severity. Through the Exception Requests application, you can:
|
Company |
The Company application stores general, financial, and compliance information at the company level. Combined with the Division and Business Unit applications, this application supports roll-up reporting of governance, risk, and compliance initiatives across the enterprise. Note: The Company application is included in the Enterprise Catalog package. |
Division |
The Division application represents the intermediate unit within the business hierarchy which is a layer below the high-level company and a layer above the individual business unit. You can use this application to further document the relationships within your business and measure the effectiveness and compliance of individual divisions within the enterprise. Note: The Division application is included in the Enterprise Catalog package. |
Business Unit |
The Business Unit application provides a detailed view of all activities related to the specific business unit. Note: The Business Unit application is included in the Enterprise Catalog package. |
Change Requests |
The Change Requests application allows users to recommend changes in Policies, Control Standards, Control Procedures, Process Narratives, Evidence Repository, Remediation Plan and allows extensions of Exception Request, based on reviews from threat assessments, regulatory news, and issues found during the Audit, Compliance and Risk Management process. |
Access Roles
Access Role |
Description |
---|---|
Findings Handler |
The Findings Handler role provides access to users in multiple handler groups who are responsible for verifying automatically generated findings |
Access roles in other use cases provide additional permissions to Issues Management applications.
Dashboards
Dashboard |
Description |
---|---|
Issues Management |
This dashboard allows you to track findings, remediation plans, exception requests, and findings folders. |