Issues Management Use Case Design

This topic explains the Issues Management use case design.

Architecture Diagrams

The following diagram shows the relationships between the applications in the Issues Management use case.

Download the source file of the diagram here: Issues Management Architecture Diagram

Issues Management - use case design relationship diagram

Note: Findings is linked to various applications and questionnaires. These applications and questionnaires can serve as the source of the Finding.

Applications

The following table describes the use case applications.

Applications/Questionnaires

Description

Findings Folder

The Findings Folder application allows you to group findings that all come from the same base issue or that a user wants to group.

Findings

The Findings application allows you to document issues, deficiencies, or gaps found through assessments and control testing. Findings are either auto-generated from questionnaires, including links back to the questionnaire, target, and any applicable control standards and authoritative sources, or are manually generated by users. Findings can be resolved through remediation tasks and/or exception requests.

Through the Findings application, you can:

  • Review findings that are auto-generated through the results of assessments and control testing.
  • Use automated workflow to route findings to the appropriate personnel.
  • Mitigate findings through remediation tasks and/or exception requests. The system calculates residual risk and compliance status based on the resolution of findings.
  • Relate multiple findings in the context of a remediation plan.
  • Track tasks associated with findings resolution.

Remediation Plans

The Remediation Plans application allows you to document the specific actions management plans to take to address identified gaps and issues. You can capture key details about remediation efforts, including estimated and actual costs, timelines, owners and detailed actions. You can associate multiple remediation plans with a single finding and track each effort individually. You can also relate a single remediation plan with multiple findings in the event that an action is designed to address multiple issues.

Exception Requests

The Exception Requests application allows you to manage the process of granting, denying, and expiring exceptions to the remediation required in a finding. Through built-in workflow, the application ensures that all exceptions are properly reviewed. The tool can also report on exceptions across the enterprise, monitoring them by control, department, or severity.

Through the Exception Requests application, you can:

  • Enable employees to submit exception requests through an easy-to-use web interface.
  • Allow designated individuals to evaluate exception requests and approve or deny the requests based on risk posed to the business.
  • Grant exceptions for a specific period of time and notify proper personnel as expiration dates approach.
  • Enable management to track granted exceptions, facilitating periodic reviews of exceptions and the exceptions’ impact.
  • Allow employees to track the status of their own policy exception requests through My Requests reports.
  • Understand the policies or standards with the most approved exceptions and use the information to support training and awareness programs.

Company

The Company application stores general, financial, and compliance information at the company level. Combined with the Division and Business Unit applications, this application supports roll-up reporting of governance, risk, and compliance initiatives across the enterprise.

Note: The Company application is included in the Enterprise Catalog package.

Division

The Division application represents the intermediate unit within the business hierarchy which is a layer below the high-level company and a layer above the individual business unit. You can use this application to further document the relationships within your business and measure the effectiveness and compliance of individual divisions within the enterprise.

Note: The Division application is included in the Enterprise Catalog package.

Business Unit

The Business Unit application provides a detailed view of all activities related to the specific business unit.

Note: The Business Unit application is included in the Enterprise Catalog package.

Change Requests

The Change Requests application allows users to recommend changes in Policies, Control Standards, Control Procedures, Process Narratives, Evidence Repository, Remediation Plan and allows extensions of Exception Request, based on reviews from threat assessments, regulatory news, and issues found during the Audit, Compliance and Risk Management process.

Access Roles

The following table describes the out-of-the-box use case access role.

Access Role

Description

Findings Handler

The Findings Handler role provides access to users in multiple handler groups who are responsible for verifying automatically generated findings

Access roles in other use cases provide additional permissions to Issues Management applications.

Dashboards

The following table describes the use case dashboard.

Dashboard

Description

Issues Management

This dashboard allows you to track findings, remediation plans, exception requests, and findings folders.