Creating a Compliance Engagement (IT Controls Assurance)

The Compliance Engagement application allows users to manage their testing life cycle, auto scope records, and create multiple tests at once.

Here are the tasks to create a Compliance Engagement:

  1. Complete the General Information section.
  2. Complete the Engagement Milestones section.
  3. Complete the Summary tab.
  4. Click the Staffing tab.
  5. Complete the Resources section.
  6. Click the Scope tab.
  7. In the Scoping Method section, do 1 of the following:
    • Scope using specific compliance scope records.
    • Scope using specific control sets and compliance scope records covering those control sets.
    • Scope using specific control sets and control procedures covering those control sets.
  8. (Optional) Click Add New or Lookup to associate compliance scope records, business processes, primary controls, applications, devices, information assets, storage devices, and facilities as needed in the respective sections.
  9. Click the Testing tab.
  10. In the Test Generation section, do the following:
    1. Define the scope of the testing, Full or Partial.
    2. Select 1 or multiple control tests to create.
    3. (Optional) Define meta data to be populated in every assessment.
    4. Click Queued.
    5. Click Generate Tests.

  11. (Optional) Click Add New to associate control self assessments, design test results, operating test results, control 302 certifications, and operating effectiveness testing packages as needed in the respective sections.
  12. Click the Additional Testing tab.
  13. (Optional) In the Technical Control Manual Assessment section, do 1 or both of the following:
    • Select an existing technical control manual assessment record.
    • Create a new technical control manual assessment.
  14. Click the Wrap-Up tab.
  15. Complete the Engagement Summary field.

Download the source file of the diagram here: IT Controls Assurance Compliance Engagement Diagram

Swim lane diagram showing how to create a compliance engagement