Compliance-supporting processes Flashcards
what are the benefits of compliance score calculation?
a nuanced result, key operational insights, and enables remediation
What is the default weight for all controls?
10
How is compliance score calculated?
weight of compliant controls divided by weight of all controls times 100
What actions trigger recalculation of compliance score?
reliant entities are added or removed, common control retired or converted to standard control, common control changes its compliance status or weighting
What is the policy acknowledgement campaign lifecycle?
New, Pending acknowledgement, Closed, Canceled
What are the enhancements to policy acknowledgement in March 2021 release?
frequency on policy record to autoschedule, acknowledgement tasks sent to new members added to audiences, due date can be extended for new members, and additional email notifications
When is the audience of a policy acknowledgement campaign identified?
after campaign set up
Who can set up a campaign, set schedule, and extend valid to date?
Policy owner, compliance user and above
Who can identify campaign audience and add users for ongoing campaign?
compliance manager and above
What happens when a policy acknowledgement campaign is pending acknowledgement?
instances are created for all users in the audience list, policy is presented on Employee Center with due date, and employee responses are captured
Policy acknowledgement audience can consist of….?
users, groups, newly defined user filter
What are the baseline options for a policy acknowledgement campaign audience receiving requests?
accept, decline, request exception
Who can cancel a policy acknowledgement campaign?
compliance manager or campaign owner
What happens when a campaign is overdue?
closed
What are the 5 configuration steps for a policy acknowledgement campaign?
Create audience, set up campaign, set properties, respond to requests, view responses and statuus
What is the path to create an audience for a policy acknowledgement campaign?
Policy and Compliance > Policy Acknowledgement > Audience
What is the path to set up a policy acknowledgement campaign?
Policy and Compliance > Policy and Procedures > Policies
What is the path to set properties of a policy acknowledgement campaign and what role is required?
Policy and Compliance > Administration > Properties. compliance admin
Where can Policy acknowledgement campaign audience members complete acknowledgement requests?
Now Platform or Service Portal
What is the path to view campaign responses and statuses and what role is required?
Policy and Compliance > Policy Acknowledgement > Overview. compliance reader
Policy table extends from the ________ table
Document
Acknowledgement campaign extends from the ______ table
Task
What is the compliance case workflow?
Report case, triage and investigate, resolve, post case review, close
Where can a user go to create a policy exception request?
Employee center, compliance workspace, policy exceptions module, control objective record, issue record
What roles are required to request a policy exception?
sn_grc.business_user or sn_grc.business_user_lite
A policy exception cannot be approved if the control objective ….?
is without controls or only has controls in draft or retired state
What are the Approval options for a policy exception?
Approve, reject, one-time extension
What is the associated flow for verification of a policy exception?
Generate initial approvals for policy exception
What is the associated flow for approval of a policy exception?
Generate final approvals for policy exception
What sets the substate to awaiting approvals if there are verification rules for an exception?
the Set Policy Exception Substate business rule
exceptions submitted via ___________ are based on a _________ and bypass the __________process
service portal or employee center, record producer, verification
What will the final approvals flow do when there is no approval rule?
run a script that obtains the impacted control owners and sets them as approvers
What is the policy exception record lifecycle?
New > Analyze > Review > Awaiting Approval > Approved > Closed