Entity Scoping Flashcards
How many Entity Types can an Entity belong to?
Zero, One, or Many
Entity + Risk Statement =
= Risk –> Assessment
Entity + Control Objective =
= Control –> Attestation
How do “dynamic capabilities” impact Entity Types
As new records meet filter criteria, new entities are created
As current records don’t meet filter criteria, they are deactivated (retired)
Scoping for Security
ISO 27001 NIST PCI DSS IFSMA NERC CIP
Scoping for IT Finacial
SOX
GDPR
BCBS (Basel)
Scoping for Healthcare
HIPPA
PCI DSS
Scoping for Insurance
NAIC
FINRA
SEC
PCI DSS
Operational Approach
Scoping at individual level
Strategic Approach
Figure out how to group
What precedes common tables?
cmn_
[cmn_department]
[cmn_location]
What precedes system tables?
sys_
What precedes core tables?
core_
[core_company]
Name of entity cleanup job
GRC Cleanup Invalid Entities
runs each night
Services Table
Server Table
Business Process Table
[cmdb_ci_service]
[cmdb_ci_server]
[cmdb_ci_business_process]
Entity Filter elements
table
filter condition
conditions
How is Entity Owner determined
“Entity owner” specified on filter
- references field with username NOT group name
- “empty owner” determines what happens if owner is blank (create, do not create, or use default)
What are the two reasons for using Entity Classes
- Risk roll-up (hierarchy)
- Reporting
Name of the Module for setting up Entity Classes
GRC Workbench - Dependency Model
entities are on the left, eligible upstream and downstream on the right
Document - Table Name and Scope
[sn_grc_document]
GRC: Profiles
Document- Extended Tables
Risk Framework (GRC: Risk Management) Authority Document (GRC: Policy & Compliance) Policy (GRC: Policy & Compliance)
Content - Table Name and Scope
[sn_grc_content]
GRC: Profiles
Content - Extended Tables
Risk Statement (GRC: Risk Management) Citations (GRC: Policy & Compliance) Control Objective (GRC: Policy & Compliance)
Item - Table Name and Scope
[sn_grc_item]
GRC: Profiles
Item - Extended Tables
Risk (GRC: Risk Management)
Control (GRC: Policy & Compliance)
Entity Type vs Entity Class
Entities can have multiple types but only one class
GRC: Profiles Common Tables
Task (global) --> Indicator Task Base Indicator [sn_grc_base_indicator] --> Indicator Planned Task (global) --> Issue Entity Type Entity Class Entity Entity Tier
Name for entity creation job
GRC Profile Generation
runs hourly) (updates entities too