Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Overview


The Compliance Dashboard provides a snapshot of an organization's compliance posture.

There are several areas on the dashboard that provide detailed metrics around program and control statuses.

Accessing the Compliance Dashboard


To access the Compliance Dashboard, complete the following:

  1. Click Dashboard | Compliance Dashboard.



Anchor
programstatus
programstatus
Program Status


The Program Status table displays all programs in your organization's instance regardless of the their state. This alphabetical list provides audit readiness statuses for two phases in of a program's development.  
Image Removed

Program Status Phases

The two phases displayed in the Program Status table are as They are then defined as low, moderate and high icons display the same regardless of phase.

Audit Readiness Phases

The two phases displayed in the Program Status table are as follows:

  • Onboarding Phase - The program has no completed audits. 
  • Audit Phase - The program has at least one completed audit.

Note
titleIMPORTANT

Both phases display the same low, moderate or high icons. They are only differentiated by what is calculated and the text on mouse hover.

Hints on how to tell them apart are outlined in the next documentation sections.


Image Added

Understanding

Onboarding Phase Audit Readiness

Since If there is no completed audit, the program is still in the onboarding phase calculates . The Audit Readiness calculations are based on percentages of objectives with mapped controls. The message displayed on mouse hover Then the low, moderate and high rating is based on that and not control effectiveness.

Tip
titleTIP

On mouse hover, the onboarding phase text provides percentages of objectives with at least one mapped control.

 Then the low, moderate and high rating is based on that percentage

Control effectiveness is not considered.




Onboarding status definitions are as follows:

  • Low - No objectives are scoped or control mappings are less than 40 percent. 
  • Moderate Control mappings are equal or greater than 40 percent and less than 80 percent. 
  • High - Control mappings are equal or greater than 80 percent. 

Tip
titleTIP

The control percentages are only calculated on objectives scoped to the selected program. If control mappings don't follow the PSSOC mappings, those controls are excluded.

Understanding

Audit Phase Audit Readiness

If there is at least one completed audit, the audit phase calculates control effectiveness during the last audit of the selected program.

And the message displayed on mouse hover provides percentages of effective controls.



Audit phase status definitions only cover the last completed audit and are as follows:

  • Low - Over 80 percent of control assessments are deemed ineffective either by design or operation.
  • Moderate Over 30 percent and less than or equal to 80 percent are deemed ineffective either by design or operation.
  • High - Less than or equal to 30 percent of control assessments are deemed ineffective either by design or operation.
Tip
titleTIP

If an assessment is mapped to multiple objects, the only assessment used for calculations is the one mapped to a control used in the last completed audit.

High Risk Entities

The High Risk Entities table reports

High Risk Entities


The High Risk Entities shows the top three object types associated with high risk scores, which then provides an organization with risk mitigation focus.

Image Modified

Understanding High Risk Entities


The High Risk Entities table displays three objects with the greatest number of high risk items. Only the following are included in this table's calculationThe numbers in the High Rick Entities graphic are calculated as follows:

  • The entity must be one of the following objectsa:

    • Contract
    • Control
    • Org Group
    • Data Asset
    • Process
    • Objective
    • Product
    • Program
    • Threat
    • Policy
    • Issue
    • Market
  • The entity must have at least one high risk status.

  • The top three entities (or objects) with the most high risk items are displayed with their counts from left to right. 

Issues


The Issues table of the Compliance Dashboard displays the top five outstanding issues in ZenGRC. These issues should then be your compliance team's focus for the next time period.

Image Modified

Understanding the Issues Table

The Issues table displays columns with the following criteria:

  • Top 5 issues - This column pulls all issues in the ZenGRC application, regardless of mappings, that are set to one of the following statuses (other statuses are ignored):
    • Identified.
    • Assigned.
    • Remediation in progress.
  • Associated Entities - This displays all objects mapped to the displayed issue.
  • Age - This is the number of days shown in red since each issue was created. The oldest issues display first.

Future Gap Analysis


The Future Gap Analysis table provides an estimated level of effort for achieving compliance with a new framework. The estimate is based on overlapping frameworks in your ZenGRC System of Record.

The table only pulls programs still in a Draft status.

Understanding the Future Gap Analysis Table

The Future Gap Analysis table displays columns with the following criteria:

  • Program - These are draft programs with at least one mapped objective.
  • Objectives not met - This is the number of objectives in the draft program not scoped to other finalized programs. These objectives still need attention.
  • Objectives potentially met - This is the number of objectives in the draft program that could be potentially met by objectives in a related finalized program.
  • Estimated coverage - Estimate of objective overlap between the finalized and draft programs to show effort in finalizing the draft program.

Risk Heatmap


The Risk Heatmap table is a scaled-down report on risks the organization faces along with their likelihood and impact. This provides risk severity and how soon action is necessary.

Click a cube on the grid to open the Risk Heatmap module.

Info
titleNOTE

For additional information, please see Risk Heatmap.


program is in the Onboarding or Audit phase.
Info
titleNOTE
For information on the the Onboarding or Audit phase in the Program Status table, please see Program Status

Individual Program Status

Clicking a program in the Program Status table displays metrics regarding the selected program's control efficiency. Metrics differ if the 

Program Status


Clicking a program in the Program Status table displays metrics regarding the selected program's control efficiency.

Note
titleIMPORTANT

If no audit has been performed on the selected program, the table pulls ratings for controls that are mapped to other programs with completed audits.

Accessing Program Metrics

To access individual program metrics, complete the following:

  1. From the Compliance Dashboard, click a linked program in the Program Status table.
  2. The metrics for the selected program display.


Control Health

The following describes how the metrics in the sections describe how Control Health graphic  metrics are obtained.

Control Count

and % Control Effectiveness

Image Removed
The effective and ineffective control numbers on the left side of the graphic are calculated as follows:

  • Only controls mapped in the PSSOC hierarchy are counted.
  • The numbers are based on latest assessments in the most recent, completed audit.
  • If the program hasn't undergone an a completed audit, metrics are pulled from completed audits for other programs that share the selected program's control mappingscontrols

% Control Effectiveness

The % control effectiveness graph in  in the middle displays colors and percentages as follows:

  • Red - 0 percent to 60 percent assessed controls are rated effective.
  • Orange - 61 percent-80 percent assessed controls are effective.
  • Green - 81 percent and above assessed controls are effective.Image Removed
Click on Effectiveness metrics or on the round percentage: take the user to the SoR listing for controls
  • filters applied: map:program
  • workaround for now: old SOR, go to program page, controls tab

    Audit Readiness

    The audit readiness rating differs depending on whether or not the program has a completed audit. This is broken down into two phases, which are the Onboarding and Audit phases.

    Info
    titleNOTE

    For information on the the Onboarding or Audit phase in the Program Status table, please see Program Status.


    Image Added

    Section Status

    all the sections for this program with metrics about mapped objectives and controls count and highlighted with colors based on control effectiveness

    • display all sections mapped up the hierarchy (to the standard and program)
    • Show objective and controlcountcontrol count
      • Objective count: all objectives mapped to the section
      • Control count: cumulative sum of all controls mapped to each objective (per section)
    • Objective count: objectives mapped to the section, standard, and program (all the way up in the hierarchy)
    • Display frame around each section color:
      • Green: more than 80 percent of the objectives have at least one control mapped
      • Orange: between 50 percent and 80 percent of the objectives have t least one control mapped
      • Red: let than 50 percent of the objectives have at least one control mapped
    • Hover on the "badge" same as in US#4 (see above)
    • on click take to the SoR objective list:
      • filter is applied: map:program
      • filter is applied: map:section
      • visible column selected: map:control
      • workaround for now: old SOR, go to program page, controls tab

    High Risk Entities

    the top 3 highest risk entities for a specific program.

    • display top three high risk entities mapped to objects that are mapped to specific program

    Top Five Issues

    the top five outstanding issues regarding a specific program

    • up to 5 non truncated titles and descriptions for issues mapped to this specific program

    Risk Matrix

    The Risk Matrix displays risks for the selected program along with the likelihood and impact. This narrows the focus of your risk management action to a single program.

    • display a scaled down risk heat map here (/risk_heatmap) only with risks mapped to this specific program
      • filter risk heat map for that specific program if on a single program view
    • clicking on the scaled down risk heat map takes me to the risk heat map page
      • select the box I clicked on
      • if a program is selected keep the same program filter