...
...
...
outline | true |
---|
...
...
...
Program
...
Directives
Regulations - An authoritative source (e.g. ISO 27001, SOX, Fisma)
...
...
Policies - A business principle that guides operations
Contracts - A legal agreement between business parties
Clause - A portion of a Contract object
...
...
Objectives/Controls
Because both objectives and controls provide information on how to meet compliance requirements, the two objects can often be confused in ZenGRC. It is up to you to decide where you would like to draw the line between controls and objectives. Below, we offer our definitions of the two objects.
...
...
...
...
Threat Actors - Individuals or organizations who impose risk from an outsider, insider or partner position
Audits - Official inspections of an individual's or organization's controls and/or accounts, typically by independent bodies
Control Assessments - A conclusion of a control's effectiveness at a certain period of time, with regards to a specific selection of mapped objects
...
...
Requests - An audit task that requires a response, usually with evidence attached
Other ZenGRC Objects
...
People
...
...
...
Feature Definitions
System of Record
ZenGRC's system of record keeps track of your compliance posture and universe. Our easy-to-use interface allows you to customize attributes without development efforts and map many-to-many relationships between all of the objects that matter to your company.
Workflow
The workflow feature enables you to complete typical compliance related tasks such as document requests. Furthermore, because of their incredible flexibility, workflows can really be used to task manage any project or process within the scope of your business operations. Workflows can be set up with varying frequencies such as daily, weekly, monthly, quarterly, annually, and so. Workflows can be broken up into smaller sub categories based on task groups, and within task groups specific tasks/requests can be created and assigned to specific ZenGRC users. Objects can be mapped to task groups and each task can be assigned to a specific person. Please view our other video on workflows for an advanced tutorial.
Audit
Our Audit module allows for 3 use cases:
Reporting
1) Downloadable reports - .csv exports that you can use to pull any piece of information from your system-of-record
...