Working with Issues


Overview


Typically, controls that receive an “Ineffective” rating in an assessment will have a corresponding issue created. Issues can easily be created from any page in ZenGRC and connected to an audit. They are then managed in Audits to keep track of remediation plans for problems the audit uncovered.

Creating Issues


NOTE

This item's creation is standard across ZenGRC and is explained in Creating New Objects, which is located in our Fundamentals of Navigating and Editing documentation.

In addition to the steps that are common to creating any object, an issue has the ability to be linked to an audit, program and assessment, so it can be tracked in the audit.

To select an audit, program and assessment, complete the following steps:

  1. Click within one of the text boxes to display a dropdown menu.
  2. Select the applicable object.
  3. Alternatively, start typing in the text box to narrow results.



  4. Make the selections and click Save or Save & Add Another.



  5. Alternatively, click Cancel to close the window without creating the issue.

Filtering by Status


To filter the issues by status, complete the following steps:

  1. Click one of the percentages displaying an issue status.
    1. Identified - This shows issues created and identified.
    2. Assigned - This displays assigned issues. 
    3. Remediation in Progress - This displays issues currently being worked on.
    4. Resolved - This shows issues that have been researched and remediated.
    5. Ignored/Invalid - This displays issues that have been found to have no basis.

Accessing Issues from Audits


Administrators and those with additional permissions access issues from the Audits module.

To view and respond to a issue from the Audit summary page, complete the following steps:

  1. Click the Issues tab.

  2. Find the issue and click the link in the Title column.


Viewing Additional Details


When compliance items are opened from the To-Do List or Audits, the pages display a toggle button to show more or less information. If these objects are accessed by clicking System of Record in the left-hand navigation, they do not have this toggle.

TIP

The example shown below is for an assessment. The functionality is the same for assessments, requests, and tasks that are opened from the To-Do List or Audits.


To change how much information is displayed in an object, complete the following steps:

  1. Open the item.
  2. In the top, right corner, click Show less for a streamlined view of onlyAttachments and Comments tabs.



  3. Alternatively, if you need more details, click Show more to display all tabs and other fields.

Managing an Issue


You can open issues in several ways, with the main access points coming from Audits. 

  1. If the Attachments area is not already displaying, select that sub tab.

    TIP

    The Status button in the upper right differs in wording that depends on which step the issue is in during the remediation process.


  2. If evidence is required, drag files from your computer into the field under the Attachments sub tab.
  3. Alternatively, click click to browse to open a dialog box and select the files.
     


  4. To add hyperlinks to the issue, click Click here to attach links.



  5. Add the URL in the Link text box and the name in the Title text box.



  6. Click Add link.
  7. To complete the step, select one of the following in the Status dropdown:
    1. Identified
    2. Assigned
    3. Remediation in Progress
    4. Resolved
    5. Ignored/Invalid
  8. The page refreshes showing the issue's status.

Exporting Issues


Issues can be exported for external auditors or any other reviewers your organization may have. The export can be formatted as a CSV or as a zip file with the attachments inside.

NOTE

For instructions on exporting, please see Managing Audits.


© 2021 Copyright Reciprocity, Inc.
https://reciprocity.com