Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 23 Next »


Benefits


ZenGRC addresses hardships surrounding audits and enables compliance teams to efficiently manage and report the results. Utilizing the application for audits fulfills three main functions:

  1. Visibility into audit progress - How close is the team to completing audit-related assignments?

  2. Clarity on audit issues - What's broken? How can it be fixed, and what's the status?
  3. Exposure of compliance posture - How effective are my controls?

IMPORTANT

It is critical that your organization has already set up your compliance program framework in ZenGRC and has set it up in the Program Onboarding wizard prior to conducting an audit. This allows you to select controls in an audit that are important to your organization and then gather evidence to verify their effectiveness. For more information, contact us at support@reciprocitylabs.com.

Overview


The Audits module allows for the following activities:

  1. Import or create evidence requests - Easily import requests with personnel assignments who are to supply evidence of control effectiveness.
  2. Evidence collection - Managing a Document Request List (DRL) is an extensive project management endeavor for external audits. ZenGRC allows you to import a DRL from your auditor, so you can collect, verify/decline evidence, and escalate the request if no action is taken.
  3. Testing and concluding on the effectiveness of controls - Once evidence is submitted, it's straightforward to determine whether your controls are operating effectively.
  4. Issue management - Internal and external auditors often discover gaps, findings, and issues. ZenGRC allows you to set up workflows so you can remediate them and keep track of the process.
  5. Reporting - ZenGRC allows you to export all data surrounding the audit progress.
  6. Add or remove headings that better serve your organization's needs.



TIP

For additional information regarding ZenGRC audit structure and process flow, see ZenGRC Diagrams.

NOTE

To locate a draft audit, please see Finding Draft Audits

Different Audit Views


There are two different Audits page displays: the Audits visual display, and the Audits list view.

NOTE

The screenshot below illustrates the Audits visual display page.




NOTE

The screenshot below illustrates the Audits list view page. This is primarily for administrators.


Accessing Audits Visual Display


This Audits page provides a more visual representation of your audits, with graphs and metrics surrounding control effectiveness, returned requests, and the status of issues. All of your information is a click away with easy-to-understand visuals of an audit's progression.

To access the Audits visual display page, complete the following steps:

  1. Click Audits in the left-hand navigation.



  2. The Audits page displays with graphs and metrics.




NOTE

To locate a draft audit, please see Finding Draft Audits.

Accessing an Audit Summary Page


The Audit summary page displays after opening an individual audit. It looks similar to the display on the Audits home page with the exception that it has additional headings and is the only audit on the page.

To access the Audit summary page, complete the following steps:

  1. Scroll to the audit and click the name.

  2. Alternatively, click the arrow beside the All Audits dropdown and select the desired audit.



  3. The Audit summary page displays for the selected audit.

    NOTE

    Editing an audit can be done on the Audit summary page and is documented in Managing Audits.

Accessing the Audits List View Page


This Audits page list view enables you to perform multiple activities directly on the page without clicking into an individual item. All audits, whether they are active, complete, or draft, are displayed together and can be sorted by the user.

NOTE

This view is for administrators who may be managing multiple audits at once.




To access the list view of audits in the system, complete the following steps:

  1. Select System of Record | Audits (under the Audit Management heading) in the left-hand navigation.



  2. The Audits list view page displays with line items of all audits in the application.

    NOTE

    For general instructions on how to edit and manage audits directly from the list view, see Fundamentals of Navigating and Editing.

    NOTE

    Continue to the next section - Creating an Audit.



  • No labels