The Take attestation at requirement level option enables administrators to perform compliance attestation at a granular level for individual control requirements within a control.
Before you begin
Role required: sn_compliance.admin, sn_compliance.manager, sn_compliance.user
Procedure
-
Navigate to .
-
Select the List icon.
-
Under Compliance library, select Controls.
-
Select the control that contains the control requirements you want to attest.
-
In the Details tab, select Take Attestation at Requirement Level.
-
The Attestation field will default to GRC CR Attestation.
-
In the Assign Respondent field, specify the user or role responsible for attestation (for example, System Administrator).
-
Select Attest.
-
Navigate to Control requirements tab, and select each control requirement.
Attestation tasks are generated for each control requirement under Assessment Instances.
-
For each assessment instance, select Take assessment.
-
Select Yes (implemented) or No (not implemented).
-
If Yes, attach evidence and provide an explanation.
-
If No, provide a reason in the Explain field.
-
Select Submit.
:
-
Review the following information for any failed assessment.
- Generates an issue for that control requirement.
- Marks the parent control as non-compliant.
- Rolls up the same status to the entity and control objective level.