Compliance Framework Data Management
Establish and organize the essential GRC database by populating custom issue types tailored for GRC processes. This foundational setup prepares your Jira environment for subsequent GRC operations, such as creating controls, testing them, and registering deficiencies.
Introducing Compliance Framework Issue Types
The plugin introduces new GRC-specific issue types to Jira to support your Governance, Risk, and Compliance processes:
Authority Documents: Foundational documents outlining specific guidelines, standards, or requirements.
Compliance Requirements: Specific mandates linked to Authority Documents.
Control Objectives: Goals describing the intent of a compliance action, linked to Compliance Requirements.
Control Templates: Actionable steps or templates fulfilling the Control Objectives. These are used as templates for automated Controls creation.
Control Assessment Templates: Questionnaires designed to standardize the assessment approach for controls that originate from the same Control Template. These questionnaires enable users to define varied assessment criteria in the form of questions, along with diverse answering options. Additionally, the questionnaires are equipped with a qualitative scoring model. This model aids in determining the overall assessment result, ensuring a comprehensive evaluation process.
GRC Hierarchy Navigation
The plugin establishes a clear hierarchy among the GRC issue types. This hierarchical design ensures users can trace the linkage from Authority Documents to the more specific Control Templates and Control Assessment Templates.
Compliance framework issue types lifecycle and workflow
These issue types are managed by users assigned to Compliance Officer’s role and follow a specific lifecycle, embodied in the workflow:
DRAFT: When a issue is first created, it begins in a DRAFT status. During this phase, the issue undergoes description and definition. Upon completion it is transitioned to REVIEW status.
REVIEW : A Compliance Officer reviews the issue in the REVIEW status. They can either:
Return the issue to DRAFT, seeking more details or clarity.
Activate the issue by transitioning it to ACTIVE status.
Deactivate the issue to by transitioning it to INACTIVE status.
Transitions user group membership checks:
All workflow transitions could be executed by members of Compliance Officer group only
Issue screens
For the compliance framework issue types, the Jira issue screens has been modified to show a list of associated child entities and provides the functionality to create and link new child entities.
Authority Document issue screen
View Linked Compliance Requirements: A section dedicated to displaying linked Compliance Requirements.
Add Compliance Requirements:
Click "Add Compliance Requirement".
Fill in the mandatory fields on the "Create Issue" screen.
The new Compliance Requirement will auto-link to the Authority Document and appear in the list.
Compliance Requirement issue screen
View Linked Control Objectives: A section dedicated to displaying linked Control Objectives.
Add Control Objective:
Click "Add Control Objective".
Fill in the mandatory fields on the "Create Issue" screen.
The new Control Objective will auto-link to the Compliance Requirement and appear in the list.
Control Objective issue screen
View Linked Control Templates: A section dedicated to displaying linked Control Templates.
Add Control Template:
Click "Add Control Template".
Fill in the mandatory fields on the "Create Issue" screen.
The new Control Template will auto-link to the Control Objective and appear in the list.
Control Template issue screen
View Linked Control Assessment Templates: A section dedicated to displaying linked Control Assessment Templates.
Add Control Assessment Template:
Click "Add Control Assessment Template".
Fill in the mandatory fields on the "Create Issue" screen.
The new Control Template will auto-link to the Control Control and appear in the list.
Follow the created issue link and design the assessment questionnaire.
Control Assessment Template issue screen
Design assessment questionnaire:
On the General Settings tab enable scoring functionality.
Select calculation method
Define assessment score transformation
On the Assessment Criteria tab:
Add criteria (questions)
Add groups of criteria
Configure answer types and options
Configure criteria mandatory settings
Clone criteria
Save criteria to Assessment Criteria Library