Remediate an issue in Policy and Compliance Management
After an issue has been identified, triaged, and investigated, you can remediate it.
Before you begin
Role required: compliance_admin, compliance_manager, sn_compliance.user, sn_grc.business_user, sn_grc.business_user_lite
Note: Starting with Version 12.0.1, the minimum role for the Assigned to user on the Remediation task form is GRC Business User [sn_grc.business_user]. The minimum role for the sn_compliance.user is GRC User [sn_grc._user].
For more information on the access control limitations to remediation tasks, see GRC business user role to control access and track usage of compliance tables.
About this task
Remediating an issue marks an intention to fix the underlying issue causing the control failure or risk exposure. Accepting an issue marks an intention to create an exception for a known control failure or risk. Controls that are Accepted remain in a non-compliant state until the control is reassessed. In this way, the issue can be used to document observations during audits.
Procedure
Open the issue you want to remediate.
Select the Remediation Tasks tab.
Note: You have two options for creating a remediation task:
- Select Suggested Remediation Tasks and select Copy to use an existing task as a basis for creating this task. A copy of the selected remediation task is created with certain information from that task copied to the new task. You can manually complete the other fields.
- Selecting New and manually creating the task.
- On the form, fill in the fields.
| Field | Description |
|---|---|
| Number | Unique identification number. |
| Assigned to | Select the user responsible for working this task.You can configure a hierarchy of users to access the remediation task. For more information, see User hierarchy access control for issue and remediation task records. |
| Issue | The issue for which this task was created. |
| State | The current state of the task. |
| Priority | Select the priority or sequence this task needs to be resolved, based on its impact and urgency. |
| Watch list | Select users who want to be notified when changes occur. |
| Created/Updated | Displays the date/time when the task was created and updated. |
| Name | Brief description of the task. This will appear in lists of tasks. |
| Description | Enter a complete description of the task. |
| Notes and Comments | |
| Additional comments | As needed, enter any customer-facing comments related to this task. |
| Work notes | Enter any non-customer-facing notes related to the remediation of the issue. |
| Task Schedule | |
| Planned duration | Estimated amount of work time. Calculated using the Planned start date and Planned end date. |
| Planned start date | Date and time that work on the task is expected to begin. |
| Planned end date | Date and time that work on the task is expected to end. |
| Actual duration | Amount of actual work time. Calculated using the Actual start date and Actual end date. |
| Actual start date | Time when work began on this task. |
| Actual end date | Time when work on this task was completed. |
| Confidentiality | |
| Confidential | Option to enable confidentiality of the record. Only the assigned confidential users or confidential groups of users can access the record.For more information on confidential option, see Confidentiality flag for audit and compliance records. |
- Select Submit.
Parent Topic:Manage issues in Policy and Compliance Management