How Ivanti Neurons for GRC Works
1 min
this is a high level overview of how you can use this software the steps and order vary depending on your organization's approach and requirements for risk and compliance management workflow after you apply the software package, import citations and controls you can manually create them, but we recommend you utilize the import for consistency and ease of entry you'll need citations and controls in the system before you can link them to authority documents create authority documents to link to citations and controls create questions and assign risk values, question impact, and question sequence to use the risk assessment form risk mitigation questions and threat analysis questions populate the risk assessment create policies to track related controls create risks to manage potential problems create mitigation plans to use with other business objects to ensure compliance with audits, risks, citations, and controls create exceptions to gain approval for non compliance with an audit or policy create a risk assessment to discover, correct, or prevent security problems create audits for scheduled review of compliance related to an industry standard such as iso 20071 2013 or key configuration items (infrastructure, supporting services, or collateral) auditors can request evidence to support audit findings manually create controls and citations and link citations to controls create attestations and control indicators for a control attestations assist you by documenting that a control has been implemented, how it has been implemented, and why control indicators help you to assure that a control is compliant, and demonstrate/ensure it is reviewed on a regular basis
