Strengthening control and monitoring in the Information Security module
K
Karla Valladares
- Relationship of residual risks with users
Currently, in the treatment of residual risk derived from the identification of risks, it is only possible to associate risks with charges.
It is proposed to enable the option of relating these risks directly to specific users, which would allow a more precise assignment of responsibilities.
- Tracking pending and notifications
Pending assigned within this module is required to have a tracking system similar to that of the Risks and Opportunities module, including:
*Automatic notifications to managers
*Clear view of pending tasks
*Action Plan Approval Flow
*Evaluation of the effectiveness, efficiency and effectiveness of the actions implemented
- Viewing observations in the risk sheet
When consulting the risk identification sheet, currently only the relationship with the point of the Applicability Declaration is shown (for example: “5.1 Information Security Policy”).
It is proposed to include the visualization of the follow-up observations associated with the applicable controls, so that the progress, status and management carried out on each control can be evidenced.
- Integration of impact factors with the risk matrix
It is necessary to enable the functionality to relate the impact factors directly to the risk matrix within this module, similar to how it is managed in the Risks and Opportunities module.
This would allow for a more comprehensive and aligned evaluation between both modules.