on 2012 Jul 18 9:04 AM
i was just reading some GRC docs and stumbled upon a term "Mitigating Controls"
could any one please explain what is this..and whether they are assigned to users or risks.
As per my understanding it is a addition check applied upon a user whick does not allow him complete a transaction unless it is approved by a an approver // moniter.
please correct i am wrong.
rgds..........kk
Help others by sharing your knowledge.
AnswerRequest clarification before answering.
Hi Krishna,
Mitigation controls are created for the risk and user/role/profile can be assigned to it.
Approver and Monitor are also assigned to the Mitigation Control.
So when you run the User/Role/Profile based Risk Analysis then you can see the Mitigated risk with the Mitigation Monitor Details.
It says that there is someone who is monitoring this User/Role/Profile with this risk.
Regards,
Shaily
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.