Citations are the individual records that represent the statement,
articles, and laws associated with an Authority Document. Controls state how
the organization will comply with the Citations that require evidence.
Citations can be created manually or through a .csv import. It is
recommended that the import be utilized for consistency and ease of entry.
To create a Citation manually:
- On the
CSM Desktop Client
or
CSM Browser Client
toolbar, select
.
- Select
ISMS Citation from the
Type drop-down list.
- From the toolbar, select
New.
- Provide a title and select an existing authority.
Authority ID field will
automatically populate.
- Provide the reference group and reference ID.
These values are determined by the strategy in your organization.
- For
Status, select one of the following options:
- Evidence Required
-
- Select the
Control Implemented
check box when at least one Control is
linked in the
Controls tab in the form
arrangement.
- Select the
Policy defined check box if the
Control has at least one associated linked Policy.
- In the
Justification section, select the
following:
- Legal Requirements
- Result of Risk Assessment
- Business Process
- Contract Requirement
- Use the
Controls tab to link Controls. Edit
the Control itself to link Policies.
- Evidence Not Required
- In the
Justification section, provide an
exclusion justification.
- (Optional) Provide a description.