Create Citations and Link to Controls
Citations are the individual records that represent the statement, articles, and laws associated with an Authority Document. Controls state how the organization will comply with the Citations that require evidence.
You can create Citations manually or through a .csv import. We recommend that you utilize the import for consistency and ease of entry.
To create a Citation manually:
- On the CSM Desktop Client or CSM Browser Client toolbar, select Tools > Table Management.
- Select GRC Citation from the Type drop-down list.
- From the toolbar, select New.
- Provide a title and select an existing authority.
The Authority ID field autopopulates.
- Provide the reference group and reference ID.
The strategy in your organization determines these values.
- For Status, select Evidence Required or Evidence Not Required and then choose or complete the appropriate options or complete the section.
Evidence Required Evidence Not Required
- The Control Implemented checkbox autofills when at least one Control is linked in the Controls tab in the form arrangement.
- The Policy defined checkbox autofills if the Control has at least one associated linked Policy.
In the Justification section, provide an exclusion justification. Justification section:
- Legal Requirement
- Result of Risk Assessment
- Business Process
- Contract Requirement
- Link Controls and edit the Control itself to link Policies.
- Provide a description and save the record.