cancel
Showing results for 
Search instead for 
Did you mean: 

Mitigation control workflow for AC10

Former Member
0 Kudos

We are configuring the Mitigation control workflow during the implementation of AC 10.

I would like to know whether its mandatory to have the workflow for Mitigation approver and monitor. As per the implementation team there is no requirement for them as this is not covered during the rampup. But I think this should be mandatory to have the mitigation approval worflow so all the mitigation risk should be approved before mitigating. Otherwise, security admin can mitigate any risk and complete the request.

Please advice.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi,

Even though they are not mandatory, It is always good to have Mitigation approver and monitor in the workflow, if you wish to mitigate the risks before they are assigned. However, in some situations, the roles will be assigned to the users without mitigting them (if they are only required for a few days).

If you don't maintain the mitigation approver and monitor in the workflow, they have to be managed manually from RAR.

Regards,

Raghu

Former Member
0 Kudos

Raghu, Thanks for the reply.

So it means if we do not have the approval workflow for mitigation control, than there is no importance for mitigation approver to be maintained. As there will be no workflow to send them the request for approval. Security team can mitigate any risk by creating mitigation controls.

Former Member
0 Kudos

Yes. But, as mentioned it is always a recommended approach to include them in the workflow There are pros and cons.. I bet this is an ongoing debate. Some feel its worthy enabling them in the workflow.. and some feel that it can be managed at a different level.

Best Regards,

Raghu

Former Member
0 Kudos

So if I find a risk while performing a risk analysis, how i can send the request to mitigating approver whether to mitigate the risk or not. As there is no workflow configured for mitigation approval.

I mean, as a security admin we want to mitigate any risk, but we want to get the approval from mitigating approver, do we need to send the risks separately via email and get the approval for mitigation.

Former Member
0 Kudos

Hi,

Yes. It will be a manual process. In some of the organizations, risks identification and mitigation will be performed manually by the Business process owners, which means in reality there will not be any risks that pop-up in CUP or RAR since they are already mitigated for the user.

If you don't want to enable the mitigation process in the workflow, you have to do it and record the evidences manually.

Hope this answers.

Regards,

Raghu