Accepting Management Controls
Not all controls defined in the central Management Controls Catalog are relevant for all organizational units or process groups. For this reason, an org unit owner or a process group owner can choose which individual management controls are relevant for that organizational unit or process group. When a management control is accepted as relevant, the assessment of the management control design automatically becomes necessary. By setting the appropriate indicator, you can specify whether the effectiveness of the management control should also be tested in addition to being assessed. It is not possible to create local management controls specific to an organizational unit or a process group.
The acceptance of a management control for a process group occurs independently of whether it is accepted for the superordinate organizational unit. This means that any of the management controls can be accepted for a process group and not just those accepted for the organizational unit to which the process group belongs.
Different tasks are delivered for the various settings, thereby allowing the tasks to be performed by different persons (see Tasks: Structure Setup Specific to Organizational Units).
· The organizational hierarchy has been defined, and the processes have been assigned to the organizational unit (see Accepting Processes ).
· The Management Control Catalog has been defined.
· You have authorization for the relevant task.
· The tasks for changing management control attributes are scheduled (see Task Scheduling).
...
1. Role Assignment
Once a person has been assigned during the assignment of roles to persons to the roles with the tasks Assign Management Controls to Organizational Unit (ASGN-MC2OU) and Assign Management Controls to Process Group (ASGN-MC2PG), these tasks can be accessed by that person in the navigation area.
2. Assignment of Management Controls
In the Web application Assignment of Management Controls, the person with the appropriate authorization can assign individual management controls or all management controls to an organizational unit or process group. For the acceptance of a process group, it is also possible to use the Assignment from Org Unit setting so that the system automatically accepts those management controls that are already assigned to the superordinate organizational unit. Moreover, it is possible to change the description of the management control that was entered centrally.
3. Change the attributes for assessment and test
Depending on how you have defined the roles, either the person who assigned the management controls or somebody else with the appropriate authorization can change the following centrally-specified attributes for assessing and testing the management control:
¡ Assessment description
¡ To Be Tested indicator
¡ Test description
The accepted management controls must be assessed and – if the To Be Tested indicator has been set – tested (see Management Control Assessment and Test).