Example: Control Design Assessment (with
Validation)
The following process flow takes examples of control design assessment to provide a detailed overview of the assessment process. The process operates by means of statuses being issued by the users involved in the different process steps and follow-up tasks consequently being generated.
This process describes control design assessment with validation of the assessment and with validation of the remediation plan.
Step/Task |
Level |
Initial Status |
Pushbuttons |
Action / |
In the task Perform Control Design Assessment, the assessor of the control design enters a negative assessment result (rating) and creates an issue. |
Assessment |
Draft |
Report Issue Delete Assessment (inactive) Review |
When the user chooses Review and then saves, the status changes to Review. |
Issue |
Draft |
Create Remediation Plan (inactive) Delete Issue |
The issue status is automatically changed with the assessment status to Review. |
|
The person performing assessment validation receives the task Review Control Design Assessment. |
Assessment |
Review |
Report Issue Delete Assessment (inactive) Rework Validate |
When the user chooses Rework, the assessment is returned to the original assessor. New status: Rework When the user chooses Validate, issue remediation is triggered. New status: Validated. |
Issue |
Review |
Create Remediation Plan (inactive) Delete Issue Rework Validate |
When the user chooses Rework, the assessment is returned to the original assessor. New status: Rework When the user chooses Validate, issue remediation is triggered. New status: Validated. |
|
If the assessment needs to be reworked, the original assessor receives the task Review Control Design Assessment. |
Assessment |
Rework |
Report Issue Delete Assessment (inactive) Review |
When the user chooses Review and then saves, the status changes to Review. Consequently, a new review is performed (see previous step). |
Issue |
Rework |
Create Remediation Plan (inactive) Delete Issue |
The issue status is automatically changed with the assessment status to Review. |
|
After assessment validation, the person entered as the issue processor receives the task Start Issue Remediation. |
Assessment |
Validated |
All inactive |
|
Issue |
Validated |
Create Remediation Plan Delete Issue (inactive) Release for Processing |
Processing without remediation plan: Enter comment and choose Release for Processing, then save. New status: Open. Processing with remediation plan: Create remediation plan and choose Release for Processing, then save. New status: In process |
|
Remediation plan (only for remediation with issue) |
New |
Delete Remediation Plan |
After saving, status: Draft |
|
Processing without remediation plan: The processor entered for the issue receives the task Close Issue Without Remediation Plan. |
Assessment |
Validated |
All inactive |
|
Issue |
Open |
Create Remediation Plan (inactive) Delete Issue (inactive) Complete |
Where required, enter a comment, change the processor, and choose Complete. New status: Resolved |
|
Processing with remediation plan: The processor entered for the remediation plan receives the task Enter Details for Remediation Plan. |
Assessment |
Validated |
All inactive |
|
Issue |
In Process |
All inactive |
|
|
Remediation Plan |
Draft |
Delete Remediation Plan Review |
Change remediation plan and choose Review. New status: Review |
|
The person performing validation receives the task Review Remediation Plan Details. |
Assessment |
Validated |
All inactive |
|
Issue |
In Process |
All inactive |
|
|
Remediation Plan |
Review |
Delete Remediation Plan (inactive) Rework Validate |
When the user performing validation chooses Rework, the processor of the remediation plan receives the task Enter Details for Remediation Plan again (see previous step). New status: Rework When the user chooses Validate, processing of the remediation plan is triggered. New status: Open. |
|
After validation, the processor for the remediation plan receives the task Document Progress of Remediation Plan. |
Assessment |
Validated |
All inactive |
|
Issue |
Validated |
All inactive |
|
|
Remediation Plan |
Open |
Delete Remediation Plan (inactive) Complete |
Specify the percentage of completion. Where 100 % applies, choose Complete. New status: Closed. |
|
Valid for both remediation types: The person who reported the issue receives the task Reassess Control Design. |
Assessment |
Reassessment |
Report Issue Delete Assessment (inactive) Review |
If the reassessment delivers an unsatisfactory result, retain the negative rating, and report a new issue, or reopen the old issue (see below). In both cases, issue remediation is triggered again with the task Start Issue Remediation (see above). If the reassessment proves successful, choose Review. This triggers a new validation of the assessment with the task Review Control Design Assessment (see below). |
Issue |
Validated |
Create Remediation Plan (inactive) Delete Issue (inactive) Close Reopen |
When Reopen is chosen, new status: Submitted. Issue remediation is triggered again (see above). When Close is chosen, new status: Closed. |
|
Remediation plan (only for remediation with issue) |
Closed |
Delete Remediation Plan (inactive) |
|