263
IBM OpenPages GRC Platform Version 7.2.0 User Guide IBM

IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

  • Upload
    others

  • View
    10

  • Download
    0

Embed Size (px)

Citation preview

Page 1: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

IBM OpenPages GRC PlatformVersion 7.2.0

User Guide

IBM

Page 2: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

NoteBefore using this information and the product it supports, read the information in “Notices” on page 241.

Product Information

This document applies to IBM OpenPages GRC Platform Version 7.2.0 and may also apply to subsequent releases.

Licensed Materials - Property of IBM Corporation.

© Copyright IBM Corporation, 2003, 2016.

US Government Users Restricted Rights – Use, duplication or disclosure restricted by GSA ADP Schedule Contractwith IBM Corp.

Page 3: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Contents

Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xi

Chapter 1. What's new? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1New features in version 7.2.0.2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1New features in version 7.2.0.1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1New features in version 7.2.0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1Changed features in version 7.2.0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3New features in version 7.1.0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3

Chapter 2. Getting started . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Logging in to OpenPages GRC Platform . . . . . . . . . . . . . . . . . . . . . . . . . . 5Logging out . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Navigating the Grid View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Frequently Asked Questions - Home Page . . . . . . . . . . . . . . . . . . . . . . . . . 7Using the Home Page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8Personalizing the My Work tab . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8Attachments: browse, files, links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9

Chapter 3. Managing your settings. . . . . . . . . . . . . . . . . . . . . . . . 11My Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11

Changing your password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11Changing your locale setting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11

Chapter 4. Adding object instances, links, and associations. . . . . . . . . . . . . 13New object instances . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13

Adding an object instance with the Add New wizard . . . . . . . . . . . . . . . . . . . . 14Adding folders . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16External URL links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16

Adding an external link to a folder . . . . . . . . . . . . . . . . . . . . . . . . . . 17Attaching an external link to an object . . . . . . . . . . . . . . . . . . . . . . . . . 17

Associations between objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18

Chapter 5. Editing items . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19Applying changes to multiple objects with bulk update . . . . . . . . . . . . . . . . . . . . 19Editing objects in a grid or filtered list view . . . . . . . . . . . . . . . . . . . . . . . . 19Editing objects in detail view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20Editing folder descriptions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20Editing file descriptions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20Navigating to an object's detail page . . . . . . . . . . . . . . . . . . . . . . . . . . . 21Unlocking objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21Copying objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21Refresh information on a page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22Using the calendar . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22

Chapter 6. Searching for objects . . . . . . . . . . . . . . . . . . . . . . . . 23Searching for objects using global search . . . . . . . . . . . . . . . . . . . . . . . . . 23Comparing Global Search to Basic and Advanced Filters . . . . . . . . . . . . . . . . . . . . 23Advanced search techniques . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24

Chapter 7. Filtering information . . . . . . . . . . . . . . . . . . . . . . . . . 25About filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25View filters in the Analytics bar . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26

Showing or hiding the Analytics bar . . . . . . . . . . . . . . . . . . . . . . . . . . 26

iii

Page 4: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Showing or hiding filters in the Analytics bar . . . . . . . . . . . . . . . . . . . . . . . 27Changing the order of filters in the Analytics bar . . . . . . . . . . . . . . . . . . . . . . 27

Setting a default filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27Creating advanced filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28Running saved filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29Editing saved filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29Deleting saved filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29Copying filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30Renaming filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30Hiding the Advanced filter panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30Export data from filter results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31Clearing filter results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31Sorting data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31

Chapter 8. Viewing information . . . . . . . . . . . . . . . . . . . . . . . . . 33Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33Controlling the column display on a Grid or Filter View . . . . . . . . . . . . . . . . . . . . 34Reordering columns . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35Viewing the change history of objects. . . . . . . . . . . . . . . . . . . . . . . . . . . 35Viewing and comparing marked-up changes to text . . . . . . . . . . . . . . . . . . . . . . 36Viewing locks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36Viewing signatures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37Viewing reports in a different format . . . . . . . . . . . . . . . . . . . . . . . . . . . 37Viewing files or links from the detail page . . . . . . . . . . . . . . . . . . . . . . . . . 37Viewing lifecycle information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37Printing Detail View information . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38

Chapter 9. Managing my work. . . . . . . . . . . . . . . . . . . . . . . . . . 41Viewing summary object information on info cards . . . . . . . . . . . . . . . . . . . . . . 41Generating and viewing reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41Activity View page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41Completing action items . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41Reassigning tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42Completing tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42Signing off on tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42Selecting reporting periods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43Reassigning primary parents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43Refreshing information on a page . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44Revoking signatures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44Using jobs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44Setting preferences for alert notifications. . . . . . . . . . . . . . . . . . . . . . . . . . 45Submit jobs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45

Submitting Jobs from a Filter List View or Grid View . . . . . . . . . . . . . . . . . . . . 45Submitting Jobs from a Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . 46Submitting Jobs from a Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . 46

Terminating jobs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46

Chapter 10. Editing objects . . . . . . . . . . . . . . . . . . . . . . . . . . . 47Downloading files for edit . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47Copying objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47Editing objects in Grid or Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . 47Copying file links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48Deleting objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48Associating objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49Disassociating objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49Moving objects to a different folder . . . . . . . . . . . . . . . . . . . . . . . . . . . 50Locking objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50Adding a child object from a detail page . . . . . . . . . . . . . . . . . . . . . . . . . 51Rename an object . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52

iv IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 5: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Renaming an Object From an Object Detail Page . . . . . . . . . . . . . . . . . . . . . . 52Renaming an Object or Folder From a Folder View Page . . . . . . . . . . . . . . . . . . . 53

Chapter 11. Working with objects . . . . . . . . . . . . . . . . . . . . . . . . 55Business entities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55

Business entities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55Business Entities Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55Business Entities Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56Business Entities Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56Adding a parent object from the Grid View. . . . . . . . . . . . . . . . . . . . . . . . 57List Views . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58Unlocking all objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58

Risk assessments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59Risk assessments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59Risk Assessments Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59Risk Assessments Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60Risk Assessments Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60

Risk assessment evals (evaluations) . . . . . . . . . . . . . . . . . . . . . . . . . . . 61Risk assessment evals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61Risk Assessment Eval (Evaluation) Detail View . . . . . . . . . . . . . . . . . . . . . . 61Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61

Control objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62Control objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62Control Objectives Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63Control Objective Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63

Processes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64Processes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64Processes Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65Processes Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65Processes Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66

Process evals (evaluations) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66Process evals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67Process Evals (Evaluations) Folder View . . . . . . . . . . . . . . . . . . . . . . . . . 67Process Evals (Evaluations) Detail View . . . . . . . . . . . . . . . . . . . . . . . . . 68

Sub-Processes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68Sub-Processes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68Sub-Processes Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69Sub-Processes Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69

Controls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 70Controls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 70Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 70Controls Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71Controls Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71

Control Evals (Evaluations) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72Control evals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72Control Evals (Evaluation) Folder View . . . . . . . . . . . . . . . . . . . . . . . . . 73Control Evals (Evaluation) Detail View . . . . . . . . . . . . . . . . . . . . . . . . . 73

Risks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74Risks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74Risks Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75Risk Detail View. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75

Risk evals (evaluations) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76Risk evals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76

Contents v

Page 6: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76Risk Evals (Evaluations) Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . 76Risk Evals (Evaluation) Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . 77

Test plans and test results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78Test plans . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78Test Results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78Test Plans or Test Results Folder View . . . . . . . . . . . . . . . . . . . . . . . . . 79Test Plan or Test Results Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . 79

Issues and Issue Action Items . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80Issue and action items . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80Adding comments to an action item . . . . . . . . . . . . . . . . . . . . . . . . . . 80Completing action items . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 81Issues and Action Items Folder Views . . . . . . . . . . . . . . . . . . . . . . . . . 81Issues and Action Items Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . 82

Preferences groups and preferences . . . . . . . . . . . . . . . . . . . . . . . . . . . 82Preferences and preferences groups . . . . . . . . . . . . . . . . . . . . . . . . . . 82Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83Preference Groups and Preferences Folder View . . . . . . . . . . . . . . . . . . . . . . 83Preference Groups and Preferences Detail View . . . . . . . . . . . . . . . . . . . . . . 84

Files, forms, and links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84Browse attachments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84Adding or attaching files from the detail page . . . . . . . . . . . . . . . . . . . . . . . 85Adding files from the Folder View or Browse Attachments option . . . . . . . . . . . . . . . . 85Attachments: browse, files, links . . . . . . . . . . . . . . . . . . . . . . . . . . . 86File check in and check out . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 86Forms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87Adding a form . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87Adding files to tasks or jobs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87Copying a View File link . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87Checking out a file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88Checking in a file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88Canceling a file checkout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88Using files, forms, and links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88Adding URL links to object views . . . . . . . . . . . . . . . . . . . . . . . . . . . 89Add a link to a task or a job. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89Uploading a new version of a file . . . . . . . . . . . . . . . . . . . . . . . . . . . 90Adding a form . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90

Signatures and locks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91Signatures and locks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91Signatures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91Adding a signature . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93

Jobs and tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93Jobs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93Using jobs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93Viewing and monitoring jobs . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94Tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94Adding a link to a task or job . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94Disassociate a file or object from a task or job . . . . . . . . . . . . . . . . . . . . . . 95

Milestones and milestone action items . . . . . . . . . . . . . . . . . . . . . . . . . . 95Milestones and Milestone Action Items . . . . . . . . . . . . . . . . . . . . . . . . . 95Adding milestones . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96My Milestone Action Items . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96Milestones Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96Milestones and Milestones Action Item Detail View . . . . . . . . . . . . . . . . . . . . . 97Milestones and Milestone Action Items List View. . . . . . . . . . . . . . . . . . . . . . 98

Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 98Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 98Reports - Frequently Asked Questions . . . . . . . . . . . . . . . . . . . . . . . . . 99

vi IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 7: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Generating and viewing reports . . . . . . . . . . . . . . . . . . . . . . . . . . . 99Emailing a report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99Viewing reports in a different format . . . . . . . . . . . . . . . . . . . . . . . . . . 99

Questionnaires . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99Questionnaires, sections, questions . . . . . . . . . . . . . . . . . . . . . . . . . . 99Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100Questionnaires Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100Questionnaires Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101

Questionnaire Templates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101Questionnaire templates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101Questionnaire Template Folder View . . . . . . . . . . . . . . . . . . . . . . . . . 102Questionnaire Template Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . 102Defining a questionnaire template . . . . . . . . . . . . . . . . . . . . . . . . . . 103

Questionnaire Assessments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107Questionnaire assessments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107Questionnaire Assessment Folder View . . . . . . . . . . . . . . . . . . . . . . . . . 108Questionnaire Assessment Detail View . . . . . . . . . . . . . . . . . . . . . . . . . 108Completing a questionnaire assessment. . . . . . . . . . . . . . . . . . . . . . . . . 109Reviewing a questionnaire assessment . . . . . . . . . . . . . . . . . . . . . . . . . 111Updating a questionnaire assessment's lifecycle assignee . . . . . . . . . . . . . . . . . . . 112

Responding to an approval app notification . . . . . . . . . . . . . . . . . . . . . . . . 113Programs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114

Programs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114Program Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 115Program Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 115Launching a program. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 116Updating and relaunching a program . . . . . . . . . . . . . . . . . . . . . . . . . 117

Capital Modeling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117Capital modeling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117Capital Modeling Folder view . . . . . . . . . . . . . . . . . . . . . . . . . . . . 118Capital Modeling Detail view . . . . . . . . . . . . . . . . . . . . . . . . . . . . 118

Model Results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 119Filtered List View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 119Model Results Folder View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 120Model Results Detail View . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 120

Chapter 12. Reference information . . . . . . . . . . . . . . . . . . . . . . . 123Automatic timeout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123Browse attachments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123Change history . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123File check in and check out. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124Using files, forms, and links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125Forms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125Notifications. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125Primary parent association . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126Rules for naming folders, objects, and files . . . . . . . . . . . . . . . . . . . . . . . . 126View pages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127Menu bar. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 128Lifecycles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 128Questionnaire assessments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 128

Questionnaire template scores and scoring methods . . . . . . . . . . . . . . . . . . . . 129Questionnaire template scoring formulas . . . . . . . . . . . . . . . . . . . . . . . . 130

Chapter 13. Using OpenPages Internal Audit Management objects . . . . . . . . . 133Getting started . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133

OpenPages Internal Audit Management (IAM) . . . . . . . . . . . . . . . . . . . . . . 133

Contents vii

Page 8: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Working with OpenPages internal audit management objects . . . . . . . . . . . . . . . . . . 133Audits. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133Auditable entities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 135Audit sections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136Plans . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138Workpapers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139Findings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 141Auditors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 142Audit review comments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 143

Chapter 14. Using OpenPages IT Governance objects . . . . . . . . . . . . . . . 145Getting Started . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145

OpenPages IT Governance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145IBM OpenPages IT Governance terms you should know . . . . . . . . . . . . . . . . . . 145

Working with IT Governance Objects . . . . . . . . . . . . . . . . . . . . . . . . . . 146Mandates. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146Sub-Mandates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150Control Plans . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 152Baselines . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154Resources and Resource Links . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156Incidents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 158Key Risk Indicators (KRI) and Values . . . . . . . . . . . . . . . . . . . . . . . . . 160Key Performance Indicators (KPI) and Values . . . . . . . . . . . . . . . . . . . . . . 162Waivers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 164Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168

Chapter 15. Using Operational Risk Management objects . . . . . . . . . . . . . 171Getting started . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171

OpenPages Operational Risk Management. . . . . . . . . . . . . . . . . . . . . . . . 171Working with Operational Risk Management objects . . . . . . . . . . . . . . . . . . . . . 172

Key Risk Indicators (KRI) and Values . . . . . . . . . . . . . . . . . . . . . . . . . 172Key Performance Indicators (KPI) and Values . . . . . . . . . . . . . . . . . . . . . . 174Loss events . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176Loss impacts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178Loss recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180Scenario analyses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181Scenario results. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183FIRST losses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 185ORIC losses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 187ORX losses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 189Cost centers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 191

Chapter 16. Using OpenPages Policy and Compliance Management objects . . . . . 195Getting started . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 195

OpenPages Policy and Compliance Management . . . . . . . . . . . . . . . . . . . . . 195IBM OpenPages Policy and Compliance Management terms you should know . . . . . . . . . . . 196

Working with Policy and Compliance Management objects . . . . . . . . . . . . . . . . . . . 196Regulation applicabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 196Mandates. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198Sub-Mandates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201Key Risk Indicators (KRI) and Values . . . . . . . . . . . . . . . . . . . . . . . . . 203Incidents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 205Waivers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207Key Performance Indicators (KPI) and Values . . . . . . . . . . . . . . . . . . . . . . 209Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211Policy review comments. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215

viii IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 9: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Campaigns . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 216Employees . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 218Attestations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220Regulators . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222Regulator Interactions, RI categories, RI requests . . . . . . . . . . . . . . . . . . . . . 223Regulatory changes and regulatory tasks . . . . . . . . . . . . . . . . . . . . . . . . 226

Chapter 17. Using OpenPages Financial Controls Management objects . . . . . . . 229IBM OpenPages Financial Controls Management . . . . . . . . . . . . . . . . . . . . . . 229Working with OpenPages Financial Controls Management objects . . . . . . . . . . . . . . . . . 229

Accounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229Sub-Accounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 231Assertion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 233

Chapter 18. Using OpenPages Regulatory Compliance Management objects . . . . . 235Getting started . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235

OpenPages Regulatory Compliance Management . . . . . . . . . . . . . . . . . . . . . 235Working with Regulatory Compliance Management objects . . . . . . . . . . . . . . . . . . . 235

OpenPages Regulatory Compliance Management Objects. . . . . . . . . . . . . . . . . . . 235

Chapter 19. Using OpenPages Model Risk Governance objects . . . . . . . . . . . 237Getting started . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237

OpenPages Model Risk Governance . . . . . . . . . . . . . . . . . . . . . . . . . . 237Working with Model Risk Governance objects . . . . . . . . . . . . . . . . . . . . . . . 237

OpenPages Model Risk Solution Objects . . . . . . . . . . . . . . . . . . . . . . . . 237

Notices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241

Glossary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 245

Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 247

Contents ix

Page 10: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

x IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 11: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Introduction

This information is intended for use with IBM® OpenPages® GRC Platform. Thecontent contains instructions for using OpenPages GRC Platform. It is intended forusers who want to understand and use the objects.

Audience

The IBM OpenPages GRC Platform User Guide is intended for use with OpenPagesGRC Platform. The content contains instructions for using the OpenPages GRCPlatform application.

Finding information

To find product documentation on the web, including all translateddocumentation, access IBM Knowledge Center (http://www.ibm.com/support/knowledgecenter).

Accessibility features

Accessibility features help users who have a physical disability, such as restrictedmobility or limited vision, to use information technology products. OpenPagesGRC Platform documentation has accessibility features. PDF documents aresupplemental and include no added accessibility features.

Forward-looking statements

This documentation describes the current functionality of the product. Referencesto items that are not currently available may be included. No implication of anyfuture availability should be inferred. Any such references are not a commitment,promise, or legal obligation to deliver any material, code, or functionality. Thedevelopment, release, and timing of features or functionality remain at the solediscretion of IBM.

xi

Page 12: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

xii IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 13: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 1. What's new?

New and changed features are available for IBM OpenPages GRC Platform.

For information about all new features for this release, see the IBM OpenPages GRCPlatform New Features Guide.

New features in version 7.2.0.2The new features in IBM OpenPages GRC Platform are described in the followingsections.

Business Entity Selector

You can use the new Business Entity Selector display type in IBM OpenPages LossEvent Entry and in most OpenPages views. This display type enables users toquickly identify the role a business entity plays.

For more information, see “Configuring the Business Entity Selector display typefor simple string fields” in the IBM OpenPages GRC Platform Administrator's Guide.

New features in version 7.2.0.1The new features in IBM OpenPages GRC Platform version 7.2.0.1 are described inthe following section.

The approval app

A casual or infrequent user of OpenPages can now use the approval app to makewell-informed decisions for GRC tasks guided by information from the systemquickly and easily, without the need for extensive training in OpenPages.

Upon email notification telling you what you are being asked to do, just click onthe hyperlink in the email and you are brought to a page in the approval app thatincludes all the relevant information and provides you with an opportunity to takethe requested action.

For more information, see “Responding to an approval app notification” on page113.

New features in version 7.2.0The new features in IBM OpenPages GRC Platform are described in the followingsections.

IBM OpenPages Regulatory Compliance Management

The new IBM OpenPages Regulatory Compliance Management solution supportsorganizations in breaking down regulations into a catalog of requirements,evaluating its impact on the business, and creating actionable tasks. For moreinformation, see “OpenPages Regulatory Compliance Management” on page 235.

1

Page 14: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

IBM OpenPages Model Risk Governance

The new IBM OpenPages Model Risk Governance solution supports firms inorganizing and centralizing their model inventory. For more information, see“OpenPages Model Risk Governance” on page 237.

Questionnaire assessments

You can use the new questionnaire assessments to assess risk and compliance or tocollect information for specific processes and asset risks. The new capabilitystreamlines, standardizes, and centralizes the collection of questionnaire-basedassessment information. The following objects are new:v Programsv Questionnaire templatesv Questionnaire assessments

For more information, see:v “Questionnaire assessments” on page 128v “Lifecycles” on page 128v “Defining a questionnaire template” on page 103v “Launching a program” on page 116v “Completing a questionnaire assessment” on page 109

Lifecycles

Lifecycles offer new capability to customize and control processes that objectsfollow. Lifecycles work with questionnaire assessments and incidents but can beextended to other objects. Lifecycles define the stages that an object type follows.For more information, see “Lifecycles” on page 128 and “Viewing lifecycleinformation” on page 37.

Lifecycle on incidents

The introduction of lifecycles on Incident objects supports firms in streamliningand standardizing how incidents are reviewed and investigated. For moreinformation, see “Lifecycles” on page 128.

Global search component

Using IBM OpenPages GRC Platform global search, you can search on objectsacross the entire application for content you are looking for. For more information,see “Searching for objects using global search” on page 23.

Analytics bar

When you are using the Filtered List View or Grid View, you can now view filtersin the Analytics bar. For more information, see “View filters in the Analytics bar”on page 26.

Enhancements to Add New wizard, filters, and views

Numerous enhancements were made to the Add New wizard, filters, and views.For more information, see the IBM OpenPages GRC Platform New Features Guide.

2 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 15: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Equation editor

You can now add mathematical equations that support IBM OpenPages ModelRisk Governance and other solutions. In all rich text fields you can click the new fxicon in the toolbar to open the CodeCogs Equation Editor. You can save and renderequations on the screen. They are rendered in all views and also represented inCognos® reports in HTML output.

Personalized home page

You can personalize the My Work tab to be more specific to your role and torearrange the panes so you can easily and quickly access what you work on everyday.

Click the Configure icon next to the My Work tab name to open thePersonalize My Work Home Page Portlets page. You can design how you wantthe panes to be organized. You use Show to control whether panes are displayedand the arrows to determine where they appear. For more information, see“Personalizing the My Work tab” on page 8.

Changed features in version 7.2.0The following features have changed in IBM OpenPages GRC Platform aredescribed in the following sections.

Renamed Show All hyperlink to View Details

On the My Tasks, My Jobs, and My Work panes on the Home page, renamed theShow All hyperlink to View Details.

Calendar widget

Improved usability by making the calendar widget consistent throughout thesystem. There is now one calendar widget that works the same from all accesspoints. Previously, there were two widgets. For more information see “Using thecalendar” on page 22.

New features in version 7.1.0The new features in IBM OpenPages GRC Platform are described in the followingsections.

New method for adding objects

Administrators and users can now easily add new object instances on a single pagefrom anywhere in the system. By using the Add New wizard, users can create andsave an object by entering only the minimum, most important information basedon the user's profile. When the Auto-naming and Save as Draft features areenabled, new objects can be added with only two clicks. Where possible, thesystem leverages context to simplify input for the users. Users can leverage alibrary of object templates to simplify input requirements and to drive corporatestandards when they create objects.

The Add New wizard can be used to add a row to a grid view and to add fileattachments, which makes it possible for the user to stay on the grid view and get

Chapter 1. What's new? 3

Page 16: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

more work done without leaving the page. The user can associate the new objectto multiple parents of different object types, eliminating the need for extranavigation and tasks in the user interface after the object is created. A confirmationmessage with a hyperlink to the new object instance appears after the object issaved. Users can access the object with one click if they choose to specifyadditional information.

For more information, see “New object instances” on page 13

Redacted fields

Your administrator may have applied security to fields within an object. For certainfields, you may see the field label, but not its value. Instead, the value is redacted,and you see some text, such as "Confidential" in place of the field value.

4 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 17: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 2. Getting started

Logging in to OpenPages GRC PlatformUse this procedure to log in to IBM OpenPages GRC Platform.

About this task

Before you log in, obtain the OpenPages GRC Platform URL and the user nameand password if single sign-on is not configured.

Procedure1. Open Google Chrome or Internet Explorer and in the Location bar enter the

OpenPages GRC Platform URL address, for example:https://opserver:10108/openpages

2. Type your user name and password. If these fields are not displayed, singlesign-on is configured and the system opens.

3. Click Log In.

Logging outYou can end a session and exit the application by clicking Log Out in the globalheader.

Navigating the Grid ViewYou can manage your work with the menus and interface in IBM OpenPages GRCPlatform.

The following illustration shows the Grid view page and a description of thenavigation components:

5

Page 18: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

The components that are labeled in the graphic are described in the followingtable:

Table 1. Grid view

Navigation Description

Global header Use it to view the product name and logged in user.

v Click ? to view online Help.

v The home page is now accessed from the global header. ClickHome in the global header to return to the home page.

v My Settings is now available in the menu under the user name.Click My Settings after your user name to change your passwordor modify locale or other settings.

Menu bar You might have object types from which you can choose as well asa reports menu. Depending upon your configuration, you mighthave one or more of the following menus:

v Use My OpenPages to work with Files, Links, and Milestones.

v Use Reporting to select and run published reports, and to useIBM Cognos Business Intelligence to create your own reports.

v Use menus, such as Organization and Remediation, to work withobjects.

Page title Object page or tool that is active.

6 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 19: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Table 1. Grid view (continued)

Navigation Description

View selector The information about an object that is displayed.

v Filtered List Views contains no editable fields and thereforecannot use the bulk update feature.

v To view objects that match a filter you select, click Filtered Listview.

v To view folder information about an object, select Folder view.

v To view a grid view that might display information about morethan one object type, select a grid view from the list.

v Grid views can have editable fields and use bulk update.

Grid toolbar This toolbar includes action icons and the Grid Actions menu. Toselect an action, click either the action icon or select an action fromthe Grid Actions menu. Actions include creating a new item,updating multiple items (bulk update), exporting information, orsaving changes. These functions are available on grid views but noton the Filtered List view.

Filter Controls Select a filter that you defined or one that is defined by theadministrator. Select a filter from the list to limit the objects that aredisplayed, based on the filter criteria. From the Detail Page Filterselector, you can also edit a selected filter or delete one. To create anew filter, click Advanced in the Detail Page Filter selector. TheAdvanced Filter Panel is displayed.

Advanced FilterPanel

After you click Advanced in the Detail Page Filter selector, use theAdvanced Filter Panel to create or edit a filter.

v Create an ad hoc filter to use one time or save a filter to use itmore than one time.

v To close the Advanced Filter Panel, click Advanced.

Grid After you open an object and select the Filter List view, availableobjects are displayed in the Grid. From the Grid, you can open aspecific object to view.

There can be up to three object types displayed in the Grid. TheGrid is a hierarchy. Expanding the top level object shows the childobjects and grandchild objects (if available).

Folder View When you select the Folder view, available objects are displayed inthe folder grid. From a Folder grid, you might be able to add,move, rename, or delete a folder.

Frequently Asked Questions - Home PageUse this topic to find links to information about frequently asked questions on thehome page.

How do I......v “Using the Home Page” on page 8v “Changing your password” on page 11v “Navigating to an object's detail page” on page 21v “Selecting reporting periods” on page 43v “Logging out” on page 5

Chapter 2. Getting started 7

Page 20: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Using the Home PageUse the Home page filtered lists and bring your work to you. The Home pagedisplays workflow tasks, objects that you plan to work on, assignments, or favoritereports. You can also use it to go to the details page of an object.

What you need to know about the Home page:v Click Home from the global header to return to the Home page from any

location.v Select a tab on the Home page to make it active.v Click the refresh icon to refresh the data on the Home page.v Click a link on any pane on the My Work tab to access more information that

item.v Click View Details to see all the items in a pane on the My Work tab. A pane

shows only a limited number of items on initial display.v Personalize the layout of the My Work tab to contain what you work with most

frequently. For more information, see “Personalizing the My Work tab.”v If you collapse a pane on the My Work tab and leave the page, it is displayed

collapsed when you return to it in this session and later sessions. If you expandit, that display preference is also retained.

Personalizing the My Work tabYou can control the display and order of the panes on the My Work tab on thehome page. Whether this feature is enabled is determined by the administrator.

About this task

The content of the My Work tab comes from your profile. It contains numerouspanes with predefined lists, filtered lists, and embedded reports that have beenconfigured by the administrator. For panes you display, the system places them intwo columns in the order listed. When you hide a pane, the remaining panes shiftup.

Procedure

1. Click Configure . The system displays the Personalize My Work HomePage Portlets page. All panes available for your profile are displayed. The

Configure icon is hidden if the administrator disabled this feature.2. Select or clear Show in the header to control whether all panes are displayed or

hidden.3. Select or clear Show next to an individual row to control whether the pane is

displayed or hidden.4. Select a row and drag and drop it to where you want it placed on the tab. You

can also use the arrow icons. You can select multiple rows at one time andplace them as a group.

8 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 21: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

5. To discard the changes and start over, click Restore Defaults.6. Click OK.7. Review the changes on the My Work tab.

Results

If you change browsers, you have to make the changes again. If an administratoradds panes to the profile you belong to, the systems displays them at the end ofthe My Work tab.

Attachments: browse, files, linksThis topic provides information about attachments, including the browse, files, andlinks functions.

How do I add...v “Adding folders” on page 16v “Adding files to tasks or jobs” on page 87v “Adding or attaching files from the detail page” on page 85v “Adding URL links to object views” on page 89

Editingv “Editing file descriptions” on page 20v “Uploading a new version of a file” on page 90v “Checking in a file” on page 88v “Navigating to an object's detail page” on page 21v “Moving objects to a different folder” on page 50v “Reassigning primary parents” on page 43v “Viewing files or links from the detail page” on page 37

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 2. Getting started 9

Page 22: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

10 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 23: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 3. Managing your settings

My SettingsThis topic provides information about the My Settings page.

How do I...v “Changing your password”v “Changing your locale setting”v “Setting preferences for alert notifications” on page 45

Tell me about...v “Using the Home Page” on page 8v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Changing your passwordYou can change your password at any time.

About this task

Note the following password requirements:v The maximum length is 32 characters.v Passwords are case-sensitive.v If your company uses a single signon, such as LDAP, you cannot change a

password with IBM OpenPages GRC Platform. You must change it with thesingle signon application.

Complete the following steps to change your password:

Procedure1. Click My Settings.2. Click Change Password.3. Type the old password.4. Specify a new password and click Save.

Changing your locale settingYou can change the display text on the user interface to another language.

Procedure1. Click My Settings.2. In the Locale Settings section, click Edit.3. From the Locale field, select a language.

11

Page 24: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

12 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 25: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 4. Adding object instances, links, and associations

New object instancesIn IBM OpenPages GRC Platform, you can add object instances from virtuallyanywhere in the system.

The Add New wizard lets you create and save object instances by entering onlythe minimum and most important information. The types of object instances thatyou are able to add are specified by your administrator and determined by yourprofile.

There are several launch points for the wizard, depending upon the permissionsthat have been granted by your administrator:v A global Add New icon appears on every page. It can be used to create any

object type. To select an object type from the list that appears when you click theAdd New icon, you can begin typing the object name in the filter area to displayonly the object types that begin with the letters you typed.

v An Add New icon appears in the toolbar for the Filtered List View, Grid View,or Home Page Filtered List View. It can be used to create an object instance thatis of the same type as the object type of the list.

v An Add New option is available from a context menu when you right-click on arow in Filtered List View, Grid View, or a Home Page Filtered List View. It canbe used to create an object instance that is of the same type as the object type ofthe list, or any of its direct children.

v An Add New option is available from the Actions menu in Detail and ActivityViews. The option allows adding an instance of a specific object type.

The Add New wizard has the following features:v If you have the appropriate permissions, you can create a new object instance

from scratch or by selecting an existing object instance to use as a template.Using a template saves time because information for the new item is populatedwith information from the existing one.

v If the auto-naming setting is enabled for an object type by your administrator, aname is automatically assigned to the new object instance.

v When you create a child object, you can select the parent object to associate withthe child object.

v If associated children are defined for an object type, you can select child objectsto link to the new object instance.

v A new object instance cannot be saved until all required fields in the Add Newwizard are complete.

v If you begin creating a new object instance but don't complete all the requiredfields, you can save it as a draft. This feature must be enabled by youradministrator.

In most instances, the Add New wizard provides the most convenient and efficientway to add object instances. However, the original add behavior is available in thefollowing places in the program:v From the Folder View

13

Page 26: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v From the Add New icon available from the Business Entity Object List View ifthe Folder View and Filtered List View are both disabled for Business Entity.

v From the Add New icon available from My OpenPages > Project > Milestones.v From the Add File link available from My OpenPages > Attachments > Browse.v From Add New on a workflow Job or Task page.

The Add New wizard consists of a series of tabs that you move between byclicking the Previous and Next icons or by clicking the tabs. The tabs that areavailable to you are determined by the object type, your profile, and theconfiguration settings specified by the administrator.

Create tabThe Create tab allows you to select an existing object instance from whichto prepopulate the field values for the new object instance you are creating.

Parents tabThe Parents tab allows you to identify the primary parent; the one inwhose context the new object will be created. For most configurations,selecting a primary parent is required. This tab also allows you to selectadditional secondary parents of the same or different object type as theprimary parent.

Object-specific tabsOne or more fields tabs follow the Parents tab. They contain the fields thatare available for the specified object type. The tabs and fields displayed aredriven by the view definition for the Add New wizard that is set up byyour administrator.

Associated children tabsIf there are child objects that can be linked to the object instance, one ormore association tabs may follow the object-specific tabs.

For example, if you are creating a questionnaire assessment, you canchoose the processes or assets to associate with the questionnaireassessment.

Review tabThe Review tab displays all of the information from the preceding tabs inread-only mode. It lets you perform a review of your choices and entriesbefore saving your work.

Adding an object instance with the Add New wizardWith the Add New wizard you can add a new object instance from many placeswithin IBM OpenPages GRC Platform.

About this task

The tabs that are available to you in the Add New wizard depend on the objecttype of the instance you are creating, and the permissions that the administratorhas assigned to your profile. Tab labels are displayed on the wizard with a circlefor each tab label. When all required fields for a page are complete and all fieldvalues have passed validation, a green circle is shown for that tab.

Procedure1. From the menu bar or other launch point, click Add New. For a list of launch

points, see “New object instances” on page 13.2. Select an object type from the list.

14 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 27: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

3. On the Create tab, click either Create from scratch or, to use an existing objectinstance as a template, click Create from existing.If you want to use an existing object instance, you can select the object usingone of the following methods:v Select an object from the Recently Used tab.v Find an object by using one of the following options on the Search tab:

– Type a term in the Search field to find an exact match to the object nameor description.

– Run a saved filter from the Filter list.The list of filters available is the same as the saved filters you see on theFiltered List View. When you run a saved filter from here, the resultsmight differ because you see only objects that can be associated with thecurrent object. When you run a saved filter from the Filtered List View,you see all objects for which you have read access.

You can refine the list of existing objects shown in the search results by usingthe Narrow by options. For example, to show only objects in a specificfolder, type the folder name in the Folder field.

Click Next.Depending on the object type or the permissions assigned to you from youradministrator, the Create tab might not appear.

4. To identify the parent object to associate with the new object instance, on theParent tab, select an object using one of the following methods:v Select an object from the Recently Used tab.v Find an object by using one of the following options on the Search tab:

– Type a term in the Search field to find an exact match to the object nameor description.

– Run a saved filter from the Filter list.The list of filters available is the same as the saved filters you see on theFiltered List View. When you run a saved filter from here, the resultsmight differ because you see only objects that can be associated with thecurrent object. When you run a saved filter from the Filtered List View,you see all objects for which you have read access.

You can refine the list of existing objects shown in the search results by usingthe Narrow by options. For example, to show only objects in a specificfolder, type the folder name in the Folder field.

If you are creating from a parent object, it might not be necessary to select aparent.

5. Type or review a name for the object.If auto-naming is not enabled and you are creating a new object, you mustenter a name. If you are copying an existing object, the name defaults to thename of the source object and you must change it.If auto-naming is enabled, a name is automatically entered for you and mightbe read-only, depending on the configuration. If you are copying an existingobject, the name is unrelated to the source object's name.

6. Move through each of the object-specific tabs in the wizard by clicking the tablabels or using Next and Previous, and complete all of the required fields.Required fields are marked with an asterisk (*). A white circle next to a tablabel indicates that all the required fields for that tab are not complete or failedvalidation.

Chapter 4. Adding object instances, links, and associations 15

Page 28: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Note: Required and optional fields vary depending on the object type.7. If there are associated children tabs in the wizard, you have the option to select

objects to associate with the new object instance on each tab.For example, if you are creating a control, you can associate it to the issuewhich indicated that the control was missing.Select a child object using one of the following methods:v Select an object from the Recently Used tab.v Find an object by using one of the following options on the Search tab:

– Type a term in the Search field to find an exact match to the object nameor description.

– Run a saved filter from the Filter list.You can refine the list of existing objects shown in the search results by usingthe Narrow by options. For example, to show only objects in a specificfolder, type the folder name in the Folder field.

If you associate a large number of child objects, for example, more than 250, thesystem saves the object and then completes the associations in a backgroundprocess instead of while you wait. You receive an email when the associationsare finished. The email contains links to a process report and to the object'sdetail page. You can also review the status of long-running processes in MyOpenPages > Background Processes > My Background Processes. Theassociations are created if all the associations in the group are error-free. Thedefault for long-running processes is 250 child objects associations but theadministrator can change it.

8. Click Save.You cannot save until all required fields are completed with valid values. IfSave as Draft is enabled by your administrator, you can save a draft of thenew object instance without completing all the required fields in the wizard.

Adding foldersYou can add a folder for an object at any level of an object hierarchy. For example,you might add folders to group objects into categories.

About this task

A top level folder exists for each object type. For example, the folder hierarchy forTest objects starts with a root storage folder named Tests. You cannot rename,move, or delete a root storage folder.

Procedure1. To add a folder to hold files or links, click My OpenPages > Browse. Select a

folder to contain the new folder, and click Add Folder.2. To add a folder from the Folder View for an object, from the menu bar, select

an object, select Folder View, select a folder to contain the new folder, and clickAdd Folder.

External URL linksAn external link is a URL that opens a browser window and displays the contentsof that target destination. Whether you add a stand-alone external link or attach anexternal link directly to an object, a copy of that external link is stored in the filerepository.

16 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 29: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

You can add an external link to a folder or attach a link to an object.

Adding an external link to a folderFrom the Links Folder View page you can create a link to an external URL. Forexample, you can create a link to a document that is on your company website.

Procedure1. From the menu bar, click My OpenPages > Attachments > Links. If necessary,

click the View field until the Folder view is displayed.2. Expand the folder hierarchy and navigate to the folder.3. To add an external link in an existing folder, select the folder that will contain

the new link.4. To add an external link to a new folder, complete the following steps:

a. Select the folder in which you want to create the new folder.b. Click Add Folder.c. Type a name and description for the new folder and click OK.d. Select the folder that you created.

5. Click Add New.6. In the Name field, type a name for the child object. In the URL box, type a

fully qualified URL internet address. For example, if you want to create a linkto your company's annual report, you might enter http://www.mycompany.com/annual-report.pdf.

7. Click Create.

Results

The link is listed, including any comments or descriptive text, on the Links FolderView page under the selected folder.

Attaching an external link to an objectAn external link is a URL that opens a browser window and displays the contentsof that target destination. Whether you add a stand-alone external link or attach anexternal link directly to an object, a copy of that external link is stored in the IBMOpenPages GRC Platform file repository.

Procedure1. Navigate to the Detail View page of the parent object.2. In the navigation pane, under Attachments, click Links.3. On the listing pane, click Actions > Add a new Link.4. In the Add Link pane, type a name for the link and a fully qualified internet

address.5. Complete all additional required fields.6. Click Save.

Results

The external link is listed, including any comments or descriptive text, in the Linkspane of the selected object.

Chapter 4. Adding object instances, links, and associations 17

Page 30: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Associations between objectsYou can link objects to form a hierarchical tree view of a company governance, riskmanagement, and compliance structure - from the business entity level down tothe details of each individual risk, control, and test.

The process of linking objects is called association. Files are attached to objects.Associations are relationships that exist among objects, or between objects andattached files. Associations can be created or removed without affecting the relatedobject or file.

The IBM OpenPages GRC Platform Object Model Framework contains businesslogic that governs the following rules:v The type of objects that can be associated together. For example, in the standard

object model, a control object can be associated with a risk and test plan but notwith a process.

v The relationship of objects in the hierarchy, for example, parent-child orstand-alone.

In a parent-child hierarchical relationship, the object that initiates the association isthe parent object, and the object that is the target of the association is the childobject. When a child object is added from a Detail or Activity View page of aparent object, the child object is a primary child and is automatically associatedwith the parent object. Depending on your object model, if an object type isallowed to have multiple parent objects through association, that child object canhave only one primary parent association. The parent-child relationship that existsbetween objects affects how certain operations such as copy, delete, association,and locking are performed by the application. For example, when a user locks aparent object, all its associated child objects are also locked and cannot be modifieduntil the lock is removed.

18 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 31: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 5. Editing items

Applying changes to multiple objects with bulk updateIf you have multiple objects that are defined in an object type, such as more thanone Business Entity, you can edit information in multiple objects, by using the bulkupdate function.

About this taskv Identify field values to change and objects to update. The fields that you identify

are updated in all objects that you select.v You can also leave fields unchanged or clear the values in a field.v Administrative settings might prevent you from updating an object.v All objects that generate no errors are updated.v Field dependencies, locks, and permissions might prevent you from modifying

selected objects. The objects that you can modify are saved with the changes,while the others are not changed.

v Currency fields and fields for which you edit the content using a pop-upwindow cannot be edited in the bulk update panel. These fields are notdisplayed.

v You cannot clear required fields.

Note: When using the bulk update feature, dependent picklists do not changevalues when the controlling value changes. Instead, all values from both thecontroller and the dependent picklist are displayed. Validation of selected valueswill be done before the objects are saved and any conflicts are reported back to theuser.

Procedure1. From the menu bar, click the object type to open.2. Click Grid Actions > Bulk Update.3. Select the objects to update. To update second or third level objects, expand the

rows in which the objects are contained and select the objects. If you selectmore than one object, select the object type to update from the object selector.

4. Edit the fields to update.5. To clear the value in a field, select Clear Value.6. Click Update. The first record is opened and the updates are applied. If the

requested change cannot be made, an error message displays the reason for theupdate failure. The bulk update feature continues to open and apply updates torecords until all records have been processed.

Editing objects in a grid or filtered list viewYou can edit fields for a single object from a grid view or a filtered list view.

Before you begin

Consider the following information before you edit an object in grid view offiltered list view:

19

Page 32: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v You cannot edit the following object fields: Folder, Creation Date, By, LastModification Date, Last Modified By.

v Remove all signature locks, including inherited locks, before you edit an object.v If you and another user simultaneously edit the same object, or if there are any

changes after you retrieve it, an error message notifies you of a conflict.v Opening an object in a new browser window to copy field data between

browser tabs or windows might cause unspecified results.v If you scroll more than a few rows away from the row you are editing, the edits

are canceled.v You can edit an item that is associated with an object from the object page.

Procedure1. Click Action > Edit this Item.2. Edit the fields.3. Click outside the row to save changes.4. To edit an item that is associated with the object, click the navigation menu in

the Association section. The number in parenthesis identifies how many itemsexist in a category.

5. Click the name of the item to edit.6. Click Action > Edit this Item.7. Edit the fields, as needed. Click Save.

Editing objects in detail viewYou can edit an object in detail view.

Procedure1. Open the Detail Page of the object to edit. You can access the detail page from

a link from an email, a helper, a home page list, the Folder View, the Filteredlist, or a grid view.

2. To edit an associated object (child or parent), complete the following steps:a. Click the object type in the navigation pane under Associations.b. From the listing pane, click the name of the object to edit.c. From the detail pane of the object, click Actions > Edit this object.

3. Update the object details, and click Save.

Editing folder descriptionsYou can change the description of an existing folder by opening the folder forediting.

Procedure1. From the View selector, open the Folder View page.2. Click the name of the folder to modify.3. On the detail page, click Edit, and edit the description.

Editing file descriptionsUse this procedure to change a file description.

20 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 33: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. Click My OpenPages > Files.2. Locate the file to modify.3. Click My OpenPages > Links.4. From the detail pane, click Edit the link and edit the description.

Navigating to an object's detail pageUse this procedure to open an object's detail page.

Procedure1. Select the object type from the menu bar.2. From the Filter List View, select a search filter to narrow the list of objects that

are displayed.3. Click the name of the object to view its detail.

Unlocking objectsUse this procedure to unlock objects.

About this task

When you unlock an object, the following occurs:v Any signature on an unlocked object remains in effect and is NOT revoked.v The lock icon is removed from the object, and the inheritance lock icon is

removed from any associated child objects.v From a grid view or Filtered List view, you can lock or unlock the top level

object types. When you lock or unlock a top level object type, it adds or removesinherited locks.

v You cannot unlock direct locks from second or third level objects.

Procedure1. Navigate to the Detail page or Grid View of the object type to unlock.

You can unlock the object using the following methods:v To unlock the selected object, in the navigation pane under Details, click the

Fields link if the fields for the selected object are not displayed.v To unlock an associated object (child or parent):

– In the Associations section, click the object type to unlock.– From the listing pane, click the name of the object you want to unlock.

2. From the detail pane of the associated object, select Actions > Unlock thisitem.

3. To view lock details on the Details page, click Details > Locks.

Copying objectsYou can copy an existing object to quickly create an object with similar values.

Procedure1. From the menu bar, select the object type to view.2. From the list of objects, click the name of the object to select.

Chapter 5. Editing items 21

Page 34: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

3. From the navigation pane, click the object to select.4. Select the object to copy.5. Click Actions > Copy an existing item.6. Type a name for the new object.7. To copy associated files, enable the option8. To copy associated issues, enable the option.9. Enable one of the following options to determine how to resolve file naming

conflicts:v Create a new version of the new object in the destination directory.v Create a new object whose name is prefixed with “Copy of”.v Do not copy resources with naming conflicts.

10. Click Finish. A duplicate instance of the object is created and listed on theparent object detail page.

Refresh information on a pageFor object overview pages and some administrative functions, you might need torefresh the page to display any new or updated information. For example, if youadded a new business entity to your organizational structure and did not see thenew entity displayed on the Business Entity Overview page, click the Refresh iconor Actions > Refresh to refresh the page and display the updated information.

Using the calendarUse the calendar widget to choose a date. It works the same from all access points.

About this task

The calendar defaults to the last date you entered in the current session. If youhave not changed the date, it defaults to today's date.

Procedure

1. Click Calendar to open the calendar.2. Choose a date or click Reset to clear the last saved date. The next time that you

open the calendar, it defaults to today's business date.

22 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 35: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 6. Searching for objects

Searching for objects using global searchYou can quickly find and act upon the objects that are relevant to your GRC tasksby using global search.

About this task

IBM OpenPages GRC Platform global search uses full-text indexing and naturallanguage processing to search across all object types or one or more object types.

When you search, the behavior sequence is: first, the results across all object typesthat you have access to are initially displayed. Then, from the Narrow by, you canselect one or more object types and your current search and subsequent searcheswill be limited to those selected object types.

The following entries describes some ways in which cross-object search responds:v If you search for “step missing”, you can expect to see “missing process steps”,

that is, the words do not need to be in order.v If you search for “trade”, you can expect to see “trading”, that is, the words do

not need to be in the exact form.v If you search for “breach”, you can expect to see in the results any object that

contains the word “breach” in its content.

You can refine the results of your search even further. For more information, see“Advanced search techniques” on page 24.

Procedure1. Type the content that you are looking for in the Search box. The search results

for all of the objects for which you have permission to view are displayed andranked from the most to least relevant, irrespective of object type.

2. Click an item in the search results. The Detail view for the selected objectopens. Depending on how your profile is set up, it is possible to have theselected object open in an Activity view.

3. To narrow down your search results by object type, you can use Narrow by torefine the results even further to within one or more object types.

Comparing Global Search to Basic and Advanced FiltersThere are differences between global search and filters search, and each style ofsearch their own advantage and use. As an IBM OpenPages GRC Platform user,you can decide which works best for you and when to use one over the other.

Filtered search uses your database search feature, which uses basic text matchingto find matching records. Global search uses full-text indexing and naturallanguage processing to find matching records. For example, to find records thatcontain the word "risking", you can enter "risking", or "risked", or "risks", or "risk",and any of those variations match records containing all the variations of the word"risk". Note that if you try to search for "isk", that is, text inside the word "risk",using global search, you do not get a match on "risk".

23

Page 36: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Advanced search techniquesA casual user can use natural language to search for objects, but you can alsorefine the results of a search by using advanced techniques in global search.

About this task

The following describes some techniques that you can use to focus the results of asearch more closely:v You can enter risk -uk to find all objects that contain the word "risk", but

exclude objects from this set that contain the word "uk".v You can enter "Accounts Receivable for North America Retail Banking" to use

quotation marks to search for specific phrases.v You can enter "accounts receivable" "retail banking" to use quotation marks

to search for two or more phrases.v You can enter "accounts receivable" -"retail banking" to eliminate the

specific phrase "retail banking".v You can enter Accounts -Receivable -North -America -Retail -Banking to

eliminate the words starting with the "-" operator from your search result.v You can enter risk OR uk OR us, using the Boolean OR operator to get results

that contain any of these words. Some results can contain all three.v You can enter risk uk => risk uk bank => uk risk bank us: the more words

you type, the narrower the search results. The word order is not important.v You can enter RiSk uK: the search results are not case-sensitive.

24 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 37: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 7. Filtering information

About filtersTo make data more manageable for viewing and selection, use filtering options tolimit the information that is returned for a specific object type. Only data thatmatches the criteria is displayed in the list.

Access an object on the Filtered List View or Grid view when you select an itemfrom the menu bar. Running a filter displays search results based on the propertyfields that you or the filter define. The results of a filtered search are displayed.

Click the name of an item in the search results to open the Detail page. If multipleitems are returned from the search, you can use the Iterator box, which is on aDetail or Activity View page, to move through, view, and edit each object in theresults list without returning to the Filtered List View or Grid View. If you are on agrid view you may be able to edit the data in place.

The following types of filters are available:v Saved filters have been saved either by you for your own use or by an

administrator for group or public use.v Public Filters are predefined by administrators and are available for group or

public use. You can select one of these filters but you cannot edit or delete them.You can copy a public filter to use as a template, change the search criteria, andthen save it as one of your own filters.

v My Filters are private filters that you define and save. You can copy, edit,rename, or delete any filters that you create.

v Ad hoc filters are filters that you create and run without saving. These filters aretemporary and do not appear on the filters list.Type text in the Filter Selector and then press Enter. The results will be filteredto include those records that contain the entered text in either the Name or theDescription field of the object.

v You can add complex logic to a search filter to help refine your search. Bydefault, the system only retrieves objects that matched all search criteria. Forexample, if you had 3 fields defined in your advanced search filter, the systemwould retrieve objects that matched all 3 fields based on the following logic: 1AND 2 AND 3.If you want to broaden the search so it includes field 1 and either fields 2 or 3,you could use the complex logic feature to modify the default search logic. Forexample, you could modify the logic in the search filter to include the ORoperator so the search would retrieve all objects that matched field 1 andmatched either fields 2 or 3 based on the following logic: 1 AND (2 OR 3).

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27

25

Page 38: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

View filters in the Analytics barWhen you use the Filtered List View or Grid view, you can also view filters in theAnalytics bar.

The Analytics bar provides an overview of saved filters for an object. Each filteralso shows the number of results available. You can customize the Analytics bar tofocus on specific filters that you want to follow. For example, you could configurethe Analytics bar to provide an overview of the number of assessments in eachstatus.

By default, when you show the Analytics bar for the first time, the filters that areshown are the same as those listed in the Filter selector.

If you create an advanced filter or copy a filter, it is automatically added to theAnalytics bar. If you delete a filter, it is also removed from the Analytics bar.

Settings that you apply in the Analytics bar are your personal settings, and do notapply to other users. They also apply to your current browser only.

If you clear the Browsing data setting in your browser, it also clears your Analyticsbar settings.

Showing or hiding the Analytics barBy default, the Analytics bar is hidden from view in the Filtered List View or Gridview for all objects. You can show the Analytics bar for individual object types.

26 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 39: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

About this task

Procedure1. Select the object type from the menu bar.2. Click Analytics Bar.

You can use the scroll bars to view all the filters available in the Analytics bar ifthey are not all shown on a single screen.If there are no saved filters available, a message is shown instead of theAnalytics bar.

3. When the Analytics bar is visible, you can click Analytics Bar to hide it again.

Showing or hiding filters in the Analytics barBy default, when you show the Analytics bar for the first time, the filters that areshown are the same as those listed in the Filter selector.

About this task

You can customize the Analytics bar to show only the filters that you want tofollow, and hide others.

Tip: You can quickly see which filters are shown

or hidden

in theAnalytics bar by viewing them in the Filter selector.

Procedure1. Hide a filter by using one of the following options:

v In the Analytics bar, click Configure for the filter to hide, then click

Toggle Visibility .

v In the Filter selector, click Hide from Analytics bar for the filter to hide.

2. To show a filter, in the Filter selector, click Show in Analytics bar for thefilter to show.

Changing the order of filters in the Analytics barYou can change the order that filters are shown in the Analytics bar.

Procedure

1. In the Analytics bar, click Configure in the filter panel that you want tomove.

2. Click the Drag and Drop Panel arrows shown in the filter panel, then drag thefilter to the new position.

Setting a default filterYou can select any saved filter as the default filter to run in the Filtered List View.Saved filters are listed in the Filter selector. If you are using the Analytics bar, thefilters might also be visible from there, depending on your settings.

Chapter 7. Filtering information 27

Page 40: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

About this task

After you set a default filter, the next time you log in to IBM OpenPages GRCPlatform, the filter results are shown when you access the object type in theFiltered List View.

Procedure1. Select the object type from the menu bar.2. To set a default filter, use one of the following options:

v In the Filter selector click Toggle Default for the filter to set as default.

v In the Analytics bar, click Configure for the filter to set as default, then

click Toggle Default .When default filter is set, a gold star is shown in the Filter selector and thefilter panel in the Analytics bar.You can remove the default filter, by selecting another filter as the default or byclearing it.

Creating advanced filtersYou can create a filter for an object type to narrow search results and locateinformation quickly.

About this task

To create a filter, select the fields to use for filtering and define the search criteria.Consider the following options:v Use complex logic with logical operators and parenthetical expressions to

further refine search results.v Some special characters have limitations.v Text that you type into text boxes is not case-sensitive.v Some object types might have hidden values that are configured for enumerated

fields. By default, hidden values are not displayed. You must display hiddenvalues before they can be used for filtering.

Note: Do not include long string fields that are encrypted using field levelencryption in the search criteria because they can return unexpected results.

Procedure1. Select the object type from the menu bar.2. Click Advanced to display the Advanced Filter panel.3. Click New.4. Select the field to use in the search and define search conditions.5. To use more than one field in the filter, click and add more search criteria.6. To run the filter, click Filter.7. If you want to save the filter, click Save.

Saved filters are available from the My filters category in the Filter selector. Ifyou are using the Analytics bar, they are also available from there.For more information, see “Running saved filters” on page 29.

28 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 41: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Running saved filtersFilters that you create and save are listed under My Filters in the Filter selector.Filters that an administrator creates for group use are listed under Public Filters. Ifyou are using the Analytics bar, the filters might also be visible from there,depending on your settings.

About this task

Procedure1. Select the object type from the menu bar.2. To run a filter, use one of the following options:v In the Filter selector, select the filter to run.v In the Analytics bar, click the filter to run.

When you run a filter from the Analytics bar, it is automatically selectedwhenever you refresh your browser, and it overrides any default filter.

Editing saved filtersYou can modify search criteria for filters that you create. These filters are listedunder My Filters in the Filter selector. If you are using the Analytics bar, the filtersmight also be visible from there, depending on your settings.

Procedure1. Select the object type from the menu bar.2. To edit a saved filter, use one of the following options:

v In the Filter selector click Edit Filter for the filter.

v In the Analytics bar, click Configure for the filter, then click Edit Filter

.When you edit a filter from the Analytics bar, you must save it to see theupdated number of results available in the filter panel.

The filter criteria is displayed in the Advanced Filter panel.3. Modify the filter values and click Save.4. To run the filter, click Filter.

Deleting saved filtersYou can delete a filter from the My filters category in the Filter selector. If you areusing the Analytics bar, and the filter is shown, you can also delete it from there.

About this task

When you delete a filter, if there are no other saved filters available, a message isshown instead of the Analytics bar.

Procedure1. Select the object type from the menu bar.2. To delete a saved filter, use one of the following options:

v In the Filter selector click Delete for the filter to delete.

Chapter 7. Filtering information 29

Page 42: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v In the Analytics bar, click Configure for the filter to delete, then click

Delete Filter .

Copying filtersYou can copy an existing filter and use it as a template. The filter is availableunder My filters in the Filter selector. If you are using the Analytics bar, the filtermight also be visible from there, depending on your settings.

Procedure1. Select the object type from the menu bar.2. To copy a filter, use one of the following options:

v In the Filter selector click Edit Filter for the filter.

v In the Analytics bar, click Configure for the filter, then click Edit Filter

.When you edit a filter from the Analytics bar, you must save it to see theupdated number of results available in the filter panel.

The filter criteria is displayed in the Advanced Filter panel.3. Click Save As, then rename the new filter.4. Edit fields as necessary, then click Save.5. To run the filter, click Filter.

Renaming filtersYou can rename a private filter.

Procedure1. Select the object type from the menu bar.2. To rename a filter, use one of the following options:

v In the Filter selector click Edit Filter for the filter.

v In the Analytics bar, click Configure for the filter, then click Edit Filter

.When you edit a filter from the Analytics bar, you must save it to see theupdated number of results available in the filter panel.

The filter criteria is displayed in the Advanced Filter panel.3. Click Rename.4. Type the new name and click Apply.

Hiding the Advanced filter panelYou can hide the Advanced filter panel after you create or edit a filter.

Procedure

To hide the advanced filter panel, click the Advanced toggle.

30 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 43: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Export data from filter resultsYou can export data into a spreadsheet (.xls format), from any filter that you run.All objects that match the filter criteria are exported.

Procedure1. Select the object type from the menu bar.2. If the Folder View page is displayed, click it and select Filtered List View.3. To export data from an adhoc filter, create an advanced filter without saving,

and click Filter.For more information, see “Creating advanced filters” on page 28.

4. To export data from a saved filter, use one of the following options:v In the Filter selector, select the filter to run.v In the Analytics bar, click the filter to run.

5. When the results of the filter are shown, click Export and follow thescreen prompts.

Clearing filter resultsIf you have applied a filter to a Filtered List View or Grid View, you can clear thefilter.

About this task

You can tell whether a filter is applied by looking at the message bar. If a filter isapplied, the Clear Filter option is available. If a filter is not applied, the messagebar displays No filter applied.

When you clear a filter, the search results from the filter are cleared. The name ofthe filter remains in the Filter selector. You can apply a new filter, ignore the valuein the filter selector, or select and delete the filter name in the Filter selector.

To clear a filter in a Filtered List View or Grid View, click Clear Filter.

Sorting dataTo sort data in the Filtered List View or Grid view, you can control the columndisplay.

For more information, see “Controlling the column display on a Grid or FilterView” on page 34.

Chapter 7. Filtering information 31

Page 44: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

32 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 45: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 8. Viewing information

Folder ViewThis topic provides information about the Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Detail ViewThis topic provides links to information about the Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

33

Page 46: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Controlling the column display on a Grid or Filter ViewFor each grid view or filter view, you can define what information is displayed onthe page. The fields that are available in the views are configured by theadministrator.

About this task

For each view, you control how the results are displayed. Define the name field inthe first column because it is the only required field. Then, in Full Mode, identifywhat fields of information are displayed. Select the fields to display from the fieldsthat the administrator configured.v You can create another view and further restrict what fields are displayed in

Compact mode. You can move between the two views. Fields that enableCompact Mode are the only fields that are displayed when Compact Mode isenabled. The fields that can be displayed in Compact mode are a subset of thefields that are displayed in Full Mode.

v To reorder multiple columns, select multiple rows by clicking Ctrl and the fieldsto reorder. Values for all fields that are configured by your administrator appearin the Info Card for that object. You can toggle the display between Compactand Full mode for an object by clicking the icon next to the label for the namefield. You can reorder the sequence of fields in the results. If you use a differentbrowser, move to a new computer, or the administrator changes the viewconfiguration, the view reverts to the default.

Procedure1. On the grid toolbar, click Grid Actions > Manage Columns.2. To remove information from the view, disable Full Mode next to the field.3. To display fields in Full Mode, enable Full Mode.4. To display fields when the column view is collapsed, enable Compact Mode.5. To control the order of fields in the results, select the fields to order. Click the

up or down arrows to move fields to the position.6. Select how to use the column information in the sorting process in the Sort

Order field: select Only this item to sort by only this column, 1 to use thiscolumn as the main sort item, and None if the column is not used.

7. If you select 1 in the Sort Order field, a 2 is displayed in the next field youselect. You can select 2 in another column to identify the secondary sortingfield. If you enable 2, a 3 is displayed in the other fields. You can select asmany sorting columns as is available.

8. Identify if the sort order is ascending or descending in the Sort Direction field.9. Click OK.

34 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 47: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Results

Attention: Changes to the Grid View are saved in the browser cookie. If yourbrowser is configured to delete cookies when the browser closes, changes to thegrid view are deleted when the browser closes.

Reordering columnsYou can define the order that columns are displayed on the page. The fields thatare available in the views are configured by the administrator.

About this task

To reorder multiple columns, select multiple rows by clicking Ctrl and the fields toreorder. Values for all fields that are configured by your administrator appear inthe Info Card for that object. You can toggle the display between Compact and Fullmode for an object by clicking the icon next to the label for the name field. You canreorder the sequence of fields in the results. If you use a different browser, move toa new computer, or the administrator changes the view configuration, the viewreverts to the default view.

Procedure1. On the grid toolbar, click Grid Actions > Manage Columns.2. To control the order of fields in the results, select a field to reorder. Click the up

or down arrow to move the field to a new location in the display.3. To sort information that is based on field values, select the field to use for

sorting. Select how to sort the field information in the Sort Order field.v Select Only this field to sort information with this column only.v Select 1 to use this column as the main sort item.v Select None if the column is not used.v If you select 1 in a field definition, a 2 is displayed in the next field that you

select. Select 2 in the field to use as the secondary sorting field.v If you enable 2, a 3 is displayed in the other fields. Continue to select more

sorting columns as is available.4. Identify if the sort order is ascending or descending in the Sort Direction field.5. Click OK.

Attention: Changes to the Grid View are saved in the browser cookie. If yourbrowser is configured to delete cookies when the browser closes, changes to thegrid view are deleted when the browser closes.

Viewing the change history of objectsThe Change History pane displays the modifications that were made to an objectduring a selected reporting period. If an object field is not listed in the ChangeHistory table, no changes were made to that field during the reporting period.

Procedure1. From the menu bar, select the object type.2. Click the name of the object to open its detail page.3. In the navigation pane under Details, click Change History.4. To compare text changes, click the View Changes link in the New Value

column.

Chapter 8. Viewing information 35

Page 48: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Viewing and comparing marked-up changes to textChanges to plain text and Rich Text Formatted (RTF) are automatically tracked. Anew version is created when the object is saved. The Change History pane displaysa changes link for all text. In addition, the old and new value of the text isdisplayed.

About this task

The View Changes link displays marked-up text and the revision history ofchanges for the selected text. The text in the viewer is read only. To change text,edit the object.

In the Change History Viewer, you can view revisions that are made to the text.Editing activities such as delete, insert, and move are tracked and displayed withmarked-up text in the viewer. The Change History Viewer does not trackformat-only changes that are made to RTF fields such as changes to style, font,color, or indentations. It does not track images that are added or deleted from theRTF field, or image changes. The Change History Viewer does not comparechanges within tables. Tables are displayed as they exist in the most recent versionof the object. View and compare HTML source between different versions of anRTF field.

Procedure1. Open the detail page that contains the change history to view.2. In the navigation pane under Details, click Change History.3. To open the Change History Viewer, click the View Changes link in the New

Value column that contains the text.4. To compare text in two versions, in the Revision History pane, select the two

versions you want to compare.5. If multiple revisions exist for a text, clear the check box for one version before

you select another version for comparison.6. Click Show Changes.7. To view comparisons in HTML source code for RTF fields, click View Source in

the Change History Viewer.8. To return changes without the code, click Changes.9. To view the change history for another reporting period, select a different

reporting period for this object. You cannot view audit trails for multiplereporting periods on the same page.

Viewing locksThe Locks pane displays the locks placed on an object during a selected reportingperiod. By default, the date and time the lock was placed on the object, the nameof the lock owner, and whether the lock was inherited is displayed.

About this task

You must have application permissions to view locks.

Procedure1. Navigate to the detail page of the object to view.2. In the navigation pane under Details, click Locks.

36 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 49: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Viewing signaturesYou can view a signature that is associated with an object.

Procedure1. Open the detail page of the object.2. In the navigation pane under Associations, click Signatures.3. From the listing pane, click the name of the signature to view.4. To view the audit trail for signatures, in the navigation pane under Details,

click Change History.

Viewing reports in a different formatIf your system is configured to display reports in different formats, you cangenerate a report and then view or save it in another format. The standard formatis HTML.

Procedure1. On the icon bar of the generated report, click Action.2. From the list, select a format.3. Follow the screen prompts.

Viewing files or links from the detail pageYou can view the contents of a file or link. If the Check In/Check Out feature isconfigured, you can view files that are checked out by another team member. Youcan edit only files that you check out.

Procedure1. Open the object that contains the file or link.2. Click the name of the object.3. From the navigation pane, click the name of the file or link in the Attachments

section.4. To view the versions of a file or link, click the name of the file or link in the

detail window. Click Versions in the Details section of the Navigation pane.

Viewing lifecycle informationIf an object is assigned to a lifecycle, you can view that information on the objectDetail View.

About this task

You can view an object's current lifecycle stage, for example, the assignee, thestatus, and comments. For more information see “Lifecycles” on page 128.

Procedure1. Open the object that is assigned to a lifecycle.2. Click the name of the object.3. From the navigation pane, click the Fields section. Lifecycle fields for the

current lifecycle stage are displayed under Lifecycle Management. The fieldsare read-only except for Update Assignee, which you might be able to change

Chapter 8. Viewing information 37

Page 50: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

depending on the object and the stage. For more information see “Updating aquestionnaire assessment's lifecycle assignee” on page 112.

4. To view previous lifecycle stage information, click Change History.

Printing Detail View informationYou can share information in IBM OpenPages GRC Platform with others byprinting the relevant part of the Detail View.

You can now print the information from the Detail pane of the Detail View. Print isa new icon next to the Actions menu. Click the Print icon to open a new windowthat contains the content to be printed. The print function not only prints what isvisible on screen, but also information that is scrolled off the screen.

As well as sections, you can print the contents of derived fields such as Orphan,Business Entity Hierarchy, Primary Parent Hierarchy, and Computed fields.

You can print labels, sections, and enum values in the locale of the user. A headerappears on every page, containing Date/Time in the locale of user.

Note: To change the time format when you print a detail view, specify the formatusing the page setup from the Print settings for the Chrome or Microsoft InternetExplorer browsers.

The print function does not print the following types of information:v Related Informationv Context Viewv Hover helpv On Demand fields content

After printing, you return to where you were before, and in same state. Forexample, if you were on the second page of child list, you return to the secondpage; if you were in Read mode, you return to Read mode.

38 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 51: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Figure 1. Sample of a Detail view ready to be printed

Chapter 8. Viewing information 39

Page 52: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

40 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 53: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 9. Managing my work

Viewing summary object information on info cardsView the info card to see a summary of an object properties.

Procedure1. From the menu bar, select the object type.2. Open the object type to view.3. To view a summary of an object, move the mouse pointer over the name of the

object. An info card displays all configured field values for that object.

Generating and viewing reportsYou can generate an individual report from the Reporting menu or select a reportfrom the Reports page.

Procedure1. To run a report, from the menu bar, click Reporting.2. From the Reporting, click the name of the report.3. For interactive reports, complete all required fields and selections.4. Click Finish to generate the report.

Activity View pageThis topic provides information about the Activity View Page.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Editing objects in Grid or Filtered List View” on page 47v “Copying objects” on page 21v “Deleting objects” on page 48v “Disassociating objects” on page 49v “Locking objects” on page 50v “Submit jobs” on page 45v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are alerts and can I change my notification options?

Completing action itemsYou can select a percentage in the Percent Complete field of an Issue Action Itemor Milestone Action Item object to identify your progress or completion of theassigned action item. To show that you have completed an action item, set thepercentage complete to 100%.

41

Page 54: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. From the menu bar, click Remediation > Action Items.2. Click the name of the action item to view.3. Click Actions > Edit This Action Item.4. In the Percent Complete field, type 100%.

Reassigning tasksYou can reassign tasks to other users. When you reassign a task, the task isremoved from the My Tasks pane on your home page. A notification is sent to theuser and includes any comments.

Procedure1. From the global header, click Home.2. From the My Tasks pane, click the name of the task to open.3. On the Task Details pane, click Reassign.4. Search for a user to whom to assign the task or click the Group icon to assign

the task to a group.5. Select a user or group and click Reassign.

Completing tasksCompleting a task is the process of setting the status of an accepted task tocomplete.

About this task

Depending on your role, a completed task can be sent to a reviewer who thenapproves or rejects the work. In most cases, you work with files associated withthe task, or add files or links to the task before you complete it.

Tasks that require approval and are rejected are returned to the owner for furtherwork and the workflow cycle is repeated until the task is approved. When youcomplete a task, the task is removed from the My Tasks list on your Home page.If your task requires a review, a notification is sent to the reviewer along with yourcomments.

Procedure1. Click Home from the menu bar.2. From My Tasks, click the name of the task you want to complete to open its

detail page. If the task is not displayed, click View Details to display allassigned tasks.

3. On the Task Details pane, click the action to take to complete this task (such as,reassign the task to another person or reject the task).

4. On the Complete this Task page, type a comment or any special instructionsand click Complete.

Signing off on tasksSome tasks can require that you approve a process or a result.

42 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 55: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. From the menu bar, select the object type.2. Open the task.3. Click Accept.4. Click Review and Signoff .5. Type a comment with your signature and click Approve.

Results

Signing off on an object automatically signs off on every object that is associatedwith it. For example, signing off on a process also signs off on all of the risks,controls, and tests that are associated with the process.

Selecting reporting periodsYou can view or search for data for a current or past reporting period. However,you can only modify data in the current reporting period.

About this task

Note: Active reporting periods are essentially in the process of being closed (or"finalized"). An active reporting period can be reapplied at any business entitylevel to synchronize the business entity and its children with the current reportingperiod. For more information, see the topic Active reporting periods and operationallimitations in the IBM OpenPages GRC Platform Administrator's Guide.

Procedure1. On any page for an object, click the Reporting Period drop-down field.2. Select a reporting period from the list. Data for the selected reporting period is

displayed.

Reassigning primary parentsAn object can have only one primary parent. If an object has multiple parentobjects, you can change the primary association from one parent object to anotherone.

Procedure1. Open the detail page of the object.2. In the navigation pane under Parents, click the parent object type.3. From the listing pane, click the name of the object to open its detail pane. If the

parent object you want is not listed, first associate the parent you want to theselected object and then make it the primary parent.

4. From the detail pane of this object, click Actions > Make this Primary. ThePrimary Association icon is displayed next to the name of the new primaryparent object.

Chapter 9. Managing my work 43

Page 56: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Refreshing information on a pageFor object overview pages and some administrative functions, you may need torefresh the page to display any new or updated information. For example, if youadded a new business entity to your organizational structure and did not see thenew entity displayed on the Business Entity Overview page, click the Refresh iconto refresh the page and display the updated information.

Procedure

To refresh information on a page, click Grid Actions > Refresh.

Revoking signaturesIf this feature is configured, you can revoke a signature or sign off on a signaturethat you manually added. You can only revoke a signature that you created.

About this task

To unlock an object with a signature lock and retain the signature, you must havethe necessary permissions. See your system administrator for assistance. Allsignature locks (including inherited locks) must be removed from an object beforeit can be edited. To remove an inherited lock, revoke the signature from theparent object.

Procedure1. Open the detail page of the object.2. In the Associations section, click Signatures.3. From the listing pane, click the name of the signature to revoke.4. From the detail pane of the signature, click Actions > Revoke this.5. On the Comment panel, type a comment.6. Click Revoke.

Using jobsThis topic provides information about jobs.

How do I...

v Start a job from an object?v Use the My Jobs lists?v View job details?v Add a file or link to a job?v Disassociate an object or file?v Terminate a job?

Tell me about...v What is a job?v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

44 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 57: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Setting preferences for alert notificationsNotifications alert you of some action that was taken on a page. By default,notifications are disabled. When you modify notification settings, the change isapplied immediately to all object types.

About this task

You can set preferences for the notifications you want to receive on objects andfields. For example, you could set a notification that alerts you when an object issuccessfully created or deleted.

Expand the alert notification window to see multiple messages. Keep the alertnotification dialog open so that notifications are always visible.

Procedure1. From user name drop-down box on the menu bar, click My Settings.2. In the Alert Notification Settings pane, click Edit.3. In the Notifications field, enable each option to activate.4. Click Apply.

Submit jobsWhen you submit a job, the workflow process for the job is initiated.

Before you begin

When you submit a job from a view page, the workflow process for that job isinitiated.

You can view the details of a submitted job from the My Jobs pane on the homepage or from a grid view. You can only submit a job for the top level objects orfrom the Automation Jobs link on a detail view page.

You can submit a workflow job from an Object detail view page, a Filter list viewpage, a Folder list view page, or a grid view.

Note: Only users with assigned permission are allowed to submit jobs.

Submitting Jobs from a Filter List View or Grid ViewWhen you submit a job from a view page, the workflow process for that job isinitiated.

Procedure1. From the menu bar, select the object type.2. If necessary, select Filter List View from the View drop-down list.3. Select each object to submit to a workflow job.4. Click Submit.5. In the Job pane, click Job Name and select a job.6. Click Submit.

Chapter 9. Managing my work 45

Page 58: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Submitting Jobs from a Folder ViewYou can submit a job from a folder view.

Procedure1. From the menu bar, select the object type.2. If Folder View is not displayed, click Filter List View and select Folder View.3. Select the object to submit to a workflow job.4. Click Submit.

Submitting Jobs from a Detail ViewYou can submit a job from a detail view page.

Procedure1. From the menu bar, select the object type to open.2. Click the object type name to open its detail page.3. To submit a job for the object, complete the following steps:

a. If the fields are not displayed, click Field in the navigation pane underDetails.

b. From the detail pane, click Actions > Submit this item.4. To submit a job for an associated child object, complete the following steps:

a. From the Associations section, select the object type to submit.b. From the listing pane, click the name of the object to submit.c. From the detail pane of this associated object, click Actions > Submit this

item.5. Click Submit.

Terminating jobsUse this procedure to stop a job.

Procedure1. From the menu bar, select the object type to open.2. Click the object type name to open its detail page.3. In the navigation pane under Details, click Automation Jobs.4. From the listing pane, click the name of the job to end.5. On the Job Details pane, click Terminate.6. Type a comment and click Terminate.

46 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 59: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 10. Editing objects

Downloading files for editBefore you can edit a file that is under revision control, first download the file toyour local system. Then, open and edit the file.

About this task

If you are using File Check out, first check out the file.

Procedure1. To locate the file to edit, complete one of the following steps:v From the menu bar, click My OpenPages > Browse. Expand the folder and

locate the file.v Click My OpenPages > Files. For a Filtered List View page, select a filter to

quickly locate the object. For a Folder View page, expand the folderhierarchy and locate the file.

2. Click the name of the file to download.3. From the detail pane, click View file to open the File Download window.4. Click Save.

Copying objectsYou can copy an existing object to quickly create an object with similar values.

Procedure1. From the menu bar, select the object type to view.2. From the list of objects, click the name of the object to select.3. From the navigation pane, click the object to select.4. Select the object to copy.5. Click Actions > Copy an existing item.6. Type a name for the new object.7. To copy associated files, enable the option8. To copy associated issues, enable the option.9. Enable one of the following options to determine how to resolve file naming

conflicts:v Create a new version of the new object in the destination directory.v Create a new object whose name is prefixed with “Copy of”.v Do not copy resources with naming conflicts.

10. Click Finish. A duplicate instance of the object is created and listed on theparent object detail page.

Editing objects in Grid or Filtered List ViewYou can edit fields for a single object from a Grid view or a Filtered List view.

47

Page 60: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Before you begin

Consider the following information before you edit an object in grid view:v You cannot edit the following object fields: Folder, Creation Date, Created By,

Last Modification Date, Last Modified By.v Remove all signature locks, including inherited locks, before you edit an object.v If you and another user simultaneously edit the same object, or if an object

changes after you retrieve it, an error message notifies you of a conflict.v Opening an object in a new browser window to copy field data between

browser tabs or windows might cause unspecified results.v If you scroll more than a few rows away from the row you are editing, the edits

are canceled.v You can edit an item that is associated with an object from the object page.

Procedure1. Open the object type from the menu bar.2. Click the name of the object to edit.3. Click Action > Edit this Item.4. Edit the fields, as needed.5. Click outside the row to save your changes.6. To edit an item that is associated with the object, click the item in the

navigation menu in the Association section. The number in parenthesisidentifies how many items exist in a category.

7. Click Action > Edit this Item.8. Edit the fields, as needed. Click Save.

Copying file linksFiles that are uploaded and stored in the file repository have a URL link to the file.You can copy and paste the link into another application, such as email orMicrosoft Word, or onto your desktop.

Procedure1. Open the detail page of the object.2. In the pane under Attachments, click Files.3. From the listing pane, click the name of the file.4. From the detail pane, drag the link to the new location, for example, to your

desktop or to an email.

Deleting objectsYou can delete a folder, file, business entity, or other object from the currentreporting period.

About this task

An object must be unlocked before it is deleted. After you delete an object, itcannot be recovered. However, if the deleted object was included in a previousreporting period, you can view details that are associated with that object throughreports. Folders that are generated by the system cannot be deleted. Consider thefollowing information before you delete an object:

48 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 61: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v When you delete a parent object, any child objects, associated issues, or actionitems are also deleted.

v When you delete a business entity, child objects, associated objects, or subentitiesthat are in the same folder, including attached external documents, are deleted.

v If you delete a control object, any associated tests and attached externaldocuments are deleted.

v Make sure that all important information that is contained in an associated testis preserved before you delete a control.

v You might be able to delete only objects in a folder and not the folder. If you areallowed to delete a folder, all contents are deleted. For a file, all versions aredeleted.

v If the file Check In/Check Out feature is configured, a file must be checked inbefore it can be deleted.

Procedure1. From the menu bar, select the object type.2. If the Detail View page is enabled but not displayed, from the View field, select

Detail View.3. Select each object to delete and click Grid Actions > Delete.4. Click Delete to verify the deletion.

Associating objectsDepending on the object type, you might be able to link multiple parent or childobjects to it. For example, a Risk object can have multiple parent objects, such asControl Objectives and Risk Assessments, child objects such as Controls and Issues,and files and links. Associations can be created or removed without affecting therelated object or file.

Procedure1. From the Filter List View, select a search filter to narrow the list of objects that

are displayed.2. Click the name of the object to view.3. In the navigation pane under Associations, click the object type to associate.4. Click Actions > Associate an existing item.5. From the list of objects, select each object that you want to associate and click

Associate Selected.6. To open the newly associated object, click its name in the list.

Disassociating objectsYou can associate a child or parent object, file, or link to an object. For example,from a Risk object, you can add links to parent objects, such as Control Objectivesand Risk Assessments. You can also remove links to child objects, files, or links.

About this task

When you disassociate an object, only the association or link between the objects isremoved. The objects remain unaffected.

Chapter 10. Editing objects 49

Page 62: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. From the menu bar, select the object type.2. Click the name of the object to view.3. Click Actions > Edit this item.4. Under Associations, select the item to disassociate from the object.5. Click Disassociate selected item.6. Click Continue to confirm the action.

Moving objects to a different folderYou can change how objects, files, and links are grouped. You can reorganizeobjects by moving them into a folder, or from one folder to another.

About this task

You cannot move folders to the top level after you move them to a different levelwithin the hierarchy. To move a folder to the top level, create a new top levelfolder with the same name and move the existing folder to the newly createdfolder. If the Check In or Check Out feature is enabled, you cannot move achecked-out file. You cannot move a self-contained object to another folder.However, you can move it and associate it with any of its parent object types.Folders that are generated by the system cannot be moved.

Procedure1. From the menu bar, select the object type.2. If the Detail View page is enabled but not displayed for the object, click the

Current View arrow and select Detail View.3. Select each object to move.4. Click Grid Actions > Move To.5. On the selection page, expand the folder hierarchy.6. Depending on your configuration, perform one of the following actions:v Enable the check box next to the name of the destination folder.v Enable the check box next to the parent object where the current object is

moved and associated.7. Click OK.

Locking objectsWhen you add a lock to an object, a lock icon is displayed next to the name of thelocked object. An inheritance lock icon is displayed next to the name of anyassociated child objects.

About this task

You can lock only first-level objects.

Procedure1. From the menu bar, select the object type.2. If the Detail View page is enabled but not displayed for the object, click

Current View and select Detail View.

50 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 63: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

3. If the fields are not displayed, click the Fields link under the Details section inthe navigation pane.

4. From the detail pane, click Actions > Lock this Item.5. To lock an associated object (child or parent), complete the following steps:

a. In the navigation pane under Associations, click the object type to lock.b. From the listing pane, select the object to lock.c. From the detail pane of the object, click Actions > Lock this.

6. To view lock details, click Details > Locks.

Adding a child object from a detail pageExcept for top level parent objects, objects can be created from the detail page of aparent object. You must first select the parent object and then you can add anobject.

About this task

You can create a child object that is associated with a parent object.

Important: Opening an object in a new window or tab to copy data betweenbrowser tabs or windows might cause unspecified results.

Attention: An object can be created quickly from the home page by inheriting thevalues that are defined in an existing object. See “Adding an object instance withthe Add New wizard” on page 14.

Procedure1. From the menu bar, select the object type to access.2. Click the name of the parent object. The Detail View opens.3. Click the object type to create from the Associations section.4. Click Action > Add a new item where item is the name of the object type to

create.5. On the Create tab, click either Create from scratch or, to use an existing object

instance as a template, click Create from existing.If you want to use an existing object instance, you can select the object usingone of the following methods:v Select an object from the Recently Used tab.v Find an object by using one of the following options on the Search tab:

– Type a term in the Search field to find an exact match to the object nameor description.

– Run a saved filter from the Filter list.The list of filters available is the same as the saved filters you see on theFiltered List View. When you run a saved filter from here, the resultsmight differ because you see only objects that can be associated with thecurrent object. When you run a saved filter from the Filtered List View,you see all objects for which you have read access.

You can refine the list of existing objects shown in the search results by usingthe Narrow by options. For example, to show only objects in a specificfolder, type the folder name in the Folder field.

Click Next.

Chapter 10. Editing objects 51

Page 64: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Depending on the object type or the permissions assigned to you from youradministrator, the Create tab might not appear.

6. To identify the parent object to associate with the new object instance, on theParent tab, select an object using one of the following methods:v Select an object from the Recently Used tab.v Find an object by using one of the following options on the Search tab:

– Type a term in the Search field to find an exact match to the object nameor description.

– Run a saved filter from the Filter list.The list of filters available is the same as the saved filters you see on theFiltered List View. When you run a saved filter from here, the resultsmight differ because you see only objects that can be associated with thecurrent object. When you run a saved filter from the Filtered List View,you see all objects for which you have read access.

You can refine the list of existing objects shown in the search results by usingthe Narrow by options. For example, to show only objects in a specificfolder, type the folder name in the Folder field.

If you are creating from a parent object, it might not be necessary to select aparent.

7. Move through each of the object-specific tabs in the wizard by clicking the tablabels or using Next and Previous, and complete all of the required fields.Required fields are marked with an asterisk (*). A white circle next to a tablabel indicates that all the required fields for that tab are not complete or failedvalidation.

Note: Required and optional fields vary depending on the object type.8. Click Save.

You cannot save until all required fields are completed with valid values. IfSave as Draft is enabled by your administrator, you can save a draft of thenew object instance without completing all the required fields in the wizard.

Rename an objectYou can rename objects and folders from the Folder view. You can rename objectsfrom the Detail view. Depending on your configuration, this applies toself-contained objects only. You can only rename objects in a folder and not thefolder itself.

About this task

Objects that reside in the same folder must have a unique name. When yourename a folder, its contents (primary associations) will also be moved to therenamed folder. If the Check In/Check Out feature is enabled, you can onlyrename a file that is checked in. Folders that are generated by the system cannot berenamed.

Use one of the following procedures to rename an object:v Renaming an Object or Folder From a Folder View Pagev Renaming an Object From an Object's Detail Page

Renaming an Object From an Object Detail PageUse this procedure to rename an object from an Object Detail page.

52 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 65: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. Navigate to the detail page of the object.2. In the navigation pane under Details, click Fields to display the fields.3. From the detail pane, select Actions > Edit this Item.4. To rename an associated object (child or parent), in the navigation pane under

Associations, click the object type you want to edit. From the listing pane, clickthe name of the object you want to rename. From the detail pane, selectActions > Edit this. Type a new name for the object.

5. Click Save.

Renaming an Object or Folder From a Folder View PageUse this procedure to rename an object or folder from a Folder View Page.

Procedure1. Select the object type from the object menu.2. If Filter List View is displayed, click it and select Folder View.3. Expand the object hierarchy to locate the object or folder in the tree.4. Select the object or folder that you want to rename.5. Click Rename.6. In the Name field, type a new name for the object or folder.7. Click OK.

Chapter 10. Editing objects 53

Page 66: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

54 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 67: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 11. Working with objects

Business entities

Business entitiesBusiness entities are abstract representations of your business structure. A businessentity can contain sub-entities (such as departments, business units, or geographiclocations). The entity structure that you create depends on your business needs.For example, you could create a parent entity for your business headquarters and asub-entity for each location or department. You might also want to represent botha legal entity structure and a business entity structure.

Business entities are also used to organize library data such as risk and controllibraries, or regulatory content (for example, laws, regulations, and standards).

When setting up your business entity hierarchy, work with your IBM OpenPagesGRC consultant. The structure of your business entities impact the type andquality of information that can be extracted from the application.

In IBM OpenPages Internal Audit Management, Business Entities also model theInternal Audit organizational structure, which facilitates reporting and security forthe Internal Audit team. The Internal Audit organizational structure is a top levelentity to minimize the chance of accidentally granting a business user access toInternal Audit information. The elements of the Audit Universe that are owned byan Internal Audit team are associated with the team Business Entity. Another toplevel Business Entity structure can be created to organize confidential Audits,providing special security to these Audits. Business Entity can also be used toorganize a Library of template audit content.

Business Entities OverviewUse the links in this topic to access frequently asked questions about the BusinessEntities Overview information.

How do I...

v Add a Business Entity?v Navigating to an Object Detail Page?v Select a different report period for this view?

Tell me about...

v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Filtered List ViewThis topic provides links to information about the Filtered List View.

55

Page 68: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Business Entities Folder ViewThis topic provides information about the Business Entities Folder View page.

How do I...v Add a folder?v Navigate to a Detail page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Business Entities Detail ViewThis topic provides links to frequently asked questions about the Business EntitiesDetail view.

56 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 69: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I add...v “Adding an object instance with the Add New wizard” on page 14v Files, form or link to a business entity?v Signature and comment to a business entity?v Associate or disassociate an object with a business entity?v Edit a Business Entity?v “Copying objects” on page 21v Delete an associated object from a business entity?v Lock or unlock an object?v Unlock all objects within an object?v “Navigating to an object's detail page” on page 21v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job from a business entity?

How do I view...v Locks for a business entity?v Change history (audit trail) for a business entity?v Signatures for a business entity?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Adding a parent object from the Grid ViewIf needed, you can add a parent object from the Grid View.

About this task

Procedure1. Select the object type from the object menu.2. Click Grid Actions > Add New.3. On the Create tab, click either Create from scratch or, to use an existing object

instance as a template, click Create from existing.If you want to use an existing object instance, you can select the object usingone of the following methods:v Select an object from the Recently Used tab.v Find an object by using one of the following options on the Search tab:

– Type a term in the Search field to find an exact match to the object nameor description.

– Run a saved filter from the Filter list.The list of filters available is the same as the saved filters you see on theFiltered List View. When you run a saved filter from here, the resultsmight differ because you see only objects that can be associated with the

Chapter 11. Working with objects 57

Page 70: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

current object. When you run a saved filter from the Filtered List View,you see all objects for which you have read access.

You can refine the list of existing objects shown in the search results by usingthe Narrow by options. For example, to show only objects in a specificfolder, type the folder name in the Folder field.

Click Next.Depending on the object type or the permissions assigned to you from youradministrator, the Create tab might not appear.

4. Move through each of the object-specific tabs in the wizard by clicking the tablabels or using Next and Previous, and complete all of the required fields.Required fields are marked with an asterisk (*). A white circle next to a tablabel indicates that all the required fields for that tab are not complete or failedvalidation.

Note: Required and optional fields vary depending on the object type.5. Click Save.

You cannot save until all required fields are completed with valid values. IfSave as Draft is enabled by your administrator, you can save a draft of thenew object instance without completing all the required fields in the wizard.

List Views

A List view displays objects of the same type in a list format, with objects listed inascending order. Depending on the object type, List Views can be displayed aseither a page or a pane.

By default, List Views are displayed as pages for the following object types:Business Entities, Milestones, and Milestone Action Items, and as panes on a Detailview page for listing associated parent or child objects.

If you have a Folder or Filtered List view for Business Entities, the default Listview for this object type is not used.

Unlocking all objectsYou can unlock all objects within a business entity or only the business entity.

About this task

Any signature on an unlocked object remains in effect and is NOT revoked. Beforeyou unlock an attached file, check it in.

You can unlock objects in a Business Subentity even if its parent Business Entity islocked. Use the unlock all operation if the remove locks option was not selectedafter a finalized reporting period. You can also use unlock all for different BusinessSubentities, such as a multinational organization, that has different reportingperiod closure dates during the year.

Procedure1. Click Organization > Business Entities. Click the name of the business entity

to unlock.2. To unlock all subentities, click Actions > Unlock All.3. To unlock only the business entity, click Actions > Unlock this Business Entity.

58 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 71: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Risk assessments

Risk assessmentsRisk assessments give you the ability to evaluate and report potential liabilities fora set of business entities or processes. A Risk Assessment object contains the namesof the assessor and reviewer, the assessment time frames, and the status of theassessment. Use a Risk Assessment to manage the risk self-assessment process.Associate Risk objects with a Risk Assessment to create a link between the businessentity and the Risks. For example, create a Risk Assessment to assess operationalrisks, such as external theft and fraud, internal fraud, physical property damage, orbusiness disruption.

Risk Assessments OverviewThis topic provides information about the Risks Assessments Overview page.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Chapter 11. Working with objects 59

Page 72: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risk Assessments Folder ViewThis topic provides information about the Risk Assessments Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risk Assessments Detail ViewThis topic provides information about the Risk Assessments Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?

60 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 73: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risk assessment evals (evaluations)

Risk assessment evalsRisk Assessment Evaluation objects are similar to Risk Evaluation objects exceptthat they are instantiated as children of Risk Assessments. They store riskassessment data.

Risk Assessment Eval (Evaluation) Detail ViewThis topic provides links to frequently asked questions in the Risk Assessment EvalDetail view.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Filtered List ViewThis topic provides links to information about the Filtered List View.

Chapter 11. Working with objects 61

Page 74: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control objectives

Control objectivesA Control Objective is an assessment object that defines the risk categories for aProcess or Sub-Process.

Control Objectives define the COSO compliance categories that the Controls areintended to mitigate. Control Objectives can be classified into categories such asCompliance, Financial Reporting, Strategic, Operations, or Unknown.

After a Control Objective is identified, the Risks belonging to that ControlObjective can then be defined. In most cases, each Control Objective has one Riskthat is associated with it. However, it might have more than one Risk that isassociated with it. For example, a financial services company employs traders thatare aware of the required ethical standards. The HR department sets up a controlobjective called 'Personnel'. A risk that is associated with the Control Objective is,“Employees engage in business dealings that conflict with the company objectivesfor ethical and fair trading.”

By default, an OpenPages Internal Audit Management Control Objective isdisabled. This object is not often used, except to align with other solutions thatmight use it.

Filtered List ViewThis topic provides links to information about the Filtered List View.

62 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 75: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Objectives Folder ViewThis topic provides information about the Control Objectives Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Objective Detail ViewThis topic provides information about the Control Objective Detail View.

Chapter 11. Working with objects 63

Page 76: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Processes

ProcessesProcesses represent the major end-to-end business activities within a businessentity that are subject to risk. Processes reside in areas such as financial reporting,compliance, and information security. For example, Processes in the AccountsReceivable department such as order-to-cash could be improved with controls toprotect against financial reporting risks such as fraudulent behavior or financialreporting inaccuracies.

In OpenPages Internal Audit Management, Processes are also used in scopingaudits. Audits can copy Processes that are created by the business entity, or createtheir own Processes.

Processes OverviewThis topic provides information about the Processes Overview page.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?

64 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 77: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Processes Folder ViewThis topic provides information about the Processes Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Chapter 11. Working with objects 65

Page 78: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Processes Detail ViewThis topic provides links to frequently asked questions about the Processes DetailView.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Process evals (evaluations)

Process evalsProcess Evaluation objects are children of Process objects and they are used tocapture process measurement values for trending purposes.

When the reporting periods do not align with the evaluation cycles, you can useProcess Eval objects to capture multiple evaluation cycles within a single reportingperiod.

66 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 79: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Process Evals (Evaluations) Folder ViewThis topic provides links to information about Process Evals Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 11. Working with objects 67

Page 80: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Process Evals (Evaluations) Detail ViewThis topic provides links to information about Process Evals Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Processes

Sub-ProcessesA Sub-Process is a component of a Process. It is used to divide Processes intosmaller units for assessment purposes. For example, an order-to-cash financialProcess might be composed of several Sub-Processes such as accounts payable,purchasing, and general accounting. Any of these Sub-Processes might expose theBusiness Entity to risk and can be improved, using controls.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filter

68 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 81: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Processes Folder ViewThis topic provides information about the Sub-Processes Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Processes Detail ViewThis topic provides information on the Sub-Processes Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?

Chapter 11. Working with objects 69

Page 82: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Controls

ControlsControls are policies and procedures that make sure that risk mitigation responsesare performed.

After identifying the risks that occur in your practices, establish controls, such asapprovals, authorizations, and verifications. These controls remove, limit, ortransfer these risks.

Controls provide either prevention or detection of risks. Controls are associatedwith tests that ensure that a control is effective. For example, the human resourcesdepartment identifies a risk in the new hire process. The process does not complywith regulations and guidelines for diversity and discrimination. Define controls tomitigate this risk, such as, establish hiring policies and procedures, and conductmandatory training for hiring managers.

In IBM OpenPages Internal Audit Management, use Controls to create a detailedmodel of the Controls that exist or that you want to enforce on the activities thatare audited. If shared with the Business, the Controls can be rated separately byInternal Audit and by the Business.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29

70 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 83: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Controls Folder ViewThis topic provides information about the Controls Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Controls Detail ViewThis topic provides information about the Controls Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?

Chapter 11. Working with objects 71

Page 84: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Evals (Evaluations)

Control evalsControl Eval objects are similar to Risk Evaluation objects except that they arecreated as children of Controls. They store control assessment data. When reportperiods and control assessment evaluation cycles are not aligned, use Control Evalobjects to capture multiple evaluation cycles within a single reporting period.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21

72 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 85: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Evals (Evaluation) Folder ViewThis topic provides information about Control Evals Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Evals (Evaluation) Detail ViewThis topic provides information about Control Evals Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

Chapter 11. Working with objects 73

Page 86: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risks

RisksRisks are potential liabilities. Risks can be associated with business processes,business entities, or a compliance with a mandate. Each risk has controls thatprovide safeguards against the risk. The controls help lessen consequences thatresult from the risk. Use the Risk object to categorize risks; capture the frequency,rating, and severity of observed and computed risk data; and view reports toidentify top risk items. For example, the Cash account has a process called Payroll.A potential risk that might occur in the payroll is a duplicate payrolldisbursements or the creation of fictitious payroll disbursements. Identifying risksin processes is a key component of developing a financial controls documentationproject.

In OpenPages Internal Audit Management, a Risk that is shared between aninternal audit and the business can be rated separately.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

74 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 87: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risks Folder ViewThis topic provides information about the Risks Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risk Detail ViewThis topic provides information about a Risk Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?

Chapter 11. Working with objects 75

Page 88: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risk evals (evaluations)

Risk evalsRisk Evaluation objects are children of Risk objects and they are used to capturerisk measurement values for trending purposes. Often reporting periods do notline up with risk evaluation cycles and so Risk Eval objects can be used to capturemultiple evaluation cycles within a single reporting period.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risk Evals (Evaluations) Folder ViewThis topic provides links to information about the Risk Evals Folder View.

76 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 89: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Risk Evals (Evaluation) Detail ViewThis topic provides links to information about the Risk Evals Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 11. Working with objects 77

Page 90: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Test plans and test results

Test plansA Test Plan is a container for tests and can be associated with parent Controlobjects and child objects, such as Test Results and Issues. Determine the operatingeffectiveness of a Control by conducting detailed tests and then documenting theresults. Test Plans describe the mechanisms that determine if a Control is effective.For example, a sample Control is: “Human Resources authorizes changes inemployee status.” A test for this control might be: “Verify HR authorization stampon new employee records.” The test verifies that the new Control is implementedand in use.

The default OpenPages Internal Audit Management configuration uses theWorkpaper object in place of the Test Plan and Test Result. The Audit object needsaccess to these objects because they are often used to document business testing.

Test ResultsA Test Result is the information obtained from running a test plan.

The default OpenPages Internal Audit Management configuration uses theWorkpaper object in place of the Test Plan and Test Result. The Audit object needsaccess to these objects because they are often used to document business testing.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

78 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 91: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Test Plans or Test Results Folder ViewThis topic provides information about Test Plans and Test Results Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Test Plan or Test Results Detail ViewThis topic provides information about the Test Plan or Test Results Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

Chapter 11. Working with objects 79

Page 92: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Issues and Issue Action Items

Issue and action itemsAlthough issues are generated in areas where internal controls are not properlyimplemented, use the Issue object to document a concern associated with anyobject type. For example, a Test is associated with a Control, but the Test failed thelast time it completed. This potential problem can be highlighted by capturing it inan Issue object.

An Issue is resolved through Action Items. You can use an Action Item or a seriesof related Action Items to form an Action Plan. Each Action Item is assigned to auser for resolution, and tracks progress. After all Action Items for an Issue arecomplete (when an assignee sets the value to 100%), close the Issue.

In OpenPages Internal Audit Management, Issues and Action Items can be usedinstead of, or with, Findings.

Adding comments to an action itemYou can use the same procedure to view or add comments to an Issue Action Itemor a Milestone Action Item.

Before you begin

From the detail page of an action item, you can add comments to the action item.After you save a comment, it cannot be edited or deleted.

Procedure1. Open the detail page of the parent object:

a. To add an Issue or Action Item, select the Remediation menu and chooseIssues or Action Items.

b. To add a Milestone Action item, select the My OpenPages menu and chooseProject, My Milestone Action Items.

2. Click the name of the action item to edit.3. To add a comment, complete the following steps:

a. From the Details pane of the action item, click the Fields link, if the fieldsfor the selected object are not already displayed.

b. Click Edit.c. Add a comment in the Comment field and click Save.

4. To view a chronology of comments, from the Details pane of the action item,click the Comments link.

Completing action itemsYou can select a percentage in the Percent Complete field of an Issue Action Itemor Milestone Action Item object to identify your progress or completion of theassigned action item. To show that you have completed an action item, set thepercentage complete to 100%.

80 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 93: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. From the menu bar, click Remediation > Action Items.2. Click the name of the action item to view.3. Click Actions > Edit This Action Item.4. In the Percent Complete field, type 100%.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Issues and Action Items Folder ViewsThis topic provides information about Issues and Action Items Folders View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Chapter 11. Working with objects 81

Page 94: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Issues and Action Items Detail ViewThis topic provides information about the Issues and Action Items Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Preferences groups and preferences

Preferences and preferences groupsThe Preference object is a child of a Business Entity, and includes variable valuesthat can drive reports, workflows, and computed fields. It has entity-specificvariable values that enable different behavior for the same workflows. Forexample, define variable values to determine the behavior for review and approvalworkflows such as the appropriate users for each level of review and approval,and the thresholds for determining how many levels of review and approval arerequired.

82 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 95: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

The Preference Group is used to group Preference objects together. Without thisgrouping object, each Preference object must be associated separately with eachrelevant Business Entities. The Preference Group helps minimize the associatedmaintenance.

In the default IBM OpenPages Internal Audit Management configuration, theseobjects are used to hold weights for Risk Factors used in Annual Assessment RiskRanking. Since the weights and factors can be different for each type of audit, suchas financial, operational, or strategic, create a separate Preference instance for eachaudit type. As a child of Business Entity, this approach provides the ability to haveentity-specific variable values.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Preference Groups and Preferences Folder ViewThis topic provides information about the Preference Groups and PreferencesFolder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?

Chapter 11. Working with objects 83

Page 96: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Preference Groups and Preferences Detail ViewThis topic provides information about Preference Groups and Preferences DetailView.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Files, forms, and links

Browse attachmentsThe Browse Attachments page displays a hierarchy of folders for all files (such asdocuments, forms, and links) in the IBM OpenPages GRC Platform file repository.

84 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 97: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Attach a file from the Detail View page of a parent object. Depending on yourconfiguration, you may also be able to add standalone document files from theBrowse Attachments page that you can later associate with parent or other objects.From the Browse Attachments page, you can view, add, delete, move, and renamefiles and folders.

File attachments that are modified and then uploaded to the OpenPages GRCPlatform file repository have a new version automatically created. You can retrievean older version of a file without losing the current version. Files that are stored inthe file repository also have a View File link on their File Detail page. You can usea drag-and-drop or cut-and-paste operation to copy a View File link from the fileinto another application (such as e-mail or a Microsoft Word document).

If an object contains a URL link to an external destination (such as a Web site orfile), the link is displayed on the detail page of that object and not on the BrowseAttachments page. When a user clicks the external link, a new window opens anddisplays the contents of the target destination. If you link to files or documentsthat are maintained outside the OpenPages GRC Platform file repository, unlessexternal security controls are in place, these files or documents will not be underversion control. Typically, you add a link from the detail page of a parent object.

If the file Check In/Check Out feature is configured for your system, the file islocked while it is checked out for editing and unlocked when it is checked in sochanges are not inadvertently overwritten by another team member.

Adding or attaching files from the detail pageWhen you add a standalone file or attach a document file to an object, a copy ofthe file is uploaded to the file repository. You can upload any type of file. Somecommon file types for upload include: text (.txt), web pages (.htm or .html),Microsoft Word (.doc), PowerPoint (.ppt), Excel (.xls), and Visio (.vsd).

Procedure

Complete the following steps to add a file to an object from the Detail page:1. Navigate to the Detail View of the parent object.2. In the navigation pane, click Files.3. On the listing pane, select the Actions > Add a new File.4. Click Browse and select the file to upload.

Adding files from the Folder View or Browse Attachmentsoption

You can add files to an object from the Browse Attachments or Files Folder Viewpage.

Before you begin

You must have permission to add a file to an object. When a file is added, it isuploaded to the repository and is listed on the Browse Attachments page under theselected folder.

Procedure1. To locate and add a file as an attachment to an object, complete the following

steps:

Chapter 11. Working with objects 85

Page 98: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

a. Click My OpenPages > Browse.b. Select the folder where the file is added and click Add File.

2. Complete the following steps to add a file from the File Folder View:a. Click My OpenPages > Files.b. Select the folder where the file is added and click Add New.

3. Click Browse and select the file to upload.4. Click Create.

Attachments: browse, files, linksThis topic provides information about attachments, including the browse, files, andlinks functions.

How do I add...v “Adding folders” on page 16v “Adding files to tasks or jobs” on page 87v “Adding or attaching files from the detail page” on page 85v “Adding URL links to object views” on page 89

Editingv “Editing file descriptions” on page 20v “Uploading a new version of a file” on page 90v “Checking in a file” on page 88v “Navigating to an object's detail page” on page 21v “Moving objects to a different folder” on page 50v “Reassigning primary parents” on page 43v “Viewing files or links from the detail page” on page 37

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

File check in and check outIf the File Check In and Check Out feature is configured, you can check out a fileand lock it and edit it. When you are finished with the file, you then check in andunlock the file.

When you work in a collaborative team environment, the File Check In and CheckOut feature allows only one person to work on a file at one time. Changes will notbe overwritten by another team member. A checked-out file has the followingcharacteristics:v A check mark is displayed next to the file name.v The name of the person who checked out the file is displayed.v The file is listed in the My Checked Out Files pane on the home page.v The file is locked.v The file can be viewed and downloaded by others, associated with objects, and

copied to an object.

86 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 99: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

FormsForms help automate the capture of data and are customized for your business.

Forms that are associated with particular object types (such as the Process Survey)automate the capture of data through a series of targeted questions.

The type of forms available on your system depends on your system configuration.

Forms can be attached to an object and then filled out by users. When you fill outa form, you will either have to create a new instance of that form from an existingtemplate, or a survey task will be assigned to you.

Adding a formAdd a new form (or survey) from the detail page of an object. The process foradding a form to an object is the same for all objects.

Procedure1. Select the object type from the object type menu.2. Click the name of the object to navigate to the detail page.3. In the Attachments section, click Files.4. Click Actions > Add a new File.5. Select the file to add and provide a description of the file.6. Click Save.

Adding files to tasks or jobsWhen you add a file to a task or job, first add it to a folder in the file repositoryand then associate it with the task or job.

Procedure1. From the global header, click Home.2. From the My Tasks or My Jobs pane, click the name of the task or job where

the file will be added. If the task or job is not displayed, click View Details toview all items and then click the name.

3. In the Attachments pane of the task or job, click Add File.4. Click Browse and select the file to add.5. Click Create. The new file is associated with the task or job.

Copying a View File linkDocument files that are uploaded and stored in the IBM OpenPages GRC Platformfile repository have a link to the URL of the file.

About this task

Copy and paste the link into another application, such as email or Microsoft Word,or onto your desktop.

Procedure1. Navigate to the detail page of the object.2. Under Attachments, click Files.3. From the listing pane, click the name of the document or file.

Chapter 11. Working with objects 87

Page 100: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

4. From the detail pane of the document or file, drag the link to the new location,for example, to your desktop or an e-mail.

5. If prompted to copy the link, click Yes.

Checking out a fileBefore you can edit a file that is stored in the repository, you must first check itout.

Procedure1. Click My OpenPages > Browse.2. From the list, click the name of the file to check out.3. From the detail pane of the file, select Actions > Check out this File. When a

file is checked out, it is added to the My Checked-Out Files list on your homepage.

Checking in a fileWhen you complete revisions to a file, check in the changed file to the IBMOpenPages GRC Platform file repository. The name of the file you check in mustmatch the name that was checked out.

Procedure1. Locate the checked-out file.2. From the object detail view page, go to the detail page.3. Under Associations, click Files.4. From the list, click the name of the checked-out file.5. In the navigation pane under File Details, click Fields if the field details for the

selected file are not displayed.6. From the detail pane of this file, click Actions > Check in this File.7. Click Check in

Canceling a file checkoutIf you accidentally check out a file, or realize that you do not want to save changesto a checked-out file, you can cancel the checkout process.

Procedure1. Open the detail page of the object to check in.2. In the navigation pane under Associations, click Files.3. From the list, click the name of the file.4. Under File Details, click Fields.5. Click Actions > Cancel Check out for this File.

Using files, forms, and linksThis topic provides a list of procedures to complete when using files, forms, andlinks.

How do I Add?

v Folder or sub-folder?v New file to a task or job?v External link (URL) to an object?

88 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 101: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v External link (URL) to a task or job?

Edit a:

v File?v Description of a file?v Upload a new version of a file?v Check out or check in a file?

Adding URL links to object viewsAn external link is a URL that opens a browser window and displays the contentsof that target destination. A copy of the external link is stored in the IBMOpenPages GRC Platform file repository.

About this task

To attach an external link from an object detail view page, complete the followingsteps:

Procedure1. Navigate to the detail view page of the parent object.2. In the navigation pane under Attachments, click Links.3. Click Actions > Add a new Link, and complete all required fields.

Add a link to a task or a jobWhen you add a URL that links to an external destination (such as a Web site orfile) to a task or job, you must first add it to a folder in the file repository and thenassociate it with the task or job.

About this task

This information is displayed on the My Tasks panel on the home page, if it isconfigured.

The external hyperlink is displayed on the details page of the task or job under theAttachments tab. When you click the hyperlink, the Link Summary page isdisplayed. From the Link Summary page, you can click the URL to open a newwindow and display the contents of the target destination.

If you link to files or documents that are maintained outside the IBM OpenPagesGRC Platform file repository, no version control is maintained unless externalsecurity controls is configured.

Procedure1. Click Home from the global header.2. From the My Tasks or My Jobs panel, click the name of the task or job to which

you want to add a file or URL.

Note: To display more tasks, click View Details to display a page that lists allassigned tasks.

3. On the Attachments pane of the task or job, click Add File to open the AddFile wizard or Add Link to open the Add Link wizard.

Chapter 11. Working with objects 89

Page 102: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

4. Select a target folder. Expand the hierarchy in the file repository as necessary toview the folders in the tree.

5. Expand the folders as necessary, to view folders. Do one of the following:v To add a file to an existing folder, select the check box next to the folder to

contain the new file.v To add a file to a new subfolder, do the following:

a. Click Add Folder.b. Type a name and description for the folder and click OK.

c. Select the check box next to the folder you created.v Select the file - click Browse and navigate to the file you want to upload.

6. To add a link, provide a name for the link, select the folder where the link isadded, and type the URL.

7. Click Finish.

Uploading a new version of a fileIf you are not using the file Check In/Check Out feature, you can revise a file onyour local system and upload a new version of that file. The uploaded filebecomes the current version. The previous version is also available and can beviewed.

Procedure1. From the Associations section of the navigation menu, click Files.2. Click the name of the file.3. If you are on a File Details page and the Actions menu is not displayed, click

Fields in the navigation pane under Details. The Details pane for the file isopened.

4. In the navigation pane under Details, click Versions.5. From the detail pane of this file, click Actions > Upload New Version.6. On the upload page, click Browse and located the edited file. The name of the

new and previous version of the file must match.7. Click Save. The new version of the file is listed in the Versions pane.

Adding a formAdd a new form (or survey) from the detail page of an object. The process foradding a form to an object is the same for all objects.

Procedure1. Select the object type from the object type menu.2. Click the name of the object to navigate to the detail page.3. In the Attachments section, click Files.4. Click Actions > Add a new File.5. Select the file to add and provide a description of the file.6. Click Save.

90 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 103: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Signatures and locks

Signatures and locksSigning an object indicates that the object meets your approval. It has noenforcement powers, and does not prevent the item from being modified afterapproval. A signed object is marked with a signature icon next to the name of thesigner on the Signatures tab.

Depending on your system configuration, signatures, with or without associatedlocks, can be applied to an object manually, automatically using a workflow task,or using both methods.

If signature locks are enabled, when you sign off on an object, the object and all itschild objects are locked. The objects cannot be modified until you revoke yoursignature or an administrator unlocks the object.

Only one active lock can be placed on an object. Multiple locks can be inheritedfrom parent objects.

An object that has a signature lock has both a signature icon and a red lock icondisplayed next to the object name. If a child object has inherited a signature lockfrom a parent object, a gray lock icon appears.

Because a lock is replicated down the object hierarchy, an object can have multiplelocks assigned to it through inheritance. It cannot be modified until all locks areremoved.

To manually add or revoke a signature, you must be a member of a group withsignature privileges. Add manual signatures from the detail page of an object.

Objects are locked or unlocked from the detail page of an object.

You cannot perform the following actions on a locked object:v Move the object to a new locationv Edit any propertiesv Rename the objectv Delete the objectv Associate other objects with the object

You can perform the following actions on a locked object:v View the details of the objectv Associate the locked object with an unlocked objectv Copy the object to a new location (the newly created copy is unlocked)

SignaturesA signature generally indicates agreement that the object meets your approval.

A signature has no enforcement powers, and does not prevent the item from beingmodified after it is approved. An object with a signature has a signature icon nextto the signer's name on the Signatures tab. Depending on your systemconfiguration, signatures (with or without associated locks) can be applied to anobject in the following ways:

Chapter 11. Working with objects 91

Page 104: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Manually from the detail page of an object.v Automatically through a workflow task.v Some combination of both automatic and manual.

If signature locks are configured on your system, when you sign off on an object,the object and all its associated child objects are locked and cannot be modifieduntil you either revoke your signature or an administrator unlocks the object. Onlyone active lock can be placed on an object. Multiple locks can be inherited fromparent objects as those objects are locked.

An object that has a signature lock, has both a signature icon and a red lock icondisplayed next to the object's name in a folder view, filtered list view, or overviewand on the object's detail page. If a child object inherits a signature lock from aparent object, a gray lock icon appears instead. Because a lock is replicated downthe object hierarchy, an object can have multiple locks assigned to it (throughinheritance), and cannot be modified until all of the locks are removed.

To manually add or revoke a signature, you must be a member of a group withsignature privileges. Manual signatures (with or without locks) are added orrevoked from the detail page of an object. To lock or unlock an object (withoutadding a signature), you must have the necessary permissions set on your account(see your system administrator for details). Objects are locked or unlocked fromthe detail page of an object.

What you cannot do to a locked object:v Move the object to a new locationv Edit any properties of the objectv Rename the objectv Delete the objectv Associate other objects with the locked object

What you can do to a locked object:v View the details of the objectv Associate the locked object with an unlocked objectv Copy the object to a new location (the newly created copy is unlocked)

How do I...v “Adding a signature” on page 93v Lock an object?v Revoke a signature?v Unlock an object?

View information...v Signatures for an object?v locks for an object?v “Change history” on page 123v Sign off on a task?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?

92 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 105: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are search filters?v What are alerts and can I change my notification options?

Adding a signatureIf configured, you can manually add a signature to, or sign off on, an object.

About this task

If signature locks are configured, when you sign off on an object, the object and allits associated child objects are locked and cannot be modified until you eitherrevoke your signature or an administrator unlocks the object. When a parent objecthas a signature lock applied to it, only one active lock can be placed on an object.Multiple locks can be inherited from parent objects as those objects are locked.

Procedure1. Navigate to the detail page of the object.2. In the navigation pane under Associations, click Signatures.3. Click Actions > Add a new Signature.4. On the Add page, provide a description and Comment.5. Click Create.

Jobs and tasks

JobsA job is a repeatable procedure that may contain multiple tasks. You can submitmultiple jobs from an object folder view page or submit a single job from anydetails page.

During the commission of a job, a completed task might trigger the assignment ofother tasks. After the last task in a job is complete, the job is finished.

Keep track of the activity for a job that you started through the My Jobs pane onyour home page. Each job displays its name, description, the object it is attachedto, and the active task.

When you click the name of a job that is running, the detail page for the job isdisplayed. From the detail page, you can view information about the job, includingcomments by users and assignees.

Using jobsThis topic provides information about jobs.

How do I...

v Start a job from an object?v Use the My Jobs lists?v View job details?v Add a file or link to a job?v Disassociate an object or file?v Terminate a job?

Tell me about...

Chapter 11. Working with objects 93

Page 106: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What is a job?v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

Viewing and monitoring jobsYou can view and monitor your jobs through the My Jobs pane on the home page,if it is configured. It displays the most recent jobs that you submitted. These jobsmay be associated with any object. They may also be standalone jobs that are notassociated with any object.

Procedure1. Click Home from the global header. Each job is listed with its name,

description, attachments, and the name of the currently active task.2. From the My Jobs pane, click the name of the job to open.

Note: To display more tasks, click View Details to list all assigned tasks.

TasksUse the links in to view information about tasks.

How do I...v “Adding comments to an action item” on page 80v “Adding files to tasks or jobs” on page 87v “Add a link to a task or a job” on page 89

Use the My Tasks listv “Completing tasks” on page 42v “Disassociate a file or object from a task or job” on page 95.

Adding a link to a task or jobWhen you add a URL that links to an external destination (such as a Web site orfile) to a task or job, you must first add it to a folder in the file repository and thenassociate it with the task or job.

About this task

If configured, this information applies to My Tasks on the Home page.

The external hyperlink is displayed on the details page of the task or job under theAttachments tab. When a user clicks the hyperlink, the Link Summary page isdisplayed. From the Link Summary page, a user can click the URL to open a newwindow, which displays the contents of the target destination.

If you link to files or documents that are maintained outside the IBM OpenPagesGRC Platform file repository, unless external security controls are in place, thesefiles or documents will not be under version control.

Procedure1. Select Home from the menu bar.

94 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 107: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

2. From the list of My Tasks or My Jobs, click the name of the task or job to addto the file.

Note: If there are more tasks to be displayed, click the View Details icon todisplay a page that lists all the currently assigned tasks.

3. On the Attachments pane of the task or job, click Add File to open the AddFile wizard.

4. In the Add File wizard, do the following:a. Select a target folder - expand the hierarchy in the file repository as

necessary to view the folders in the tree.b. To add a file to an existing folder, select the check box next to the folder

that will contain the new files.c. To add a new subfolder, select the checkbox next to the folder that will

contain the new subfolder. Click Add Folder. Type a name and descriptionfor the new folder. Click OK.

5. Select the file - click Browse and navigate to the file you want to upload.6. Click Finish. The new file is associated with the task or job is listed on the

Attachments pane of the task or job detail page and on the My Tasks or MyJobs tab on the Home page.

Disassociate a file or object from a task or jobWhen you disassociate a file or object from a task or job, you remove the linkbetween the task and the object or file without affecting the related object or file.

About this task

If configured, this information applies to My Tasks or My Jobs on the Home page.

Procedure1. Click Home from the global header.2. From the list of My Tasks or My Jobs, click the name of the task or job you

want to open its detail page.3. On the Attachments pane, select the check box next to each file or object you

want to remove from the list.4. Click Disassociate.5. Click OK.

Milestones and milestone action items

Milestones and Milestone Action ItemsA Milestone represents a significant point in the development of your project. Youcan tie Milestones to specific dates, or use them to signify the completion of aportion of the entire project. Milestones can contain other Milestones or MilestoneAction Items. You cannot associate a Milestone with other objects in the objecthierarchy.

A Milestone Action Item is a specific objective that must be completed in order toreach a Milestone. In general, all Milestone Action Items associated with aMilestone must be completed in order to reach a Milestone. When you areassigned a Milestone Action Item object, it is displayed (if configured) in the MyMilestone Action Items section of your My Work tab.

Chapter 11. Working with objects 95

Page 108: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Adding milestonesUse this procedure to add a milestone.

Procedure1. Select Organization > Milestones.2. On the Milestones page, click Grid Actions >Add New.3. On the Adding Milestones page, type a name for the new milestone. Complete

required fields.4. Click Create.

My Milestone Action ItemsThe My Milestone Action Items page displays a list of all unfinished action itemsthat are currently assigned to you. Each project action item identifies the startingdate, due date, and completion percentage.

Procedure1. From the menu bar, click My OpenPages.2. Click My Milestone Action Items.3. Click the name of a project action item.

Milestones OverviewThis topic provides information about the Milestones Overview page.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

96 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 109: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Milestones and Milestones Action Item Detail ViewThis topic provides information about the Milestones and Milestones Action ItemDetail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 11. Working with objects 97

Page 110: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Milestones and Milestone Action Items List ViewClick on the links to view information about Milestones and Milestone ActionItems List View.

How do I...v “Adding a child object from a detail page” on page 51v “Navigating to an object's detail page” on page 21v Move an object to another folder?v Rename an object?v Delete an object?v Select a different report period for this view?

Reports

ReportsIBM OpenPages GRC Platform comes with a variety of pre-defined informationaland exception reports, such as graphical summary dashboard reports, specific taskreports that are assigned to users, issues monitoring reports, and managementreports. Some reports may also link to sub-reports, which contain more detailedinformation on a particular area. Reports can be generated on demand at any time.

Example of using an Operational Report - You want to find out what the loss eventtrends were for workplace safety in a particular month. You might select, forexample, the Loss Events Summary Report. It displays a chart of the financial loss,non-financial loss, and loss event count for the selected month.

To narrow the scope of the data that is returned for workplace safety, you couldselect the Risk category called Employment Practices and Workplace Safety and aCausal Category of People.

Example of using a Financial Report - You are working on effective and ineffectivefinancial controls and want to see all the effective and ineffective financial controlsfor a division of the company. You could select, for example, the Financial ControlOperating Effectiveness Report. To narrow the scope of the control data that isreturned to the division you want, select the name of the division on the reportprompt page.

Depending on your configuration, you may also select reports either embedded orlisted on the home page. Reports are categorized as follows:v Interactive - reports that prompt you to select or enter values that filter the data

in the report. For example, these reports may prompt you to select a BusinessEntity, reporting period, or start and end dates. The report then limits the scopeof the returned data. Reports that prompt for a Business Entity return data forobjects under that entity.

v Static - reports that are generated as soon as you click the name of the report.

You can access a list of available reports from the Reporting menu on the menubar. Available reports are directly listed on the Reporting menu. Alternately, youcan select the All Reports menu item to display the Reports page where reports aregrouped by folder categories and new reports can be added (requires administratorprivileges).

98 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 111: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Reports - Frequently Asked QuestionsThis topic identifies information about Reports.

How do I...v “Generating and viewing reports” on page 41v “Emailing a report”v “Viewing reports in a different format” on page 37

Tell me about...v “Reports” on page 98

Generating and viewing reportsYou can generate an individual report from the Reporting menu or select a reportfrom the Reports page.

Procedure1. To run a report, from the menu bar, click Reporting.2. From the Reporting, click the name of the report.3. For interactive reports, complete all required fields and selections.4. Click Finish to generate the report.

Emailing a reportIf your system is configured, you can generate a report and send it by email.

Procedure1. On the generated report, click the Keep this version link.2. Click Email Report.3. In the Set the email options window, type an email address in the To box.4. To send the report to multiple addresses, separate each address with a

semicolon (;).5. Type a subject line and a message.6. Select whether the report is sent as an attachment or as a link.7. Click OK.

Viewing reports in a different formatIf your system is configured to display reports in different formats, you cangenerate a report and then view or save it in another format. The standard formatis HTML.

Procedure1. On the icon bar of the generated report, click Action.2. From the list, select a format.3. Follow the screen prompts.

Questionnaires

Questionnaires, sections, questionsThis topic provides a description of questionnaires, sections, and questions.

Chapter 11. Working with objects 99

Page 112: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Questionnaire, Section, and Question objects are used together to implementquestionnaires. Questionnaires are created as templates in a library and gatherinformation from respondents. Section objects are children of parent Questionnaireobjects and organize sets of related questions. Question objects are children ofSection objects and capture respondent data. Business administrators use theQuestionnaire Set Up Activity View to configure questionnaire templates.Questionnaire templates are then copied to parent Business Entity, Process,Sub-Process, or Employee object types.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Questionnaires Folder ViewThis topic provides information about the Questionnaire Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

100 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 113: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Questionnaires Detail ViewThis topic provides information about the Questionnaires Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Questionnaire Templates

Questionnaire templatesQuestionnaire templates are used in programs to launch questionnaire assessments.They contain questions that are organized in sections and subsections. Respondentsanswer the questions in questionnaire assessments.

Filtered List ViewThis topic provides links to information about the Filtered List View.

Chapter 11. Working with objects 101

Page 114: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Questionnaire Template Folder ViewThis topic provides information about the Questionnaire Template Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Questionnaire Template Detail ViewThis topic provides links to frequently asked questions about the QuestionnaireTemplate Detail view.

102 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 115: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I add...v “Adding an object instance with the Add New wizard” on page 14v Associate or disassociate an object with a questionnaire template?v Edit a questionnaire template?v “Copying objects” on page 21v Delete an associated object from a questionnaire template?v Lock or unlock an object?v Unlock all objects within an object?v “Navigating to an object's detail page” on page 21v Reassign a primary parent for an object?

How do I view...v Locks for a questionnaire template?v Change history (audit trail) for a questionnaire template?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?v “Questionnaire assessments” on page 128v “Launching a program” on page 116

Defining a questionnaire templateQuestionnaire templates contain the questions that respondents answer when theycomplete a questionnaire assessment.

Before you beginv Create a questionnaire template object.v Plan the questionnaire template content and decide what method to use for

scoring. For information see “Questionnaire template scores and scoringmethods” on page 129.

About this task

To define a questionnaire template, you launch it with Assessments >Questionnaire templates. The system opens the template in the author UI. It issimilar to the questionnaire UI that users open to complete a questionnaireassessment.v The section list shows the overall structure of the questionnaire template. It also

displays how many questions are in each section.v Your work is automatically saved. Click Save Draft to manually save at any

time.v Anyone who can access the questionnaire template can also work on it.v You can change a questionnaire template until it is launched with a program

and sent to respondents. After that point, the system locks it and only users withappropriate credentials can unlock it, edit the questionnaire template, and lock itagain. The changes take effect immediately.

Chapter 11. Working with objects 103

Page 116: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. Click Assessments > Questionnaire Template. The system displays a list of

questionnaire template objects.2. Click Launch in the Authoring UI column of the questionnaire template you

want to work on. The system opens the questionnaire template in a newwindow and displays a launch page.

3. Click Open questionnaire. The system displays a getting started message andprompts you to create your first section. The next time that you open thequestionnaire assessment it opens beginning with the first question of the firstsection. You are using the author UI.

4. Create the sections and subsections. For information see “Adding sections andsubsections to a questionnaire template.”

5. Write the questions. For information see “Adding questions to a questionnairetemplate” on page 105.

6. Click Preview to check your work and review how the questionnaire templateappears when a respondent works on it. When you are finished previewing,click Edit to return to editing mode.

7. Review the questionnaire template. You can edit and delete sections,subsections, and questions. You can reorder the sections.

8. To stop working on a questionnaire template, close the browser window.9. To resume working on a questionnaire template, launch the questionnaire

template again. The system displays the questionnaire template beginning withthe first question of the first section.

What to do next

The next step is to launch the questionnaire template with a program. Forinformation see “Launching a program” on page 116.

Adding sections and subsections to a questionnaire templateSections and subsections provide structure for a questionnaire template.

Before you begin

Create the questionnaire template and plan how the sections and subsections areorganized and weighted for scoring. For information see “Defining a questionnairetemplate” on page 103.

About this task

Use this task to add, edit, and delete sections and subsections on a questionnairetemplate.

Procedure1. Click Assessments > Questionnaire Template. The system displays a list of

questionnaire assessment objects.2. Click Launch in the Authoring UI column of the questionnaire template you

want to work on. The system opens the questionnaire template in a newwindow and displays a launch page.

3. Click Open questionnaire.4. Click the + Section icon to add a section.5. Enter a Title. This value is displayed in the questionnaire assessment.

104 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 117: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

6. Enter a Description. This value is displayed in the questionnaire assessment.7. Enter a value 0 - 9999 in Weight. Enter 0 to exclude all the questions in the

section from scoring. It is not displayed in the questionnaire assessment.8. Enter a Reference. This value is not displayed in the questionnaire

assessment.9. Enter a Rationale. This value is not displayed in the questionnaire assessment.

10. Click Add Section. The system adds the section to the end of the template.You can now add subsections to it.

11. To add a subsection, highlight the section to which you want to add asubsection and click + Subsection. After you add a subsection, you can shift itup or down in the section but you cannot move it to another section.

12. Complete all the fields for the subsection. They are the same as for a section.13. Click Add Subsection. The system adds the subsection to the end of the

section.14. Click Preview to check your work and see how the questionnaire template

looks when a respondent works on it. Verify the organization andcompleteness of the sections and subsections. Check for errors. When you arefinished previewing, click Edit to return to editing mode.

15. Add more sections and subsections.16. The status bar shows how many sections and questions are in the

questionnaire template.17. Click Reorder to change the order of sections or subsections within a section.

You cannot move a subsection to another section. You cannot move a questionto another subsection.

18. To edit a section or subsection, click Edit Section or Edit Subsection andenter the changes.

19. To delete a section, click Delete Section. When you delete a section, thequestions and subsections in it are deleted.

20. To delete a subsection, click Delete Subsection. When you delete a subsection,the questions in it are deleted.

21. To stop working on the questionnaire template, close the browser.

What to do next

The next step is to add questions to the subsections. For information see “Addingquestions to a questionnaire template.”

Adding questions to a questionnaire templateQuestions contain the information that you want respondents to answer orprovide.

Before you begin

Add sections and subsections to the questionnaire template. For information see“Adding sections and subsections to a questionnaire template” on page 104.

About this task

Use this task to add, edit, and delete questions on a questionnaire template.

Chapter 11. Working with objects 105

Page 118: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedure1. Click Assessments > Questionnaire Template. The system displays a list of

questionnaire assessment objects.2. Click Launch in the Authoring UI column of the questionnaire template you

want to work on. The system opens the questionnaire template in a newwindow and displays a launch page.

3. Click Open questionnaire.4. Highlight the section and then the subsection to which you want to add a

question. Click Add Question. You can add questions only to a subsection,not a section. After you add a question, you can shift it up or down in thesubsection but you cannot move it to another subsection.

5. Enter a Title. This value is displayed in the questionnaire assessment.6. Enter a Description. This value is displayed in the questionnaire assessment.7. Enter a value 0 - 9999 in Weight. Enter 0 to exclude a question from scoring. It

is not displayed in the questionnaire assessment.8. Enter a Reference. This value is not displayed in the questionnaire

assessment.9. Enter a Rationale. This value is not displayed in the questionnaire assessment.

10. Set the values in Show only if and Has been answered if the question is adynamic question. A dynamic question is hidden or displayed dependent onthe respondent's answer to a previous question, called the control question. InShow only if, you select the control question that the dynamic questiondepends on. You can choose only from questions in the subsection you are in.They must be single or multi choice questions. In Has been answered, youselect the control question's answer that makes the dynamic question display.In the questionnaire assessment, dynamic fields are displayed below theirdependent questions with a slight indentation. Leave Show only if and Hasbeen answered blank if the question is always displayed and not dependenton other questions.

11. Select a Type. Choose one of the following options:v Single Choice

The respondent can choose only one answer. You write the answers.v Multi Choice

The respondent can choose multiple answers. You write the answers.v Short Text

The respondent can enter up to 200 characters of text. Short text questionshave no answer score and are excluded from scoring.

v Long Text

The respondent can enter up to 1000 characters of text. Long text questionshave no answer score and are excluded from scoring.

12. If you chose Single Choice or Multi Choice in Type, write the answers thatrespondents can choose from. Enter the answer text in Choice.

13. If you chose Single Choice or Multi Choice in Type, enter an answer scorebetween -1 and 9999. Enter -1 for answers you want to exclude from scoring.For example, the answer, Not-applicable, can be scored -1. Use a higheranswer score for better answers, for example, use 10 for the best answer. Use aconsistent range and keep it as small as possible, for example, 1 - 10. Use alarger range only if a question has many answers, for example, more than 10.When the score is calculated, question scores are normalized 0 - 10.

106 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 119: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

14. Select Show Comment to enable comments. If enabled, the respondent canoptionally provide multiple comments. The default is selected.

15. Select Show Attachment to enable attachments. If enabled, the respondent canoptionally provide multiple attachments. The default is selected.

16. If comments are enabled, click the Comments icon to make a commentmandatory for an answer. If it is mandatory, the answer is marked asincomplete until the respondent adds a comment.

17. If attachments are enabled, click the Attachments icon to make an attachmentmandatory for an answer. If it is mandatory, the answer is marked asincomplete and not scored until the respondent adds an attachment.

18. Click Preview to check your work and see how the questionnaire templatelooks when a respondent works on it. When you are finished previewing,click Edit to return to editing mode.

19. To edit a question, click Edit Question and enter the changes.20. To delete a question, click Delete Question. To delete a control question, first

delete the dynamic question or remove the dependencies.21. To stop working on the questionnaire template, close the browser.

What to do next

Continue adding and editing questions until the questionnaire template is finished.

Review the questions:v Verify the completeness of the questions and check for errors.v Verify the answers and check for errors.v Verify that comments and attachments are correctly marked as mandatory. In

Preview mode, the system displays a message next to questions with mandatorycomments or attachments.

v Check for duplicate questions.v Check that question weights and answer scoring are correct and consistent.v Review dynamic questions and verify that dependencies are working. To remove

dependencies between questions, clear the dynamic question's values in Showonly if and Has been answered.

Questionnaire Assessments

Questionnaire assessmentsQuestionnaires assessments are a means of gathering information from businessusers in the organization. Respondents complete the questions and submit thefinished questionnaire assessment.

Questionnaire assessments are created when a program is launched. Do not createthem with Add New in Assessments > Questionnaire Assessments because theywill have incomplete lifecycle information. For more information see “Launching aprogram” on page 116.

Filtered List ViewThis topic provides links to information about the Filtered List View.

Chapter 11. Working with objects 107

Page 120: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Questionnaire Assessment Folder ViewThis topic provides information about the Questionnaire Assessment Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Questionnaire Assessment Detail ViewThis topic provides links to frequently asked questions about the QuestionnaireAssessment Detail view.

108 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 121: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I add...v Associate or disassociate an object with a questionnaire assessment?v Edit a questionnaire assessment?v “Copying objects” on page 21v Delete an associated object from a questionnaire assessment?v Lock or unlock an object?v Unlock all objects within an object?v “Navigating to an object's detail page” on page 21

How do I view...v Locks for a questionnaire assessment?v Change history (audit trail) for a questionnaire assessment?v “Viewing lifecycle information” on page 37

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?v “Questionnaire assessments” on page 128v “Launching a program” on page 116

Completing a questionnaire assessmentAs a respondent you can complete a questionnaire assessment that the enterpriserisk team has sent you.

About this task

To complete a questionnaire assessment, you use the questionnaire UI.

Questions can be in the following formats:v Single choice answer (you can choose one answer)v Multiple choice answer (you can choose all answers that apply)v Short text answer (you can write up to 200 characters)v Long text answer (you can write up to 1000 characters)

Questions can be dynamic, meaning they are displayed or hidden based on youranswer to a previous question. For example, if you answer a question with theanswer YES, the questionnaire displays three more questions about that topic. Butif you answer NO, the system hides the additional questions.

Your progress percentage, Compliance Score, and Risk Score are displayed on theQuestionnaire Assessment Filtered List View. These values are continually updatedas you work on the questionnaire assessment. The compliance score is thenormalized score result of all the questions you answered so far. The risk score isthe non-normalized score result. The reviewer can also see this information.

Anyone who can access a questionnaire assessment can also work on it. More thanone respondent can work on one questionnaire assessment.

Chapter 11. Working with objects 109

Page 122: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

In detail view, the fields on a questionnaire assessment are read-only. If you createan activity view, define the fields as read-only.

Procedure1. Open the email and click the URL. The system opens the questionnaire

assessment in a new window and displays a launch page. If email is notconfigured, click Assessments > Questionnaire assessments. The systemdisplays a list of questionnaire assessments. Click Launch in theQuestionnaire UI column of the questionnaire assessment you want tocomplete. The system opens the questionnaire assessment in a new windowand displays a launch page.

2. Click Open questionnaire. The system displays the questionnaire assessmentbeginning with the first question of the first section. You are using thequestionnaire UI.

3. Begin answering questions:v You can start in any section or subsection.v Work sequentially through questions in a subsection. Questions can be

shown or hidden based on your answers.v You can change your answers as often as needed until you submit.v Your answers are automatically saved. Click Save Draft to manually save at

any time.v You can stop and start again as often as needed.v You might be able to leave questions unanswered, it depends on how the

questionnaire template was defined.v You can use the question filter in the title bar to control the questions that

are displayed. You can choose: All questions, Completed questions,Incomplete questions, or Rejected questions.

v Click Reset to discard an answer or text you entered and set the questionback to its initial state.

v Click Details to see who last answered a question and when.4. If comments are enabled for a question, click Comments to add additional

information to an answer. A question can have multiple comments. Acomment can be an optional or mandatory part of an answer. If it ismandatory, your answer is marked as incomplete until you add a comment.Maximum length is 252 characters. You can copy and paste text into acomment. If you copy the text from another source, it must be in one linewithout paragraph breaks. Comments cannot be deleted.

5. If attachments are enabled for a question, click Attachments to addsupporting documentation to an answer. An attachment can be an optional ormandatory part of an answer. If it is mandatory, your answer is marked asincomplete and not scored until you add an attachment. You can add adescription to an attachment; maximum length is 100 characters. How manyattachments a question can have is determined at the server level and followsthe rules for standard file objects. Attachments can be deleted.

6. To stop working on a questionnaire, close the browser window.7. To resume working on a questionnaire, launch the questionnaire assessment

again. The system displays the questionnaire assessment beginning with thefirst question of the first section.

8. When you are finished answering questions, verify that you finished all thequestions and that they are complete. You can still change any answers, ifneeded. Verify that you added comments and attachments to questions thatrequire them. You can delete attachments and add new ones, if needed.

110 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 123: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Choose Incomplete questions in the question filter. If no questions are listed,you answered all the questions and the answers are complete.

9. Click Submit or Submit and Close. The lifecycle determines which icon isdisplayed. The system displays a summary screen that lists the due date,percentage of completed questions, and number of rejected questions. You canadd a comment.

10. Click Submit. The system changes the stage to closed for a two-stage lifecycleor to review for a three-stage or four-stage lifecycle. You can still access it butyou can no longer edit it.

11. Close the browser window.

Results

After you submit a question assessment, what happens next is determined by itslifecycle. If it is assigned to a two-stage lifecycle, it is finished. If it is assigned to athree-stage or four-stage lifecycle, a reviewer receives an email and reviews it. Ifthey reject it, it is returned to you. Look in the section list for messages aboutrejected answers. Open the section and find the rejected answers. The revieweradded comments or reasons that explain why your answer was rejected. Make thecorrections and resubmit it.

Reviewing a questionnaire assessmentYou can review questionnaire assessments that people in your organization havecompleted. You can review a questionnaire assessment if it is at the review lifecyclestage.

About this task

When a questionnaire assessment is in the review lifecycle stage, Review Mode isdisplayed in the top-level section of the questionnaire UI. Only a reviewer canopen it and review answers. They can approve a questionnaire assessment or rejectit.

Procedure1. Open the email and click the URL. The system opens the questionnaire

assessment in a new window and displays a launch page. If email is notconfigured, click Assessments > Questionnaire assessments. The systemdisplays a list of questionnaire assessments. Click Launch in the QuestionnaireUI column of the questionnaire assessment you want to review. The systemopens the questionnaire assessment in a new window and displays a launchpage.

2. Click Review questionnaire. The system displays the questionnaire assessmentbeginning with the first question of the first section. You are using thequestionnaire UI in reviewer mode.

3. Review the answers.4. If all the answers are complete, click Action > Approve and Close (three-stage

lifecycle) or Action > Submit for Approval (four-stage lifecycle). The lifecycledetermines which icon is displayed.

5. If an answer is incorrect or incomplete, you can reject it:a. Click Reject Answer.b. Add a comment and click Reject in the dialog box. In the section list, the

system displays how many questions in the section are rejected. You canreject only individual questions not sections or subsections.

Chapter 11. Working with objects 111

Page 124: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

c. Review the remaining answers.d. When you are finished, click Action > Reject in the title bar. The

questionnaire assessment goes back to the information gathering stage. It issent back to the respondent. The respondent launches the assessment,answers the rejected questions, and resubmits it. When it comes back toyou, you open it again and follow the same process to review it. You canapprove it or reject it again. On the second and subsequent reviews, youcan provide a comment on answers you accept that you previously rejected.

Results

After you approve a question assessment, what happens next is determined by itslifecycle.

If it is assigned to a three-stage lifecycle, the system closes it. At that point ReadOnly is displayed in the top-level section. Both the respondent and the reviewercan view it but neither one can edit it.

If it belongs to a four-stage lifecycle, an approver receives an email and reviews it,following the same process as the reviewer and using the questionnaire UI inReview Mode. The approver can reject answers and send it back to you. Look inthe section list for messages about rejected answers. Open the section and find therejected answers. The approver added comments or reasons that explain why ananswer was rejected. Review the comments and resubmit it or reject it. If you rejectit, it goes back to the respondent. When the approver clicks Action > Approve, thesystem closes the questionnaire assessment. At that point Read Only is displayedin the top-level section. You can view it but no longer edit it.

Updating a questionnaire assessment's lifecycle assigneeYou can update a questionnaire assessment's lifecycle assignee if it is empty orincorrect.

Before you beginv Verify that the assets that are assigned to the questionnaire assessment have

employee names or primary owners and that they are correct.

About this task

If a questionnaire assessment's lifecycle assignee is empty, the system cannotinitiate the first lifecycle stage owner. If the lifecycle assignee is incorrect, thesystem cannot set the stage owner to the correct user.

Procedure1. Click Assessments > Questionnaire Assessment.2. Open the questionnaire assessment in the Detail or Activity View.3. If the fields are not displayed, click the Fields link under the Details section in

the navigation pane.4. In the Lifecycle Management fields set Update Assignee to Yes.5. Click Save.

What to do next

You must relaunch the program that initially created the questionnaire assessment.For more information see “Launching a program” on page 116.

112 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 125: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Responding to an approval app notificationWhen the lifecycle stage determines that action is needed by you, you receive anemail with a link to the To Do item that needs your attention.

Before you begin

For the approval app to be available, you must have the OpenPages 7.2.0.1 or laterfix pack installed. The approval app must be installed and configured.

About this task

Upon email notification telling you what you are being asked to do, just click onthe hyperlink in the email and you are brought to a page in the approval app thatincludes all the relevant information and provides you with an opportunity to takethe requested action.

Here are a few things to keep in mind about the approval app:v You can use this feature on tablets and mobile devices that use the Chrome

browser or the Internet Explorer browser, versions 9 and later.v Completed items are stored in the web browser where the action was taken. If

you change web browsers or clear the browser cache, you don't see thecompleted items from the previous browser.

v You can have up to 50 completed items in the browser. Completed items arekept for 90 days from completion.

v You can hover, click, or tap on a field label to see guidance about how that fieldis used. If the guidance tooltip persists, simply click on the guidance tooltip thenclick off it. (Tap if you are using a mobile device.)

For information about approval app installation and configuration, see Installingand configuring the approval app (http://www.ibm.com/support/knowledgecenter/SSFUEU_7.2.0/com.ibm.swg.ba.cognos.op_grc_fix_pack_7201_installer.7.2.0.1.doc/c_op_deck_install_config.html).

Procedure1. Open the email and click the hyperlink.

The To Do item opens, showing the due date, a description, and the action thatyou must take.

2. Click the > symbol. The system displays the following sections. Click on asection header to expand or collapse that section.v A Details section. Click this to see details about the To Do item in question.v A Related Content section. Click this to see information about objects related

to the To Do item to provide sufficient context for you to make your actiondecision.

v A Recent Activity section. Click this to see a timeline describing the actionstaken so far about the To Do item in question.

You can return to your To Do list by clicking the logo at the top left of thepage.

Chapter 11. Working with objects 113

Page 126: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Programs

ProgramsYou use programs to define and launch questionnaire assessments.

A program defines the people who are involved in an assessment, this includes theresponsible manager, the reviewers, and the approvers. It also defines the lifecycleand the questionnaire template that the program uses. A program is based on anunderlying asset that you want to assess. These assets can be processes,subprocesses, resources, or employees.

Programs that are based on employees create questionnaire assessments that aresent to the employees. Programs that are based on resources, processes, orsubprocesses are based on selected objects and are sent to the objects' primaryowner. If an employee has no employee name or an asset has no primary owner,there is no respondent for the questionnaire assessment and the lifecycle assigneeis empty.

First, create a program object and assign the questionnaire template, a lifecycle,and assets to it. When you launch it, the questionnaire assessments' lifecycle stageis set to information gathering. A questionnaire assessment moves from one stageto the next when a user submits, rejects, or approves it. The stage owner can comefrom the underlying asset or the program owner if it is the final stage. For moreinformation see “Lifecycles” on page 128.

You can review lifecycle information in a questionnaire assessment's Detail andActivity View. For more information see “Viewing lifecycle information” on page37.

Users who launch programs must have read permissions for questionnaireassessment and questionnaire template objects. Set up permissions so that onlyprogram owners can delete questionnaire assessments.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another object

114 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 127: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Program Folder ViewThis topic provides information about the Program Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Program Detail ViewThis topic provides links to frequently asked questions about the Program Detailview.

How do I add...v “Adding an object instance with the Add New wizard” on page 14v Associate or disassociate an object with a program?v Edit a program?v “Copying objects” on page 21v Delete an associated object from a program?v Lock or unlock an object?v Unlock all objects within an object?v “Navigating to an object's detail page” on page 21

How do I view...v Locks for a program?v Change history (audit trail) for a program?v “Viewing lifecycle information” on page 37

Chapter 11. Working with objects 115

Page 128: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?v “Questionnaire assessments” on page 128v “Launching a program”

Launching a programYou launch a program to create questionnaire assessment instances.

Before you beginv Create a program object.v Verify that the questionnaire template, lifecycle, and assets that are assigned to

the program are correct.v Verify that the assets have employee names or primary owners.

About this task

When you launch a program the first time, the system creates questionnaireassessment instances. You can launch it again if new assets were added. When youlaunch a program a second time, the system creates only questionnaire assessmentsfor the new assets. Existing, unchanged questionnaire assessments are not affected.

For more information see “Programs” on page 114.

Procedure1. Click Assessments > Programs. The system displays a list of programs.2. Click Launch in the Launch Program column. The system displays a message

with the number of questionnaire assessment instances that will be created.3. Click Launch.

Results

The system:v Creates one questionnaire assessment object per employee, resource, process, or

subprocess in the program. It does this in a background process.v Starts the lifecycle for the questionnaire assessments.v Sends emails to the respondents.v Locks the questionnaire template.

What to do next

You can click the Process History link to review the status of the program launchor any other background processes related to this object, such as child associations.Review the questionnaire assessments the program created. Verify that the objectshave a lifecycle assignee and that the assets are correct. If there are errors, youmust make the corrections and launch the program again. For more informationsee:v “Updating a questionnaire assessment's lifecycle assignee” on page 112v “Updating and relaunching a program” on page 117

116 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 129: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

To delete questionnaire assessments that were created in error, you must dissociatethe questionnaire assessment from the asset.

Updating and relaunching a programYou can update the assets that are assigned to a program and relaunch it if newassets were added after the initial launch.

About this task

You can relaunch a program if new assets were added after it was initiallylaunched.

Procedure1. Click Assessments > Programs.2. Open the program in the Detail or Activity View.3. In the navigation pane under Associations, click the asset type: Employees,

Processes, Resources, or Sub-Processes. You can see what assets are currentlyassigned to the questionnaire assessment.

4. Click Actions > Add a new <asset type> and select a new asset.5. Click Actions > Associate an existing <asset type> to associate the program

with an existing asset.6. Launch the program again.

What to do next

Verify that questionnaire assessments for the new assets were created. You canrelaunch a program multiple times, if needed.

Capital Modeling

Capital modelingIBM OpenPages Capital Modeling helps you allocate scarce resources andminimize potential exposures. It provides a set of analytical tools to assess,simulate, and quantify operational risk capital. It enables multiple methods of riskcapital calculation. Featuring a robust simulation engine, OpenPages CapitalModeling offers analytical tools, statistics, and scaling features.

IBM OpenPages GRC Platform now integrates with OpenPages Capital Modeling.You can print capital modeling reports from within IBM OpenPages GRC Platform.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30

Chapter 11. Working with objects 117

Page 130: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Capital Modeling Folder viewThis topic provides information about using the Capital Modeling Folder view.

How do I...v Add a folder?v Navigate to a Detail page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Capital Modeling Detail viewThis topic provides information about the Capital Modeling Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?

118 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 131: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Model Results

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 11. Working with objects 119

Page 132: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Model Results Folder ViewThis topic provides information about the Model Results Folder View page.

How do I...v Add a folder?v Navigate to a Detail page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Model Results Detail ViewThis topic provides information about the Model Results Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

120 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 133: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Chapter 11. Working with objects 121

Page 134: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

122 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 135: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 12. Reference information

Automatic timeoutThe solutions in the IBM OpenPages GRC Platform Enterprise suite are set toautomatically timeout after a period of system inactivity.

If you attempt to perform an operation after the application has timed out, thesystem automatically moves to the Log On page where you can log on again.

Browse attachmentsThe Browse Attachments page displays a hierarchy of folders for all files (such asdocuments, forms, and links) in the IBM OpenPages GRC Platform file repository.

Attach a file from the Detail View page of a parent object. Depending on yourconfiguration, you may also be able to add standalone document files from theBrowse Attachments page that you can later associate with parent or other objects.From the Browse Attachments page, you can view, add, delete, move, and renamefiles and folders.

File attachments that are modified and then uploaded to the OpenPages GRCPlatform file repository have a new version automatically created. You can retrievean older version of a file without losing the current version. Files that are stored inthe file repository also have a View File link on their File Detail page. You can usea drag-and-drop or cut-and-paste operation to copy a View File link from the fileinto another application (such as e-mail or a Microsoft Word document).

If an object contains a URL link to an external destination (such as a Web site orfile), the link is displayed on the detail page of that object and not on the BrowseAttachments page. When a user clicks the external link, a new window opens anddisplays the contents of the target destination. If you link to files or documentsthat are maintained outside the OpenPages GRC Platform file repository, unlessexternal security controls are in place, these files or documents will not be underversion control. Typically, you add a link from the detail page of a parent object.

If the file Check In/Check Out feature is configured for your system, the file islocked while it is checked out for editing and unlocked when it is checked in sochanges are not inadvertently overwritten by another team member.

Change historyChanged information is displayed on the Change History page and cannot bemodified. You can view change history information for a selected reporting periodfrom the Detail View page of an object.

Change History displays the following types of changes:v Associated objects displays additions or removals of associated child object

types.v Object values displays old values and changed field values.

The Change History table displays the following information:

123

Page 136: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Table 2. Change History Table

Information Description

Name The name of the property or field that was changed.

Old Value The value of the property or field prior to the change. ForRich Text Formatted (RTF) fields and any large text fields,this column will be empty.

New Value The new value of the property or field. Text fields, inaddition to the new value, also display a View Changeslink. However, RTF and large text fields have only a ViewChanges link (no new value is displayed). When the ViewChanges link is clicked, the Change History Viewer opens ina new window where you can view and compare changes.

Modified By The name of the user who made the change.

Modified The date and time the change was made.

Associated objects, files, links, forms, and signatures - when associations betweenobjects are created or removed, the Change History page of the parent objectdisplays the following information for each associated object type. Changes aresorted by date (newest first).

Table 3. Association History Table

Table Column Heading Description

Name The name of the associated object that was added orremoved.

Status Indicates whether the associated object was added orremoved.

Possible status values are:

v Added - An object was associated as a child object in thehierarchy

v Removed - The object was logically deleted from therepository.

v Added Primary - The association type has been set toPrimary. The first association will always be set to Primary.

v Removed Primary - The association has been changed toNon-Primary. This could happen if the user selects anotherobject relationship to be the Primary parent-childassociation or the current Primary association was deleted.

Modified By The name of the user who made the change.

Modified The date and time the change was made.

File check in and check outIf the File Check In and Check Out feature is configured, you can check out a fileand lock it and edit it. When you are finished with the file, you then check in andunlock the file.

When you work in a collaborative team environment, the File Check In and CheckOut feature allows only one person to work on a file at one time. Changes will notbe overwritten by another team member. A checked-out file has the followingcharacteristics:

124 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 137: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v A check mark is displayed next to the file name.v The name of the person who checked out the file is displayed.v The file is listed in the My Checked Out Files pane on the home page.v The file is locked.v The file can be viewed and downloaded by others, associated with objects, and

copied to an object.

Using files, forms, and linksThis topic provides a list of procedures to complete when using files, forms, andlinks.

How do I Add?

v Folder or sub-folder?v New file to a task or job?v External link (URL) to an object?v External link (URL) to a task or job?

Edit a:

v File?v Description of a file?v Upload a new version of a file?v Check out or check in a file?

FormsForms help automate the capture of data and are customized for your business.

Forms that are associated with particular object types (such as the Process Survey)automate the capture of data through a series of targeted questions.

The type of forms available on your system depends on your system configuration.

Forms can be attached to an object and then filled out by users. When you fill outa form, you will either have to create a new instance of that form from an existingtemplate, or a survey task will be assigned to you.

NotificationsNotifications alert you of some action that was taken on a page.

By default, notifications are disabled. You can set preferences for the type ofnotifications you want to receive on objects and fields. For example, you could seta notification that alerts you whenever an object is successfully created or deleted.

Use notifications for the following tasks:v Set preferences for the types of notifications you want displayed.v Expand the alert notification dialog to see multiple messages.v Keep the alert notification dialog open so that notifications are always visiblev Show or hide notifications in the alert box.

Chapter 12. Reference information 125

Page 138: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Primary parent associationWhen a child object is added from the detail page of a parent object, it isconsidered to be a “primary child” and is automatically associated to that parentobject upon creation.

Object types that are allowed to have multiple parent objects through associationcan have only one primary parent association. For example, if Control-01 wasadded from the detail page of Risk-01 and was also associated to Risk-02,Control-01 would have two parents: Risk-01 and Risk-02. However, only Risk-01would be considered the primary parent of Control-01.

A primary parent object is identified in the application by the Primary Associationicon, which is displayed next to that parent object on a child object’s Detail Viewpage.

When primary associations are enabled:v You can change an object’s primary association from one parent object to another

by reassigning the primary parent.v Any re-assignment of the primary association from one parent object to another

parent object is reflected on the Change History pane of an object.v A child object with multiple parents that is disassociated from its primary parent

object is automatically re-assigned a new primary parent.v Cascading operations on objects (such as sign-off, delete, locking or unlocking),

are based upon primary associations.v Objects with multiple parents that are not included in a cascade delete operation

(such as issues and action items) are automatically re-assigned a new primaryparent.

v Copy operations on objects will duplicate existing associations (includingprimary associations) whenever possible. A new primary parent association isalso assigned to the first association.

Rules for naming folders, objects, and filesWhen you name a folder, object, or file, follow the restrictions identified in thistopic.

Use the following conventions to name folders, objects, and files:v The maximum length of an object name is 252 characters.v If auto-naming is enabled, the name of the object is automatically created.v Special characters are allowed in certain instances. Refer to the following table

for the special character restrictions:

Table 4. Special character restrictions

Specialcharacter Description

Allowed inFolder Name?

Allowed inObject Name?

Allowed in FileName?

& ampersand Yes Yes No

* asterisk Yes Yes No

\ backward slash No No No

: colon Yes Yes No

" double quote Yes Yes No

126 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 139: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Table 4. Special character restrictions (continued)

Specialcharacter Description

Allowed inFolder Name?

Allowed inObject Name?

Allowed in FileName?

! exclamationpoint

Yes Yes No

/ forward slash No No No

> greater than Yes Yes No

< less than Yes Yes No

% percent Yes Yes No

| pipe Yes Yes No

# pound Yes Yes No

? question mark Yes Yes No

For a folder name,

CorrectClaims and Liability Management, Claims & Liability Management

IncorrectClaims \ Liability Management, Claims/Liability Management

View pagesYou can use the View pages to locate and navigate to an object detail page.

When you select an object type from the menu bar, a Filtered List View or FolderView page is displayed. The IBM OpenPages GRC Platform application providesthe following View pages:v Overview - this view page displays a tree-view of all the objects in the entity or

folder hierarchy that are associated with the selected object type. This is theview you see when you click any object that contains the word Overview.

v Folder View - this view page displays objects of the same type in a folderhierarchy that were created for this object type. From a Folder View page, youcan add, move, or delete objects.

v Filtered List View - this page displays search filter options that you can use todisplay objects of the same type that match your search criteria.

v Detail View - this view page displays the fields of an object for viewing orediting, and any associations it has to other objects. This is the view you seewhen you click, for example, the linked name of an object from a Folder, List,Filtered List, or Overview page. From an object's detail page, you can perform avariety of actions, such as add, associate, disassociate, and delete objects.

v Activity View - this type of view page is configured by your systemadministrator to meet your unique business needs. If configured, activity pagesdisplay selected details of object fields and associated objects. From an object'sactivity view page, you can perform activities on both the selected object as wellas on multiple associated objects. If configured, this page appears as a selectionin the Current® View list on an object's Detail View page. If a Detail View is notconfigured for an object, the activity View page appears as the only detail page.

v List View - this view page lists objects of the same type in an alphabetical listformat. This is the page you see when you select, for example, the Business

Chapter 12. Reference information 127

Page 140: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Entities or Milestones menu item from the menu bar. From an object's List Viewpage, you can perform a number of actions, such as add, rename, and moveobjects.

Menu barYou use the menu bar to go to an object's Overview, Folder View, or Filtered ListView page.

To reveal menu items for selection, hover over or click on a menu name.

Your assigned role and permissions determine which menus and page views areavailable.

Example: To display a list of Control objects (assuming you have access), selectAssessments and then click the Controls menu item.

LifecyclesLifecycles define the stages that an object type can follow. Lifecycles work withquestionnaire assessments and incidents but can be extended to other objects.Users are informed in an email that they must complete a task, for example,answer questions in a questionnaire assessment. When the user completes the task,the object moves to the next task and the next user. The lifecycle process is finishedwhen all the tasks are completed. You have a record of who did what task andwhen.

At each lifecycle stage, the system:v Identifies a lifecycle assigneev Defines the actions available to move to a different stagev Sends an email to the new lifecycle assigneev Defines other attributes (read-only and in review) that are related to the current

stage

Lifecycle information is stored on the object instance. Open an object in theActivity or Detail View to see its lifecycle information. Lifecycle fields areread-only, except for Update Assignee. The assignee for a stage is defined in thelifecycle trigger. An object can have only one lifecycle assignee per stage. A usercan add a comment with each transition.

For more information see the IBM OpenPages GRC Platform Solutions Guide.

Questionnaire assessments

Questionnaire assessments are based on the following objects:v Assetsv Questionnaire templatesv Programsv Questionnaire assessments

Assets are the existing objects that the questionnaire assessments assess andmeasure. They can be resources, processes, subprocesses, or employees. You usequestionnaire templates to design and write the questions. You use programs to

128 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 141: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

define, launch, and distribute questionnaire assessments to respondents. Thelifecycle guides the questionnaire assessments through the stages, determines whothe asset owners are, and who is allowed to do what task. The lifecycle can betwo-stage, three-stage, or four-stage.

To set up and use questionnaire assessments:1. Plan the questionnaire assessments and program you want to create. Decide

what resources you want to measure, the lifecycle you want it to follow, andthe program you want to use to launch it.

2. Plan the questionnaire template's content (sections, subsections, and questions)and scoring.

3. Create a questionnaire template object.4. Launch the questionnaire template and add content to it.5. If they do not exist, create the assets (resources, processes, subprocesses, or

employees) that the questionnaire assessment is measuring. Identify the assetowners.

6. Create a program. Assign the questionnaire template, a lifecycle, and assets toit. Launch it. The system creates the questionnaire assessments and sends anemail with a link to the respondents. The lifecycle on questionnaire assessmentsbegins and is set to the information gathering stage.

7. Respondents receive and answer questionnaire assessments. As they work, thesystem calculates their progress and compliance and risk scores. Reviewers cansee this information and monitor their progress.

8. Respondents finish the answers and submit their questionnaire assessments.The questionnaire assessments move through the lifecycle stages until they areclosed.

Questionnaire templates, resources, and programs must be in the current reportingperiod. The system issues a message if a respondent opens a questionnaireassessment that is assigned to a resource in a reporting period other than thecurrent reporting period. It also issues a message if you launch a questionnairetemplate or program that is in a reporting period other than the current reportingperiod.

Questionnaire template scores and scoring methodsThe system calculates compliance score and risk score when a respondentcompletes a questionnaire assessment. How these scores are calculated depends onthe scoring method, simple or weighted risk average, that you assign to aquestionnaire template.

Use the simple method if the focus of the questionnaire template is at the questionlevel. The question weight defines the importance of each question. To not applyweights, give all the sections, subsections, and questions the same weight, forexample, 1.

Use the weighted average method if the focus of the questionnaire template is atthe subsection level. Use this method if there are subsections that have a highersignificance than other subsections. The difference between the two methods is thatthe simple method does not calculate a weighted average at the subsection level,which affects the overall results in the compliance and risk scores.

To plan the scoring for a questionnaire template:v Decide what questionnaire scoring method to use: simple or weighted average.

Chapter 12. Reference information 129

Page 142: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Decide what weight to assign to each section and subsection and be consistent.v Decide what answer scores you want to apply to single and multiple choice

questions. Use a higher answer score for better answers, for example, use 10 forthe best answer. Keep the range as small as possible, for example, 1 - 10. Use alarger range only if a question has many answers, for example, more than 10.

v Consider how dynamic questions are scored. Only questions visible to therespondent are included in the scoring. Questions that are hidden from therespondent are excluded.

v Consider that long text and short text questions are excluded from scoring.

For information about the formulas used in scoring see “Questionnaire templatescoring formulas.”

Questionnaire template scoring formulasWhen a respondent answers a questionnaire assessment, the system calculates andupdates the compliance score and risk score every time it is saved. The system alsocalculates total score and max score but they are not displayed to the respondent.To calculate the scores, the system uses formulas that consider the questionnairescoring method and values you provide on the questionnaire template.

You provide the following values on a questionnaire template:

Table 5. Questionnaire template weights and scores

Code Name Value

QW Question weight 0 - 9999, 0 excludes question

AS Answer score -1 to 9999, -1 excludes answer

SW Section weight 0 - 9999, 0 excludes section

SSW Subsection weight 0 - 9999, 0 excludes subsection

The system uses the following formulas:

Table 6. Score formulas

Code Name Formula

QS Question score 0 - 10, formula depends on whether aquestion is single or multi choice. 1

WQS Weighted question score QS * QW

SSS Subsection score for totalscore

Formula depends on the questionnairescoring method. 2

MSSS Subsection score for maxscore

Formula depends on the questionnairescoring method. 3

SS Section score SS = SW * SUM (SSS)

TS Total score TS = Sum SS

MS Max score MS = Sum MSSS

CS Compliance score CS = [TS / MS] *100

RS Risk score RS = MS – TS

How the system calculates question scores1

For single choice questions:

130 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 143: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

QS = [AS / MAX(AS)] * 10

For multi choice questions:QS= [SUM(Selected AS)/ SUM(All AS)] * 10

For short text and long text questions, no question score is calculated.

How the system calculates subsection scores for the total score2

If the questionnaire scoring method is simple:SSS = SSW*SUM(WQS)

If the questionnaire scoring method is weighted average:SSS = SSW* [SUM(WQS)/SUM(QW) * 10]

How the system calculates subsection scores for the max score3

If the questionnaire scoring method is simple:MSSS = SSW * [SUM(QW*10)]

If the questionnaire scoring method is weighted average:MSSS = SSW * 10

The 10 in the max score formulas is the maximum question score.

Chapter 12. Reference information 131

Page 144: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

132 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 145: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 13. Using OpenPages Internal Audit Managementobjects

Getting started

OpenPages Internal Audit Management (IAM)IBM OpenPages Internal Audit Management (IAM) provides internal auditors witha uniquely configured view into organizational governance, risk, and compliance(GRC), affording audit the chance to supplement and coexist with broader risk andcompliance management activities.

As with all solutions, IBM OpenPages Internal Audit Management is completelyintegrated with financial controls management, IT governance, policy andcompliance efforts and operational risk management programs. The internal auditteam has the capability to work as a fully integrated partner to businessstakeholders, completely independently, or anywhere in between, as determined bythe specific needs of the audit department or a particular audit being undertaken.

Key features include:v The capability to risk rank the audit universe, configured according to your

audit methodology– Powerful support for your risk assessment methodology– Full reporting across the entire audit universe

v The ability to define, plan, execute and report on audits across your business– Track and manage audits, audit sections, workpapers, and audit resource

requirements and allocations– Automate operations through fully configurable reporting and workflow

v The ability to provide independent assurance to the business or work as anintegrated part of GRC efforts– Opine on management's GRC efforts independently– Control access to confidential audits, fields, and audit-only views

Working with OpenPages internal audit management objects

Audits

AuditsAn Audit represents each execution of an audit against an Auditable Entity. Forexample, if an Auditable Entity is audited every two years, a separate child Auditinstance must be created for each two year period, such as 2006 and 2008. Anorganization might audit various processes. For example, you could audit anentity, a specific regulatory requirement, or a data center physical security.

The Audit object is configured as a self-contained object type and a folder isautomatically created for each Audit instance. This configuration allows you tocopy template audits and audit components from a library to the audit hierarchywithout object naming conflicts.

133

Page 146: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Planning and scheduling of the Audit resources is done at the Audit level.

High level Audit progress can be tracked by monitoring the Status values and Datevalues on the Audit. Key audit milestones can be tracked by adding fields thatrepresent completion dates for each of the key milestones to track.

Use the Audit object to manage the audit process across your enterprise. The Auditidentifies a holding point to capture information such as scope, objectives, timinginformation, review, execution and approval roles. You can track a subset of auditsthat you are undertaking in a given planning horizon, or all audits in the audituniverse.

Audits Folder ViewThis topic provides information about the Audit Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Audits Detail ViewThis topic provides information about the Audit Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

134 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 147: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Auditable entities

Auditable entitiesAn Auditable Entity object is a child of a Business Entity. An Internal AuditBusiness Entity hierarchy is established and all Auditable Entities are created as achild of the Internal Audit Business Entity object. Auditable Entities that arealigned with elements of the Business Entity Organizational Hierarchy are alsoassociated to those Business Entities.

An Auditable Entity represents a single element of the Audit Universe; thecollection of things in the business that might be audited. Most Auditable Entitiesrepresent business or legal entities, but they can also represent processes,long-running projects or initiatives, compliance programs, or shared IT Services.

Auditable Entities are risk ranked every year to determine the priority ofperforming an audit that year. A Weighted Risk Score is calculated but the scorecan be overridden.

Auditable Entities OverviewThis topic provides information about the Auditable Entities Overview.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Auditable Entities Folder ViewThis topic provides information about the Auditable Entities Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?

Chapter 13. Using OpenPages Internal Audit Management objects 135

Page 148: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Auditable Entities Detail ViewThis topic provides information about the Auditable Entities Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Audit sections

Audit sectionsAudit Sections can be used to represent the phases of the Audit, work programswithin the Audit, or other components of the Audit at the desired level ofgranularity.

136 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 149: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Organizations might have multiple standard components for each Audit. Templateaudits that include sections for each standard component can be created in alibrary. Planned and Actual Start and End Dates for these sections are used toreport progress on key milestones in the audits.

Detailed Audit progress can be tracked by including an Audit Section for eachmilestone. Alternatively, some organizations might add fields on the Audit thatrepresent completion dates for each of the key milestones they wish to track.

Although Audit Sections can be used for planning and scheduling Audit resources,most organizations find this method to be too detailed.

Audit Sections Folder ViewThis topic provides information about the Audit Sections Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Audit Sections Detail ViewThis topic provides information about the Audit Sections Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

Chapter 13. Using OpenPages Internal Audit Management objects 137

Page 150: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Plans

PlansA Plan object type facilitates audit resource scheduling and allocation at any level.For example, you can create a single Plan object for an entire audit, or you cancreate one Plan object per task for each auditor involved with the audit. Planobjects are used to determine the availability, skills, and experience required of thedesired resource. OpenPages Audit Activity Views, reports, etc. are aligned withPlanning at the Audit level. Plans can instead be associated to Audit Sections, inwhich case these components would need to be modified.

Plan objects also drive time tracking - all time is tracked against Plans. ATimesheet object type is used to record weekly actual hours and expensesexpended against a Plan object for an Audit. Because Timesheet objects areassociated with Plans, it is easy to track deviations between planned and actualtime and expenses. The Timesheet Entry interactive report should always be usedto enter or modify time and expense data. For this reason, there is no Timesheettop menu item in the default OpenPages Internal Audit Managementconfiguration.

You typically create or modify a Plan object using the Add or Modify Plans helper,accessed from a link on the Audit detail page.

Plans Folder ViewThis topic provides information about the Plan Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

138 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 151: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Plans Detail ViewThis topic provides information about the Plans Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Workpapers

WorkpapersA Workpaper is any artifact or deliverable you want to track in the scope of anaudit. It can represent an engagement letter, a testing matrix, interview notes oranything else appropriate to the audit in question. The workpaper itself can beattributes stored on the Workpaper object, or it can be a Microsoft Word, MicrosoftExcel or other type of file attached to a Workpaper object. When Workpaper isused for test evidence, it documents both the test planning and the test results.

Create a Workpaper object from the detail page of an Audit Section. Workpaperobjects can also be copied from a library, where they represent templates ofdifferent types of workpapers generated by an internal audit department.

Workpapers Folder ViewThis topic provides information about the Workpapers Folder View.

Chapter 13. Using OpenPages Internal Audit Management objects 139

Page 152: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Workpapers Detail ViewThis topic provides information about the Workpapers Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

140 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 153: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Findings

FindingsFindings can be used to represent observations which are reportable to thebusiness, to the Audit Committee, or both. Alternatively, Findings can be used torepresent individual factual observations, while Issues are used to representconsolidated themes and systemic problems, which are then reported to thebusiness, to the Audit Committee, or both.

A Finding represents anything uncovered in the course of an audit that needs to beaccounted for and addressed by management. You can use a finding to trackmanagement's progress in addressing the underlying issue identified. The Issueobject can be used in place of, or in conjunction with, the Finding object.

Findings Folder ViewThis topic provides information about the Findings Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Findings Detail ViewThis topic provides information about the Findings Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?

Chapter 13. Using OpenPages Internal Audit Management objects 141

Page 154: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Auditors

AuditorsResource planning and allocating requires key information about each individualwho might perform audit work. The Auditor object is used to create a pool ofAuditors who can be assigned to Audits.

Each user who is assigned to audit work is represented as an Auditor instance.Auditors are then available for resource allocation. The Auditor object includesattributes to use to evaluate and select Auditors for audit engagements, such asspecialties, languages, and certifications. Auditor objects are associated with therelevant component of the Internal Audit organizational hierarchy. As a bestpractice, match the Name on the Auditor object with the username.

Auditors Folder ViewThis topic provides information about the Auditors Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Auditors Detail ViewThis topic provides information about the Auditors Detail View.

142 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 155: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Audit review comments

Audit review commentsThe Audit Review Comment object type is used to provide feedback during thereview process for an Audit and its components. It is associated as a child to theinstance of the Audit, Section, Workpaper or Finding for which feedback is beingprovided.

Audit Review Comments Folder ViewThis topic provides information about the Audit Review Comments Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Chapter 13. Using OpenPages Internal Audit Management objects 143

Page 156: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Audit Review Comments Detail ViewThis topic provides information about the Audit Review Comments Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

144 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 157: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 14. Using OpenPages IT Governance objects

Getting Started

OpenPages IT GovernanceIBM OpenPages IT Governance (ITG) is an enterprise IT Governance solution thataligns IT services, risks and policies with corporate business initiatives, strategy,and operational standards.

IBM OpenPages IT Governance allows you to manage internal IT control and riskaccording to the business processes they support. In addition, IBM OpenPages ITGovernance unites multiple silos of IT risk and compliance to deliver improvedvisibility, better decision support, and ultimately enhanced corporate performance.

Key features include:v IT Regulatory and Policy Compliancev Risk and Control Assessmentsv Control Testing and Issue Remediationv IT Resource Managementv Incident Trackingv Key Performance and Key Risk Indicatorsv Reporting, monitoring and analytics

IBM OpenPages IT Governance terms you should knowThis topic provides terms to use in IBM OpenPages IT Governance.

ApplicationAn object that defines a software program that is used to support an ITservice.

IncidentAn object that records an IT occurrence that has an actual or potentiallyadverse effect on your enterprise.

InfrastructureAn object that defines the physical equipment or physical location that isused to support an IT service.

Library A holding area for the mandates that are relevant to your enterprise.

Mandate(1) An obligation to which an enterprise must comply. A mandate can be agovernmental regulation (local, federal, or international), a best practicestandard established by a standards organization, or an internal companypolicy. (2) An object used to establish your enterprise's compliancemanagement process for a specific regulation or policy, such as PCI.

Personnel An object that identifies the type of human resource (DBA, systemadministrator, business team, etc.) that is required to support an IT service.

145

Page 158: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

ResourcePersonnel, infrastructure, or application that is used to support an ITservice.

Sub-mandateAn object used to establish the compliance management process for asub-section of a regulation or policy. Usually a child of a Mandate object.

Working with IT Governance Objects

Mandates

Mandates

Mandates represent external items with which organizations need to comply, suchas laws, regulations, and standards. Out of the box the configuration directlysupports content provided by Deloitte and UCF, and can be adapted to supportcontent from other vendors. Mandates are represented in a Library Business Entitystructure, and are not replicated throughout the system. For example, an insurancecompany has a Mandate object for HIPAA and another Mandate object for GLBA.You can associate the same mandate with different groups within yourorganization. Privacy mandates, for example, might apply to payroll, insuranceservices, legal, and IT departments. Mandate also supports content for regulatorycompliance. Regulations can be extracted from IBM Regulatory ComplianceAnalytics and populated as Mandates for IBM OpenPages Regulatory ComplianceManagement.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

146 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 159: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Mandates OverviewThis topic provides information about the Mandates Overview page.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Mandates Folder ViewThis topic provides information about the Mandates Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Mandates Detail ViewThis topic provides information about the Mandates Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?

Chapter 14. Using OpenPages IT Governance objects 147

Page 160: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Mandates

Sub-MandatesSub-Mandates represent external (or internal) sub-items with which theorganization needs to comply. Out of the box the configuration directly supportscontent provided by Deloitte and UCF, and the configuration can be adapted tosupport content from other vendors. Typically, Sub-Mandates are represented in aLibrary Business Entity structure, and are not replicated throughout the system.Sub-Mandate is recursive, but Deloitte and UCF content use exactly one level ofSub-Mandate. Sub-Mandates also support content for regulatory compliance.Sub-mandates can be used to represent paragraphs derived from regulatorypapers. Paragraphs can be extracted from IBM Regulatory Compliance Analyticsand populated as Sub-Mandates for regulatory compliance management.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an object

148 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 161: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Mandates Folder ViewThis topic provides information about the Sub-Mandates Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Mandates Detail ViewThis topic provides information about the Sub-Mandates Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

Chapter 14. Using OpenPages IT Governance objects 149

Page 162: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Requirements

RequirementsA requirement represents a collection of controls with which an organization mustcomply. Generally, a requirement is not specific to a single mandate and can spanmultiple mandates. The Requirement object simplifies the management of controls.

For example:v Which object types and actions are available on a page depends on your

particular setup and permissions.v To access the Requirements option on the Compliance menu and the My

Requirements tab on your Home page, you must have the necessary permissionsset on your account.

Typically, you create requirements as standalone objects from the RequirementFolder View page that you can later associate to other objects. Alternatively, youcan also create a Requirement object from the detail page of a parent object (suchas control objectives, controls, mandates, or sub-mandates).

From the detail page of a Requirement object, you can create, associate, ordisassociate child objects (such as issues, signatures, files, or links), associate parentobjects, view change history for and edit the property fields of a Requirementobject.

You can access the Requirements menu item from the Compliance menu on themenu bar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

150 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 163: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Requirements Folder ViewThis topic provides information about the Requirements Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Requirements Detail ViewThis topic provides information about the Requirements Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?

Chapter 14. Using OpenPages IT Governance objects 151

Page 164: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Plans

Control plansControl Plan is a self-contained object type; this means that folders are created foreach Control Plan. It groups multiple Baselines to represent elements in theoperating environment that can be assessed for risk. It acts as a container for acollection of Baseline objects that together perform a function or comprise an ITservice. For example, a Control Plan object could represent the servers, operatingsystems, applications, databases, support personnel, and facilities that provide thecorporate email.

From the detail page of a Control Plan object, you can associate parent objects,attach files or links, view change history, and edit the Control Plan object propertyfields.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

152 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 165: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Plans OverviewThis topic provides information about the Control Plans Overview

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Plans Folder ViewThis topic provides information about the Control Plans Folder View page.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Control Plans Detail ViewThis topic provides information about the Control Plans Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?

Chapter 14. Using OpenPages IT Governance objects 153

Page 166: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Baselines

BaselinesA Baseline object type represents a template of library requirements. It isself-contained, meaning folders are created for each Baseline. Baselines in theLibrary represent elements of the IT operating environment. They are linked toRequirements for that type of element. The Baseline object is copied from thelibrary to the business hierarchy, an association is made to a Requirement in thelibrary, and Risk, Control, and Test object types are created as child objects. TheRisk, Control, and Test objects are populated with data from the Requirement.

For example, a Baseline object can represent a collection of Requirement objects fora data center with Personally Identifiable Information (PII) and a Confidential Dataclassification. For each Requirement object, set up a best practice to define what tocontrol (Risk object) and how to control it (Control object). You can also establish apractice for verifying the effectiveness of the Control (Test object).

Typically, Baseline objects are created in the library as a starting point. Baselineobject content will later be modified to conform to a specific operatingenvironment, and assessments will be performed against the actual operatingenvironment for this content.

You add a Baseline object via the Add a Baseline link on a Control Plan's detailpage. The Baseline object is copied from the library to the business hierarchy, anassociation is made to a Requirement in the library, and Risk, Control, and Testobject types are created as child objects of the Baseline object. The Risk, Control,and Test objects are populated with appropriate data from the Requirement.

From the detail page of a Baseline object, you can associate parent objects, attachfiles or links, view change history, and edit the Baseline object property fields.

154 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 167: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Baselines Folder ViewThis topic provides information about the Baselines Folder View page.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Baselines Detail ViewThis topic provides information about the Baselines Detail View.

Chapter 14. Using OpenPages IT Governance objects 155

Page 168: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I Add?v New child object to an object?v File, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v “Copying objects” on page 21v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v “Navigating to an object's detail page” on page 21v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Resources and Resource Links

ResourcesThe Resource object type is used to represent categories of personnel, applications,infrastructure, processes, facilities, and functions.

Note: Which object types and actions are available on a page depends on yourparticular setup and permissions.

Although Resource objects can represent an individual IT asset (for example, aparticular application server), they more often represent a group of assets, such asa pool of application servers used for a specific application.

Typically, Resource objects are created by the owning or responsible IT businessentity, and then associated with the object they support such as Business Entities,Processes, and Baselines.

You can access the Resources menu item from the Assets menu on the menu bar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

156 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 169: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Resource linkResource objects of the same type often need to be related to each other. You canuse a Resource Link® object type to link two Resource objects.

You can click the Create Resource Link on a Resource object detail page to createlinks to another Resource. Various filtering options allow you to select theResource that you want to link to the Resource on the detail page. The ResourceLink that is created is a child object of both of the linked Resources and ispopulated with the attributes of the parent objects.

Note that if the names or attributes of either parent Resource objects are changedafter the Resource Link is created, the Resource Link name and its attributes willno longer correctly map to its parent Resources.

Users with administration permissions can access the Resource Links menu itemfrom the Administration > Object Menu selection on the menu bar.

Resources and Resources Links Folder ViewThis topic provides information about the Resources and Resources Links FolderView.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?

Chapter 14. Using OpenPages IT Governance objects 157

Page 170: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Resources and Resource Links Detail ViewThis topic provides information about the Resources and Resource Links DetailView.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Incidents

IncidentsAn incident is an occurrence that has a potentially adverse effect on yourenterprise. Create an Incident object to record information, such as the personresponsible for investigating the incident and other related data. The Incidentobject is used with lifecycles to facilitate incident analysis. Categories that apply to

158 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 171: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

incidents include Regulatory Compliance, Legal Compliance, Information Security,and IT. Incidents are stored under the Business Entity or IT Resource where theevent occurred and associated secondarily to an impacted Mandate or Policy.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Incidents Folder ViewThis topic provides information about the Incidents Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 14. Using OpenPages IT Governance objects 159

Page 172: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Incidents Detail ViewThis topic provides information about the Incidents Detail View.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?v View information about lifecycles?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?v What are lifecycles?

Key Risk Indicators (KRI) and Values

KRIs and KRI valuesKRIs (Key Risk Indicators) are components of the risk monitoring process and areused to provide leading or lagging indicators for potential risk conditions. Eachinstance of a KRI within the organization can have unique target and thresholdlimits. KRI values are used to record the actual value of an indicator at a specificpoint in time.

You create and associate a KRI from the detail page of a parent object type (forexample, Risk, Control, Business Entity). From the detail page of a KRI object, youcan associate one or more parent business entities, risks or controls, and create,copy, and/or associate one or more KRI values and issues.

Note: You can associate KRIs with controls. Some KRIs can function like controlindicators by signaling that a control is not working properly. For example, you setup several security perimeter controls with an associated KRI. If your companyexperiences a significant number of security breaches, the associated KRI canindicate that your security perimeter controls are not effective.

KRI values are used to record the actual value of an indicator at a specific point intime.

You can access the KRI and KRI Values menu items from the Indicators menu onthe menu bar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filter

160 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 173: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Risk Indicators (KRI) and Values Folder ViewThis topic provides information about the Key Risk Indicators (KRI) and ValuesFolder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Risk Indicators (KRI) and Values Detail ViewThis topic provides information about the Key Risk Indicators (KRI) and ValuesDetail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?

Chapter 14. Using OpenPages IT Governance objects 161

Page 174: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values

KPIs and KPI valuesKPIs (Key Performance Indicators) are components of the risk monitoring processand are used to provide leading or lagging indicators for potential risk conditions.Each instance of a KPI within the organization can have unique target andthreshold limits. The KPI Value object type records the value of a KPI object at aspecific point. Create a KPI object, and then periodically (daily, weekly, monthly)create a KPI Value object so you can detect trends.

A KPI object can be associated with one or more parent object types (such as,Business Entity, Control, Control Plans, Process, Sub-Process). Typically, you createand associate a KPI from the detail page of a parent object type.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a column

162 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 175: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values Folder ViewThis topic provides information about the Key Performance Indicators (KPI) andValues Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values Detail ViewThis topic provides information about the Key Performance Indicators (KPI) andValues Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?

Chapter 14. Using OpenPages IT Governance objects 163

Page 176: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Waivers

WaiversWaivers give you the ability to document, process and manage the lifecycle ofexceptions to Corporate Policies, InfoSec Policies, IT Policies or RegulatoryCompliance Requirements. Waivers can be associated to Business Entities, Policies,Procedures, Requirements, Risks, Controls, Baselines and Resources.

Some business examples of exceptions for which waivers may be requested includethe following:v Deviation from Policy (such as corporate, information security, and IT policies)v Accepting Riskv Authority to Operate (ATO)v Interim ATO - allows a process to move forward prior to receiving certification

(part of NIST guideline 800-37)

From the detail page of a Waiver object, you can associate parent objects, attachfiles or links, view change history, and edit the Waiver object property fields.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21

164 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 177: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Waivers Folder ViewThis topic provides information about the Waivers Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Waivers Detail ViewThis topic provides information about the Waivers Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

Chapter 14. Using OpenPages IT Governance objects 165

Page 178: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policies

PoliciesPolicies represent internal guidelines generally adopted by the Board of Directorsor senior governance body within an organization. The text of a Policy can eitherbe stored in standardized fields on the object or as an attachment to the object.Policies typically have a distinct lifecycle from Draft to Published to Expired, aswell as a review and approval process. Draft policies typically reside in theOrganizational Business Hierarchy, while Published and Expired Policies typicallyreside in reference Library entities. Policies are also often mapped to applicableMandates in the Library to which they relate.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

166 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 179: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Policy OverviewThis topic provides information about the Policy Overview page.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policies Folder ViewThis topic provides information about the Policies Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policies Detail ViewThis topic provides information about the Policies Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?

Chapter 14. Using OpenPages IT Governance objects 167

Page 180: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Procedures

ProceduresProcedures represent the what, where, when, and how of how policies areimplemented in an organization. The text of Procedures is typically stored in thefields on the object. Typically, Procedures are represented as children of a Policyand reside in the same entity structure as its parent Policy.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

168 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 181: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Procedures Folder ViewThis topic provides information about the Procedures Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Procedures Detail ViewThis topic provides information about the Procedures Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?

Chapter 14. Using OpenPages IT Governance objects 169

Page 182: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are search filters?v What are alerts and can I change my notification options?

170 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 183: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 15. Using Operational Risk Management objects

Getting started

OpenPages Operational Risk ManagementIBM OpenPages Operational Risk Management combines document and processmanagement with a monitoring and decision support system that enablesorganizations to analyze, manage, and mitigate risk in a simple and efficientmanner.

OpenPages Operational Risk Management helps automate the process ofmeasuring and monitoring operational risk. It combines all risk data, including riskand control self assessments, loss events, scenario analysis, external losses, and keyrisk indicators (KRI), into a single integrated solution.

OpenPages Operational Risk Management includes the following key features:v Loss Events, which include the following activities:

– Tracking, assessing, and managing both internal and external events thatcould result in operational loss.

– Managing multiple impact events and recoveries that are associated withoperational losses.

v Risk and Control Self Assessments (RCSA), which include the followingactivities:– Identification, measurement, and mitigation of risks.– Testing and documentation of internal controls.

v Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), which cantrack performance metrics to potentially show the presence or state of a riskcondition or trend.

v Scenario Analysis, which is an assessment technique that is used to identify andmeasure specific kinds of risks, in particular, low frequency, high-severity events.

v External Loss Events provide the ability to import loss data from IBM Algo®

FIRST, ORX, and ORIC loss databases into OpenPages Operational RiskManagement for scenario analysis, benchmarking, and reports generation. Youcan also export loss data to analytic tools or capital allocation applications.

v Issue Management and Remediation (IMR), which includes the followingactivities:– Issue Creation and Assignment– Action Creation and Assignment– Remediation Performance– Issue closedown– Reporting

v Reporting, monitoring, and analytics.

171

Page 184: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Working with Operational Risk Management objects

Key Risk Indicators (KRI) and Values

KRIs and KRI valuesKRIs (Key Risk Indicators) are components of the risk monitoring process and areused to provide leading or lagging indicators for potential risk conditions. Eachinstance of a KRI within the organization can have unique target and thresholdlimits. KRI values are used to record the actual value of an indicator at a specificpoint in time.

You create and associate a KRI from the detail page of a parent object type (forexample, Risk, Control, Business Entity). From the detail page of a KRI object, youcan associate one or more parent business entities, risks or controls, and create,copy, and/or associate one or more KRI values and issues.

Note: You can associate KRIs with controls. Some KRIs can function like controlindicators by signaling that a control is not working properly. For example, you setup several security perimeter controls with an associated KRI. If your companyexperiences a significant number of security breaches, the associated KRI canindicate that your security perimeter controls are not effective.

KRI values are used to record the actual value of an indicator at a specific point intime.

You can access the KRI and KRI Values menu items from the Indicators menu onthe menu bar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

172 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 185: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Risk Indicators (KRI) and Values Folder ViewThis topic provides information about the Key Risk Indicators (KRI) and ValuesFolder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Risk Indicators (KRI) and Values Detail ViewThis topic provides information about the Key Risk Indicators (KRI) and ValuesDetail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

Chapter 15. Using Operational Risk Management objects 173

Page 186: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values

KPIs and KPI valuesKPIs (Key Performance Indicators) are components of the risk monitoring processand are used to provide leading or lagging indicators for potential risk conditions.Each instance of a KPI within the organization can have unique target andthreshold limits. The KPI Value object type records the value of a KPI object at aspecific point. Create a KPI object, and then periodically (daily, weekly, monthly)create a KPI Value object so you can detect trends.

A KPI object can be associated with one or more parent object types (such as,Business Entity, Control, Control Plans, Process, Sub-Process). Typically, you createand associate a KPI from the detail page of a parent object type.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

174 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 187: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values Folder ViewThis topic provides information about the Key Performance Indicators (KPI) andValues Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values Detail ViewThis topic provides information about the Key Performance Indicators (KPI) andValues Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Chapter 15. Using Operational Risk Management objects 175

Page 188: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Loss events

Loss eventsLoss Events are used to track operational losses that occur in any part of anorganization. Loss Events are typically stored under the Business Entity where theloss occurred. The Loss Event objects are used to track, assess, and manage therelated internal loss data. You can add multiple impacts and recoveries for eachLoss Event using the Loss Impact and Loss Recovery objects. Loss Event, LossImpact, and Loss Recovery objects can also be created in IBM OpenPages LossEvent Entry.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Loss Events OverviewThis topic provides information about the Loss Events Overview page.

How do I...v Add a folder?v Navigate to a Detail Page?

176 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 189: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Loss Events Folder ViewThis topic provides information about the Loss Events Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Loss Events Detail ViewThis topic provides information about the Loss Events Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?

Chapter 15. Using Operational Risk Management objects 177

Page 190: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Loss impacts

Loss impactsA loss impact is a financial and non-financial consequence resulting from a lossevent. Loss Impacts track different types of impacts triggered by a Loss Event,such as legal liability, asset loss and damage, or business interruption. There can bemultiple Loss Impacts associated with each Loss Event.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

178 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 191: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Loss Impact Folder ViewThis topic provides information about the Loss Impact Folder View page.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Loss Impact Detail ViewThis topic provides information about the Loss Impact Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 15. Using Operational Risk Management objects 179

Page 192: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Loss recovery

Loss recoveriesLoss Recovery objects are used to track the processes associated with recoupingdamages that result from Loss Events.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Loss Recoveries Folder ViewThis topic provides information about the Loss Recovery Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?

180 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 193: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are search filters?v What are alerts and can I change my notification options?

Loss Recoveries Detail ViewThis topic provides information about the Loss Recovery Detail View

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Scenario analyses

Scenario analysisScenario Analysis is an assessment technique used to identify and measure specifickinds of risks, in particular, low frequency, high-impact events such asearthquakes, recessions, or power grid failures.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filter

Chapter 15. Using Operational Risk Management objects 181

Page 194: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Scenario Analyses Folder ViewThis topic provides information about the Scenario Analyses Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Scenario Analyses Detail ViewThis topic provides information about the Scenario Analyses Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?

182 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 195: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Scenario results

Scenario resultsScenario Result objects are children of Scenario Analysis objects and they are usedto capture the results of Scenario Analysis workshops for comparison and trendingpurposes.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Chapter 15. Using Operational Risk Management objects 183

Page 196: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Scenario Results Folder ViewThis topic provides information about the Scenario Results Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Scenario Results Detail ViewThis topic provides information about the Scenario Results Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

184 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 197: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

FIRST losses

FIRST lossesFIRST Loss objects can be imported from the FIRST external loss database, for usewith scenario analysis, benchmarking, and reports generation, and to export lossdata to analytic tools or capital allocation applications. FIRST Loss objects are oftenorganized by loss categories, such as product lines or event types. For example,use a Business Entity to create a hierarchy for FIRST loss data. Name the rootobject “FIRST-data”, and create category folders under the root. Link externallosses to it.

Typically, you create a FIRST Loss object from a parent Business Entity that residesin a library structure. The FIRST Loss object is a child of the library Business Entityand can then be associated to Scenario Analysis and other Business Entity objecttypes.

From the detail page of an FIRST Loss object, you can associate parent objects,attach files or links, view change history, and edit the FIRST Loss object propertyfields.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

Chapter 15. Using Operational Risk Management objects 185

Page 198: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

FIRST Losses Folder ViewThis topic provides information about the FIRST Losses Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

FIRST Losses Detail ViewThis topic provides information about the FIRST Losses Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?

186 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 199: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are search filters?v What are alerts and can I change my notification options?

ORIC losses

ORIC lossesORIC Loss objects can be imported from the ORIC external loss database, for usewith scenario analysis, benchmarking, and reports generation, and to export lossdata to analytic tools or capital allocation applications.

ORIC Loss objects are typically organized by loss categories (such as by productlines or event types) into a non-business library structure. For example, you coulduse a Business Entity object type to create a hierarchy for ORIC loss data, name theroot object ORIC data, and create category folders under the root and link externallosses to it.

Typically, you create an ORIC Loss object from a parent Business Entity thatresides in a library structure. The ORIC Loss object is a child of the libraryBusiness Entity and can then be associated to Scenario Analysis and other BusinessEntity object types.

From the detail page of an ORIC Loss object, you can associate parent objects,attach files or links, view change history, and edit the ORIC Loss object propertyfields.

You can access the ORIC Losses menu item from the Events menu on the menubar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?

Chapter 15. Using Operational Risk Management objects 187

Page 200: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are search filters?v What are alerts and can I change my notification options?

ORIC Losses Folder ViewThis topic provides information about the ORIC Losses Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

ORIC Losses Detail ViewThis topic provides information about the ORIC Losses Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

188 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 201: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

ORX losses

ORX lossesORX Loss objects can be imported from the ORX external loss database, for usewith scenario analysis, benchmarking, and reports generation, and to export lossdata to analytic tools or capital allocation applications. You can import externalORX loss data into OpenPages Operational Risk Management

ORX Loss objects are typically organized by loss categories (such as by productlines or event types) into a non-business library structure. For example, you coulduse a Business Entity object type to create a hierarchy for ORX loss data, name theroot object ORX data, and create category folders under the root and link externallosses to it.

Typically, you create an ORX Loss object from a parent Business Entity that residesin a library structure. The ORX Loss object is a child of the library Business Entityand can then be associated to Scenario Analysis and other Business Entity objecttypes.

From the detail page of an ORX Loss object, you can associate parent and childobjects, attach files or links, view change history, and edit the ORX Loss objectproperty fields.

You can access the ORX Losses menu item from the Events menu on the menubar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an object

Chapter 15. Using Operational Risk Management objects 189

Page 202: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

ORX Losses Folder ViewThis topic provides information about the ORX Losses Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

ORX Losses Detail ViewThis topic provides information about the ORX Losses Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

190 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 203: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Cost centers

Cost centersCost Center objects are used to group loss events under a business entity. In manycases, firms want to track where loss events occur at a fine granularity, such as costcenter level, but do not want to represent all of the organizational layers asbusiness entities.

Typically, you create a Cost Center object from the detail page of a parent BusinessEntity. You can then associate child Loss Event objects to a parent Cost Centerobject.

From the detail page of a Cost Center object, you can create, associate, ordisassociate objects, attach files or links, view change history and edit the propertyfields of the Cost Center object.

You can access the Cost Centers menu item from the Organizations menu on themenu bar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Chapter 15. Using Operational Risk Management objects 191

Page 204: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Cost Centers Folder ViewThis topic provides information about the Cost Centers Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Cost Centers Detail ViewThis topic provides information about the Cost Centers Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

192 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 205: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 15. Using Operational Risk Management objects 193

Page 206: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

194 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 207: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 16. Using OpenPages Policy and ComplianceManagement objects

Getting started

OpenPages Policy and Compliance ManagementIBM OpenPages Policy and Compliance Management is an enterprise compliancemanagement software solution that reduces the cost, complexity, and cumbersomenature of compliance with multiple regulatory mandates and corporate policies.

IBM OpenPages Policy and Compliance Management allows companies to manageand monitor compliance activities through a full set of integrated functionalityincluding:v Regulatory Libraries and Change Managementv Risk and Control Assessmentsv Policy Management, including Policy Creation, Review & Approval and Policy

Awarenessv Control Testing and Issue Remediationv Regulator Interaction Managementv Incident Trackingv Key Performance Indicatorsv Reporting, monitoring, and analytics

Within IBM OpenPages Policy and Compliance Management, IBM OpenPages GRCPlatform supports three approaches:

DatacentricPolicy attributes are stored as metadata in the Policy object. Policy andProcedure content is created, stored, edited, and reviewed in PolicyViewers. Red-lined track changes within draft iterations are not supported.

DocucentricPolicy attributes are stored as metadata in the Policy object. Policy andProcedure content is created outside of OpenPages GRC Platform and theentire document is attached to the Policy Object. Policy and Procedurecontent is never imported nor stored in OpenPages GRC Platform.

HybridPolicy attributes are stored as metadata in the Policy object. Policy andProcedure content is created and edited in Microsoft Word documents thenimported and stored in OpenPages GRC Platform. The Track Changesfunctionality available in Microsoft Word is used for tracking red-linechanges within draft iterations.

For more information, see the OpenPages GRC Platform PCM Solution Detailsdocument.

195

Page 208: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

IBM OpenPages Policy and Compliance Management termsyou should know

This topic provides terms you should know to use the OpenPages Policy andCompliance Management.

Sub-mandateAn object used to establish the compliance management process for asub-section of a regulation or policy. Usually a child of a Mandate object.

LibraryA business entity that contains the text of the regulations that are relevantto your enterprise. Within the business entity, each regulation isrepresented by a mandate.

Mandate(1) An obligation to which an enterprise must comply. A mandate can be agovernmental regulation (local, federal, or international), a best practicestandard established by a standards organization, or an internal companypolicy. (2) An object used to establish your enterprise's compliancemanagement process for a specific regulation or policy, such as HIPAA orGLBA.

Working with Policy and Compliance Management objects

Regulation applicabilities

Regulation applicabilitiesThe Regulation Applicability object resides in the organizational business hierarchy.It assesses and tracks the regulatory impact of a Mandate in the library on aBusiness Entity.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

196 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 209: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulation Applicabilities Folder ViewThis topic provides information about the Regulation Applicabilities Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulation Applicabilities Detail ViewThis topic provides information about the Regulation Applicabilities Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Chapter 16. Using OpenPages Policy and Compliance Management objects 197

Page 210: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Mandates

Mandates

Mandates represent external items with which organizations need to comply, suchas laws, regulations, and standards. Out of the box the configuration directlysupports content provided by Deloitte and UCF, and can be adapted to supportcontent from other vendors. Mandates are represented in a Library Business Entitystructure, and are not replicated throughout the system. For example, an insurancecompany has a Mandate object for HIPAA and another Mandate object for GLBA.You can associate the same mandate with different groups within yourorganization. Privacy mandates, for example, might apply to payroll, insuranceservices, legal, and IT departments. Mandate also supports content for regulatorycompliance. Regulations can be extracted from IBM Regulatory ComplianceAnalytics and populated as Mandates for IBM OpenPages Regulatory ComplianceManagement.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

198 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 211: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Mandates Folder ViewThis topic provides information about the Mandates Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Mandates Detail ViewThis topic provides information about the Mandates Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 16. Using OpenPages Policy and Compliance Management objects 199

Page 212: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Sub-Mandates

Sub-MandateSub-Mandates represent external or internal sub-items with which the organizationneeds to comply.

Out of the box the configuration directly supports content provided by Deloitteand UCF, and the configuration can be adapted to support content from othervendors. Typically, Sub-Mandates are represented in a Library Business Entitystructure, and are not replicated throughout the system. Sub-Mandate is recursive,but Deloitte and UCF content use exactly one level of Sub-Mandate.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Mandates Folder ViewThis topic provides information about the Sub-Mandates Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?

200 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 213: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Mandates Detail ViewThis topic provides information about the Sub-Mandates Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Requirements

RequirementsRequirement object types represent the normalized “things you need toaccomplish” to comply with all of their associated Sub-Mandate objects.

Requirement objects accomplish two primary purposes: they translate the oftendifficult and wordy legal jargon of Mandates/Sub-Mandates into plain English,and they use the commonality across multiple Sub-Mandates. For example, therecan be many Sub-Mandates across numerous Mandates that require the use ofstrong passwords. A single Requirement object can document the details for strongpasswords. By complying with this single Requirement, IT can satisfy many

Chapter 16. Using OpenPages Policy and Compliance Management objects 201

Page 214: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Mandates and/ or Sub-Mandates. Default configuration directly supports contentprovided by Deloitte and UCF, and can be adapted to support content from othervendors. Typically, Requirement objects are represented in a library Business Entitystructure, and are not replicated throughout the system.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Requirements Folder ViewThis topic provides information about the Requirements Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

202 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 215: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Requirements Detail ViewThis topic provides information about the Requirements Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Risk Indicators (KRI) and Values

KRIs and KRI valuesKRIs (Key Risk Indicators) are components of the risk monitoring process and areused to provide leading or lagging indicators for potential risk conditions. Eachinstance of a KRI within the organization can have unique target and thresholdlimits. KRI values are used to record the actual value of an indicator at a specificpoint in time.

You create and associate a KRI from the detail page of a parent object type (forexample, Risk, Control, Business Entity). From the detail page of a KRI object, youcan associate one or more parent business entities, risks or controls, and create,copy, and/or associate one or more KRI values and issues.

Note: You can associate KRIs with controls. Some KRIs can function like controlindicators by signaling that a control is not working properly. For example, you setup several security perimeter controls with an associated KRI. If your companyexperiences a significant number of security breaches, the associated KRI canindicate that your security perimeter controls are not effective.

Chapter 16. Using OpenPages Policy and Compliance Management objects 203

Page 216: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

KRI values are used to record the actual value of an indicator at a specific point intime.

You can access the KRI and KRI Values menu items from the Indicators menu onthe menu bar.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Risk Indicators (KRI) and Values Folder ViewThis topic provides information about the Key Risk Indicators (KRI) and ValuesFolder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

204 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 217: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Risk Indicators (KRI) and Values Detail ViewThis topic provides information about the Key Risk Indicators (KRI) and ValuesDetail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Incidents

IncidentsAn incident is an occurrence that has a potentially adverse effect on yourenterprise. Create an Incident object to record information, such as the personresponsible for investigating the incident and other related data. The Incidentobject is used with lifecycles to facilitate incident analysis. Categories that apply toincidents include Regulatory Compliance, Legal Compliance, Information Security,and IT. Incidents are stored under the Business Entity or IT Resource where theevent occurred and associated secondarily to an impacted Mandate or Policy.

Filtered List ViewThis topic provides links to information about the Filtered List View.

Chapter 16. Using OpenPages Policy and Compliance Management objects 205

Page 218: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Incidents Folder ViewThis topic provides information about the Incidents Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Incidents Detail ViewThis topic provides information about the Incidents Detail View.

206 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 219: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?v View information about lifecycles?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?v What are lifecycles?

Waivers

WaiversWaivers give you the ability to document, process and manage the lifecycle ofexceptions to Corporate Policies, InfoSec Policies, IT Policies or RegulatoryCompliance Requirements. Waivers can be associated to Business Entities, Policies,Procedures, Requirements, Risks, Controls, Baselines and Resources.

Some business examples of exceptions for which waivers may be requested includethe following:v Deviation from Policy (such as corporate, information security, and IT policies)v Accepting Riskv Authority to Operate (ATO)v Interim ATO - allows a process to move forward prior to receiving certification

(part of NIST guideline 800-37)

From the detail page of a Waiver object, you can associate parent objects, attachfiles or links, view change history, and edit the Waiver object property fields.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21

Chapter 16. Using OpenPages Policy and Compliance Management objects 207

Page 220: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Waivers Folder ViewThis topic provides information about the Waivers Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Waivers Detail ViewThis topic provides information about the Waivers Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

208 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 221: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values

KPIs and KPI valuesKPIs (Key Performance Indicators) are components of the risk monitoring processand are used to provide leading or lagging indicators for potential risk conditions.Each instance of a KPI within the organization can have unique target andthreshold limits. The KPI Value object type records the value of a KPI object at aspecific point. Create a KPI object, and then periodically (daily, weekly, monthly)create a KPI Value object so you can detect trends.

A KPI object can be associated with one or more parent object types (such as,Business Entity, Control, Control Plans, Process, Sub-Process). Typically, you createand associate a KPI from the detail page of a parent object type.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?

Chapter 16. Using OpenPages Policy and Compliance Management objects 209

Page 222: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values Folder ViewThis topic provides information about the Key Performance Indicators (KPI) andValues Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Key Performance Indicators (KPI) and Values Detail ViewThis topic provides information about the Key Performance Indicators (KPI) andValues Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

210 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 223: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policies

PoliciesPolicies represent internal guidelines generally adopted by the Board of Directorsor senior governance body within an organization. The text of a Policy can eitherbe stored in standardized fields on the object or as an attachment to the object.Policies typically have a distinct lifecycle from Draft to Published to Expired, aswell as a review and approval process. Draft policies typically reside in theOrganizational Business Hierarchy, while Published and Expired Policies typicallyreside in reference Library entities. Policies are also often mapped to applicableMandates in the Library to which they relate.

Policy OverviewThis topic provides information about the Policy Overview page.

How do I...v “Adding an object instance with the Add New wizard” on page 14v “Navigating to an object's detail page” on page 21v Refresh the information displayed on this page?v Select a different report period for this view?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21

Chapter 16. Using OpenPages Policy and Compliance Management objects 211

Page 224: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policies Folder ViewThis topic provides information about the Policies Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policies Detail ViewThis topic provides information about the Policies Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

212 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 225: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policy review comments

Policy review commentPolicy Review Comments support and facilitate the review and approval process ofPolicies and Procedures by Subject Matter Experts and Compliance Personnel.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policy Review Comments Folder ViewThis topic provides information about the Policy Review Comments Folder View.

Chapter 16. Using OpenPages Policy and Compliance Management objects 213

Page 226: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Policy Review Comments Detail ViewThis topic provides information about the Policy Review Comments Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

214 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 227: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Procedures

ProceduresProcedures represent the what, where, when, and how of how policies areimplemented in an organization. The text of Procedures is typically stored in thefields on the object. Typically, Procedures are represented as children of a Policyand reside in the same entity structure as its parent Policy.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Procedures Folder ViewThis topic provides information about the Procedures Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Chapter 16. Using OpenPages Policy and Compliance Management objects 215

Page 228: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Procedures Detail ViewThis topic provides information about the Procedures Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Campaigns

CampaignsThe Campaign object is part of the Policy Awareness capability and is used tomanage the project management aspects of an awareness campaign. It is also usedto define the requirements and criteria that identify which employees need to readand attest to each Policy. Campaigns are typically created in the Published PolicyHierarchy.

Filtered List ViewThis topic provides links to information about the Filtered List View.

216 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 229: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Campaigns Folder ViewThis topic provides information about the Campaigns Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Campaigns Detail ViewThis topic provides information about the Campaigns Detail View.

Chapter 16. Using OpenPages Policy and Compliance Management objects 217

Page 230: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Employees

EmployeesThe Employee object is part of the Policy Awareness Capability. It is used tocapture information about individual employees such as the name, title, email,region, department, status, etc. Information from the employee profile is thenmatched against the Attestation Requirements defined on a Campaign to determinewhich Employees need to attest to each Policy. Employee data is typically derivedfrom an HR system export, loaded via Online FastMap, and resides in thereference Employee Business Entity. It is a best practice that the Employee Namefield matches the user's username.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29

218 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 231: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Employees Folder ViewThis topic provides information about the Employees Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Employees Detail ViewThis topic provides information about the Employees Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?

Chapter 16. Using OpenPages Policy and Compliance Management objects 219

Page 232: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Attestations

AttestationsThe Attestation object, part of the Policy Awareness capability, is used to capturean employee affirmation that they have read and understood a policy. AnAttestation's primary parent is the Employee record and the secondary parent isthe associated Campaign.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

220 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 233: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Attestations Folder ViewThis topic provides information about the Attestations Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Attestations Detail ViewThis topic provides information about the Attestations Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Chapter 16. Using OpenPages Policy and Compliance Management objects 221

Page 234: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulators

RegulatorsThe Regulator object is part of the Regulator Interaction Management capabilityand provides the ability for organizations to create a single inventory of allRegulators with which they interact. Regulators are typically created in a referenceLibrary Business Entity. The object is a child of Business Entity and can beassociated to Mandates and Regulator Interactions.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulators Folder ViewThis topic provides information about the Regulators Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?

222 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 235: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulators Detail ViewThis topic provides information about the Regulators Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulator Interactions, RI categories, RI requests

Regulator interactionsThe Regulator Interaction object is part of the Regulator Interaction Managementcapability and provides the ability to manage the interactions, communication,internal work, review and approvals associated with external regulators such asinquiries, submissions, filings, exams and audits. For complex interactions such as

Chapter 16. Using OpenPages Policy and Compliance Management objects 223

Page 236: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

exams and audits, customers can use a three-tier object structure (RegulatorInteraction, RI Category and RI Request) to manage and track the overallinteraction, each section of the interaction, and the individual requests. For simplerrequests and inquiries, customers can use the Regulator Interaction object by itselfto manage the request details and response details.

RI categoriesThe RI Category object is part of the Regulator Interaction Management capabilityand is used as the middle tier of the three-tier object model (Regulator Interaction,RI Category and RI Request). The object is used to organize and track the progressof individual sections or categories of a complex interaction such as an exam oraudit.

RI requestsThe RI Request object is part of the Regulator Interaction Management capabilityand is used as the last tier of the three-tier object model (Regulator Interaction, RICategory and RI Request). The object is used to organize and track the individualrequests, reviews and approvals of pre-work and onsite tasks as part of a complexinteraction such as an exam or audit.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulators Interactions, Regulator Interaction Categories, andRegulator Interaction Requests Folder ViewThis topic provides information about the Regulators Interactions, RI Categories,and RI Requests Folder View.

224 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 237: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulators Interactions, RI Categories, and RI Requests DetailViewThis topic provides information about the Regulators Interactions, RI Categories,and RI Requests Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 16. Using OpenPages Policy and Compliance Management objects 225

Page 238: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Regulatory changes and regulatory tasks

Regulatory changesThe Regulatory Change object is part of the Regulatory Change Managementcapability. It supports the ability to track regulatory changes (change or guidanceto an existing regulation or a new regulatory requirement), assess the impact of achange on the organization, communicate the change internally to the appropriatepeople and drive internal processes in response to the change. Regulatory Changestypically reside in the Library Business Entity, and are associated directly to theMandate that changed. It then has multiple Regulatory Tasks associated to it; onefor each Business Entity impacted by the respective Mandate.

Regulatory tasksThe Regulatory Task object is part of the Regulatory Change Managementcapability. It facilitates the change management process associated with aRegulatory Change. A Regulatory Task is created in the Organizational BusinessHierarchy and assigned to an individual in each of the Business Entities impactedby the Mandate that was changed. The object is then used to track and monitor ifan action is required as a result of the change (such as revise policy, controlassessment, training) and the progress of the action.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulatory Changes and Regulatory Tasks Folder ViewThis topic provides information about the Regulatory Changes Folder View.

226 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 239: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Regulatory Changes and Tasks Detail ViewThis topic provides information about the Regulatory Changes and Tasks DetailView.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Chapter 16. Using OpenPages Policy and Compliance Management objects 227

Page 240: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

228 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 241: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 17. Using OpenPages Financial Controls Managementobjects

IBM OpenPages Financial Controls ManagementIBM OpenPages Financial Controls Management reduces the time and resourcecosts associated with ongoing compliance for financial reporting regulations.

IBM OpenPages Financial Controls Management combines powerful document andprocess management with rich interactive reporting capabilities in a flexible,adaptable easy-to-use environment, enabling CEOs, CFOs, managers, independentauditors and audit committees to perform all the necessary activities for complyingwith financial reporting regulations in a simple and efficient manner.

IBM OpenPages Financial Controls Management allows users to easily see thestatus of their financial controls documentation project, and provides a securerepository for the storage of their internal controls documentation.

Key features include:v Financial Controls Management Repository, which logically presents processes,

risks and controls in many-to-many and shared relationships at multiple levels,and enables file attachment capability and action plans for processes, risks,controls and tests at all levels.

v Flexible automation, which provides notification and completion of financialcontrols management activities, such as design review, operating review andcertification.

v Reporting, monitoring and analytics.

Working with OpenPages Financial Controls Management objects

Accounts

AccountsAccounts correspond to one or more line items on a financial report. Each accountis affected by recurring Processes. These Processes can introduce Risks that mustbe documented during the financial controls documentation project. An account isidentified as significant based on factors such as size, complexity of the processesthat operate on the account, or if the account is associated with new product lineswithin the business. The risks that might materialize and have material effect onthe account are identified by consideration of the processes operating on theaccount.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filter

229

Page 242: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Accounts Folder ViewThis topic provides information about the Accounts Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Accounts Detail ViewThis topic provides information about the Accounts Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?

230 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 243: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Accounts

Sub-AccountsA Sub-Account represents a smaller, more targeted line item that is part of a largerparent Account (or of another Sub-Account). Each Sub-Account object can beassociated with parent Account or Sub-Account objects.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Chapter 17. Using OpenPages Financial Controls Management objects 231

Page 244: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Accounts Folder ViewThis topic provides information about the Sub-Accounts Folder View.

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Sub-Accounts Detail ViewThis topic provides information about the Sub-Accounts Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

232 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 245: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Assertion

AssertionsThe Assertion object is used to link a control directly to the account (orsub-account) it affects and to document which assertions it covers for the particularaccount or sub-account.

A common practice is to store the type of assertion that the control is covering as adata field on the Assertion object. Create an Assertion object from the detail pageof a parent Account, Sub-Account, or Control object type.

Which object types and actions are available on a page depends on your setup andpermissions.

Filtered List ViewThis topic provides links to information about the Filtered List View.

How do I search or filter for data?v “View filters in the Analytics bar” on page 26v “Setting a default filter” on page 27v “Running saved filters” on page 29v Create a filterv Clear a filterv “Editing saved filters” on page 29v “Copying filters” on page 30v “Export data from filter results” on page 31

How do I work with data and objects on the grid?v Edit datav Sort data in a columnv “Navigating to an object's detail page” on page 21v Move an object under another objectv Delete an objectv Select a different report period for this view

Tell me about...v How are the objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Assertions Folder ViewThis topic provides information about the Assertions Folder View.

Chapter 17. Using OpenPages Financial Controls Management objects 233

Page 246: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

How do I...v Add a folder?v Navigate to a Detail Page?v Move an object to another folder?v Rename an object?v Delete an object?v Narrow the search for an object?v Select a different report period for this view?v Submit a job for an object?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

Assertions Detail ViewThis topic provides information about the Assertions Detail View.

How do I Add?v New child object to an object?v file, form or link to an object?v Signature and comment to an object?v How are the objects related to each other in the hierarchy?v Edit an object?v Copy an object?v Delete an associated object from an object?v Lock or unlock an object?v Unlock all objects within an object?v Navigate to a Detail Page?v Reassign a primary parent for an object?v Rename an object type?v Select a different report period for this view?v Submit a job for an object?

How do I View?v Locks for an object?v Change history (audit trail) for an object?v Guidance on a field?

Tell me about...v How are objects related to each other in the hierarchy?v What are object view pages and how do these pages differ?v What are search filters?v What are alerts and can I change my notification options?

234 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 247: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 18. Using OpenPages Regulatory ComplianceManagement objects

Getting started

OpenPages Regulatory Compliance ManagementIBM OpenPages Regulatory Compliance Management supports organizations inbreaking down regulations into a catalog of requirements, evaluating its impact tothe business, and creating actionable tasks.

As a solution it provides a configurable and customizable platform, allowing firmsto:v Maintain a repository of regulatory initiatives they must comply withv Break down regulatory initiatives into component paragraph partsv Identify and create a catalog of requirements that fulfill the regulatory initiativesv Map regulatory requirements to internal control frameworkv Create groupings of requirements into Compliance Themesv Conduct assessments of regulatory requirements under Compliance Plans

Working with Regulatory Compliance Management objects

OpenPages Regulatory Compliance Management ObjectsIBM OpenPages Regulatory Compliance Management contains the followingobjects.

Table 7. OpenPages RCM objects

Navigation Description

Compliance Plan Compliance Plans allow for the creation of an overall plan toaddress regulatory requirements in a structured setting, or tostructure a set of regulatory tasks. For example, a Compliance Planmay be created to track regulatory tasks, or to conduct complianceassessments against various regulatory requirements. One ormultiple Compliance Themes can be grouped into an overallCompliance Plan for the organization.

Compliance Theme Compliance Themes allow users to organize regulatoryrequirements into themes for assessment purposes. This allows forassessing compliance requirements beyond the typical businessentity approach, by grouping regulatory requirements across themesthat impact across the organization. Sample themes may includedata privacy, governance, accountability, etc. This allows users toassess the impact of regulations not just within business entities, butacross themes that touch on multiple areas of the organization.

Project A project is designed to organize regulatory tasks into an overallcompliance project. For example, there may be regulatory changesthat need to be addressed in the compliance framework; users cancreate a project to identify and assign tasks.

235

Page 248: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Table 7. OpenPages RCM objects (continued)

Navigation Description

Regulatory Initiative The Regulatory Initiative object is a child of the Business Entity andcaptures descriptive information about regulations that impact anorganization. Regulatory Initiatives represent a broader grouping ofregulations. For example, Anti-Money Laundering could be aRegulatory Initiative that includes several different moneylaundering regulations that organizations must comply with. Theseregulatory initiatives, along with their associated regulatoryrequirements may be sourced from IBM Regulatory ComplianceAnalytics solution and integrated into OpenPages RCM forassessment purposes.

RequirementEvaluation

Once users have mapped internal controls to requirements derivedfrom regulations, users can conduct an evaluation of how well theyare operating vis-à-vis the identified requirement. Users canevaluate the operating effectiveness and design effectiveness ofcontrols in within the scope of a compliance theme.

RequirementEvaluation Value

Requirement Evaluation Values are used to record the actual valueof requirement at a given point in time within the scope of aRequirement Evaluation.

236 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 249: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Chapter 19. Using OpenPages Model Risk Governance objects

Getting started

OpenPages Model Risk GovernanceIBM OpenPages Model Risk Governance supports organizations in organizing andcentralizing their Model Inventory.

As a solution it provides a configurable and customizable platform, allowing firmsto:v Organize and maintain the enterprise-wide list of modelsv Document and track issues that are associated with models in a central locationv Record Model Change management governance activitiesv Schedule, track, and manage Model Reviews and Validationsv Assign appropriate roles and responsibilities for model ownership and model

risk managementv Report on Model Inventory and Model Issues

Working with Model Risk Governance objects

OpenPages Model Risk Solution ObjectsIBM OpenPages Model Risk Governance contains the following objects.

Table 8. OpenPages MRG objects

Navigation Description

Change Request The Change Request object is a child of the Model and Usageobjects and allows for the creation and tracking of governanceactivities related to changes in Models and their deployments. Theobject captures data such as Change Type, Change Description andStatus as well as allowing for the recording of the key Approvaland governance steps in the change request lifecycle.

Committee The Committee object is a child of the Business Entity and allowsan organization to represent governance groups/committees. Thesecan then be aligned to Usages and can also be a parent of theEmployee object. It can store information such as the Terms ofReference for a committee, frequency of meetings and detail of theChairperson.

Documentation Documentation objects allow a user to capture large volume richtext content that is often associated with the development,deployment, and review of Models. Through the use of a separateobject to the Model these Documentation objects can be easilyassociated with multiple Models and/or Reviews. They can also beassociated with Report Section objects in the process of ModelReporting. Documentation types include (but are not limited to)Assumptions, Theory and Methodology, Development content, andData. The Documentation object aligns to a "data centric" approachto Model documentation.

237

Page 250: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Table 8. OpenPages MRG objects (continued)

Navigation Description

Metric The Metric object records the definition of a performancemeasurement that the organization chooses to track. A user sets theMetric Type, Yellow, and Red Thresholds and other collectioninformation. A Metric is a child of the Business Entity, Usage andModel objects.

Metric Value The Metric Value object records the result of the metric performancemeasurement. It is designed to behave in a way to allow theorganization to store time series results of measurement.

Model The Model object provides representation of the Models within anorganization. At a theoretical level a model as a quantitativemethod, system or approach that applies statistical, economic,financial or mathematical theories, techniques and assumptions toprocess input data into quantitative estimates. Within the Modelobject in OpenPages key model information can be represented,including: Model Description, Model Ownership, Model Status,Development lifecycle dates, Model Type and Category, Model RiskAssessment data.

Model Link Where an organization wants to adopt a more granular approach toModel documentation the Model Input object provides the ability torecord the inputs. Fields include Input Owner, Type, Status andDescription. Model Inputs can also be the child of a Model Output.This allows for the creation of Model chains at a detail level (shouldthe ModelLink approach not be granular enough).

Model Output Where an organization wants to adopt a more granular approach toModel documentation the Model Output object provides the abilityto record the Outputs of the Model. The intended purpose is torecord the Description and Overview of the Output from agovernance point of view and not to record the Model Result.

Register The Register object is a child of Entity and a parent of the Usageand Model objects. The usage of the Register object is optional. Itsprimary purpose is to act as a library of Models duringdevelopment. It can also be used to store read only copies of Usageafter they have been approved as part of the deployment cycle.

Report This object is the header record for collation of a Master Modelreport or Model Documentation Report. Fields include: Description,Author, Status, and Summary.

Report Section This object is used in Model Report Collation. It is a child of ModelReport and parent to Documentation. A report collator/authorgenerates Report Sections to subdivide Model Documentation. EachReport Section can then be associated multiple pieces ofDocumentation to render in a master report. Fields includeDescription, Summary and Display order.

Review The Review object is used to record the scheduling and outcomes ofany Model Review activity. It is the child of both the Usage andModel objects. Fields include (but are not limited to): Description,Scope, Planned and Performed Date, Performer, Reviewer, andOutcome. The object is intended to capture the outcomes ofReviews whether they are Pre Implementation, PostImplementation, and Performed by Second or Third Line ofDefense.

238 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 251: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Table 8. OpenPages MRG objects (continued)

Navigation Description

Usage The Usage object is a child of the Business Entity and Committee. Itis used a key element of recording the deployment of one or moremodels. The Usage contains information such as Description, Status,Owner and fields to allow for the risk assessment of a given set ofModels. Usage is the parent of the Model, Model Report, ChangeRequest, and Metric objects.

Chapter 19. Using OpenPages Model Risk Governance objects 239

Page 252: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

240 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 253: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Notices

This information was developed for products and services offered worldwide.

This material may be available from IBM in other languages. However, you may berequired to own a copy of the product or product version in that language in orderto access it.

IBM may not offer the products, services, or features discussed in this document inother countries. Consult your local IBM representative for information on theproducts and services currently available in your area. Any reference to an IBMproduct, program, or service is not intended to state or imply that only that IBMproduct, program, or service may be used. Any functionally equivalent product,program, or service that does not infringe any IBM intellectual property right maybe used instead. However, it is the user's responsibility to evaluate and verify theoperation of any non-IBM product, program, or service. This document maydescribe products, services, or features that are not included in the Program orlicense entitlement that you have purchased.

IBM may have patents or pending patent applications covering subject matterdescribed in this document. The furnishing of this document does not grant youany license to these patents. You can send license inquiries, in writing, to:

IBM Director of LicensingIBM CorporationNorth Castle DriveArmonk, NY 10504-1785U.S.A.

For license inquiries regarding double-byte (DBCS) information, contact the IBMIntellectual Property Department in your country or send inquiries, in writing, to:

Intellectual Property LicensingLegal and Intellectual Property LawIBM Japan Ltd.19-21, Nihonbashi-Hakozakicho, Chuo-kuTokyo 103-8510, Japan

The following paragraph does not apply to the United Kingdom or any othercountry where such provisions are inconsistent with local law: INTERNATIONALBUSINESS MACHINES CORPORATION PROVIDES THIS PUBLICATION "AS IS"WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED,INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OFNON-INFRINGEMENT, MERCHANTABILITY OR FITNESS FOR A PARTICULARPURPOSE. Some states do not allow disclaimer of express or implied warranties incertain transactions, therefore, this statement may not apply to you.

This information could include technical inaccuracies or typographical errors.Changes are periodically made to the information herein; these changes will beincorporated in new editions of the publication. IBM may make improvementsand/or changes in the product(s) and/or the program(s) described in thispublication at any time without notice.

241

Page 254: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Any references in this information to non-IBM Web sites are provided forconvenience only and do not in any manner serve as an endorsement of those Websites. The materials at those Web sites are not part of the materials for this IBMproduct and use of those Web sites is at your own risk.

IBM may use or distribute any of the information you supply in any way itbelieves appropriate without incurring any obligation to you.

Licensees of this program who wish to have information about it for the purposeof enabling: (i) the exchange of information between independently createdprograms and other programs (including this one) and (ii) the mutual use of theinformation which has been exchanged, should contact:

IBM CorporationLocation Code FT0550 King StreetLittleton, MA01460-1250U.S.A.

Such information may be available, subject to appropriate terms and conditions,including in some cases, payment of a fee.

The licensed program described in this document and all licensed materialavailable for it are provided by IBM under terms of the IBM Customer Agreement,IBM International Program License Agreement or any equivalent agreementbetween us.

Any performance data contained herein was determined in a controlledenvironment. Therefore, the results obtained in other operating environments mayvary significantly. Some measurements may have been made on development-levelsystems and there is no guarantee that these measurements will be the same ongenerally available systems. Furthermore, some measurements may have beenestimated through extrapolation. Actual results may vary. Users of this documentshould verify the applicable data for their specific environment.

Information concerning non-IBM products was obtained from the suppliers ofthose products, their published announcements or other publicly available sources.IBM has not tested those products and cannot confirm the accuracy ofperformance, compatibility or any other claims related to non-IBM products.Questions on the capabilities of non-IBM products should be addressed to thesuppliers of those products.

All statements regarding IBM's future direction or intent are subject to change orwithdrawal without notice, and represent goals and objectives only.

This information contains examples of data and reports used in daily businessoperations. To illustrate them as completely as possible, the examples include thenames of individuals, companies, brands, and products. All of these names arefictitious and any similarity to the names and addresses used by an actual businessenterprise is entirely coincidental.

If you are viewing this information softcopy, the photographs and colorillustrations may not appear.

242 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 255: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

This Software Offering does not use cookies or other technologies to collectpersonally identifiable information.

Copyright

Licensed Materials - Property of IBM Corporation.

© Copyright IBM Corporation, 2003, 2016.

US Government Users Restricted Rights – Use, duplication or disclosure restrictedby GSA ADP Schedule Contract with IBM Corp.

This information contains sample application programs in source language, whichillustrate programming techniques on various operating platforms. You may copy,modify, and distribute these sample programs in any form without payment toIBM, for the purposes of developing, using, marketing or distributing applicationprograms conforming to the application programming interface for the operatingplatform for which the sample programs are written.

These examples have not been thoroughly tested under all conditions. IBM,therefore, cannot guarantee or imply reliability, serviceability, or function of theseprograms. You may copy, modify, and distribute these sample programs in anyform without payment to IBM for the purposes of developing, using, marketing, ordistributing application programs conforming to IBM's application programminginterfaces.

Trademarks

IBM, the IBM logo and ibm.com are trademarks or registered trademarks ofInternational Business Machines Corp., registered in many jurisdictions worldwide.

The following terms are trademarks or registered trademarks of other companies:v Microsoft, Windows, Windows NT, and the Windows logo are trademarks of

Microsoft Corporation in the United States, other countries, or both.

Other product and service names might be trademarks of IBM or other companies.A current list of IBM trademarks is available on the Web at “ Copyright andtrademark information ” at www.ibm.com/legal/copytrade.shtml.

Notices 243

Page 256: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

244 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 257: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Glossary

In this glossary, you can find terms anddefinitions for IBM OpenPages GRC Platform

access control list (ACL)A concept in computer security used todetermine the permissions (Read, Write,Delete, and Associate) a user or group canhave on the folder structure of an objecttype (such as, an Entity, Risk, or Test).ACLs provide a means to control who hasaccess to what and with whichpermissions. ACLs can be assigned togroups and users via a Role Template.

Action MenuThe menu bar that is always displayed atthe beginning of a page. To reveal menuitems, hover your mouse pointer over amenu name. Your permissions determinewhich menus and items are available.

Actor ACLsThese are a set of administrator accessrights (Manage, Lock, Unlock, ResetPasswords, Assign Roles, Browse) definedon users and groups. These access rightscontrol the operations an administratorcan perform on a particular user orgroup.

administratorA user that is granted special permissionto manage a Business Entity, including theassignment of Roles to users and groups.

application permissionsA list of permissions that allow groupsand users to access certain activities,including administration, within theapplication (such as the ability to view,lock, or unlock objects, or create anddelete reporting periods).

associationsRelationships that exist among objects, orbetween objects and attached files.Example: A sub-entity may be directlyassociated with a process or businessfunction.

audit universeThe aggregate of all areas within anorganization that can be audited.

business unitOne or more Entities, Processes orSub-Processes.

CSV Comma separated values. A type of filethat uses a comma-delimited format.

group A generic term that encompasses bothorganizational and security domaingroups.

listing paneThe pane on an object's Detail View pagethat is displayed when you click the nameof an associated object type. It lists all thenames of objects for that type that areassociated with the current object, and hasan Actions Menu for adding new objects,or associating and copying existingobjects of the same type.

object Any item that contains or receivesinformation, such as Business Entities,Processes, Risks, Controls, Issues, Testsand so forth. In a security context, anobject is the piece of data to which accesscontrol is applied (such as, BusinessEntity, Process, Sub Process, RiskAssessment). Also called “resource”.

object typeA category or type of object, such as aRisks, Controls, Issues and so forth. In ahierarchy of objects, each object type hasa set of allowed relationships with otherobject types.

organizational groupA group that is created by anadministrator to organize users within anorganization. Organizational groups aretypically associated with security domaingroups and other organizational groups.

pane A section or component of an object view.For example, a Detail View page typicallyconsists of several panes, such as a Detailspane, Context pane, Associations pane,Listing pane, and an Attachments pane.

resourceSee “object”.

Resource ACLsThese are a set of access rights (Read,Write, Delete and Associate) defined on

245

Page 258: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

the parent folder of an object. Theseaccess rights control the operations a usercan perform on the folder and any objectsunder that folder.

role An instance of a Role Template that isapplied to a set of Users/Groups for aspecific security context. Roles are grantedto Users/Groups which allows themaccess to objects with certain permissions.Some examples of roles are: ProcessOwner, Control Owner, and Tester.

Role TemplateA security object that you can use todefine all aspects of application securityfor various groups and users within abusiness unit. It contains access controldefinitions on folder structures for objecttypes and application permissions. RoleTemplates generally reflect the usual orexpected function that a user or groupplays within an organization. Someexamples or Role Templates that can bedefined are Process Owner, ControlOwner, and Tester. The template can thenbe applied to different Users/Groups fora specific security context.

security context pointA point defined in the OpenPagessecurity model that you can use to assignroles to users and groups for controllingaccess and application permissions toobjects under that security point.

security domain groupA group that is automatically created bythe system when a business entity orsubentity is created. Business entitysecurity domain groups are located underthe top level (root) Security Domainsfolder on the Users, Groups andDomains page.

246 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 259: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Index

AAccounts description 229Accounts Detail View 230Accounts Folder view 230action item comment:adding 80Action items, completing 42, 81Activity View Page 41Add a link to a job 89Add a link to a task 89add files 85add files, Attachments option 85add files, Folder view 85add milestones 96Add New wizard 13, 14add signature 93add, folder 16add:action item comment 80Adding

objects 51Adding files to jobs 87Adding files to tasks 87Adding form

Form, adding 87, 90adding link to task or job 94Adding parent objects

Parent objects, adding 57Adding URL links to object views 89Advanced filter panel

hiding 30advanced filters 28advanced search techniques 24alerts, defining notification 45Analytics bar

changing the order of filters 27hiding 27hiding filters 27overview of 26showing 27showing filters 27

Assertions description 233Assertions Detail View 234Assertions Folder View 234associating objects 49Association 18attach files 85Attachments 9, 86Attachments option, add files 85Attestations description 220Attestations Detail View 221Attestations Folder View 221Audit Review Comments 143Audit Review Comments Detail View 144Audit Review Comments Folder View 143Audit Sections description 137Audit Sections Detail View 137Audit Sections Folder View 137Auditable Entities description 135Auditable Entities Detail View 136Auditable Entities Folder view 135Auditable Entities overview 135Auditors description 142

Auditors Detail View 143Auditors Folder View 142Audits description 133Audits Detail View 134Audits folder view 134automatic timeout 123

BBaselines description 154Baselines Detail View 156Baselines Folder View 155browse attachments 85, 123Business Entities Detail View 57Business Entities Folder View 56Business Entities Overview information 55Business Entity definition 55

CCampaigns description 216Campaigns Detail View 218Campaigns Folder View 217Cancel a file checkout 88change file description 21change history definition 123Checking in a file 88Checking out a file 88Column, control display 34Column, reorder 35compare text changes 36Completing action items 42, 81completing, tasks 42Control column display 34Control Evals (Evaluation) Detail View 73Control Evals (Evaluation) Folder View 73Control Evals definition 72Control Objective Detail View 64Control Objectives definition 62Control Objectives Folder View 63Control Plans description 152Control Plans Detail View 153Control Plans Folder View 153Control Plans Overview 153Controls definition 70Controls Detail View 71Controls Folder View 71copy file link 48copy: file link 87Cost Centers description 191Cost Centers Detail View 192Cost Centers Folder View 192

Ddefault filter 28defining, alert notification 45delete object 48deleting

filters 29

247

Page 260: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Detail page 21Detail View 33Detail view, edit object 20detail view:submitting a job 46disassociate file or object from task or job 95Disassociating objects 49Downloading files 47

Eedit folder description 20Edit object, detail view 20editing object types 48Editing object types 19email report 99Employees description 218Employees Detail View 219Employees Folder View 219

Ffile check in 86, 124file check out 86, 124File checkout, cancel 88file description, change 21file links, copy 48File, checking in 88file, disassociate from task or job 95file, view 37file: copy link 87files, add 85files, attach 85Files, downloading 47files, rules for naming 126files, using 88, 125Filtered List View 25, 56, 59, 62, 63, 65, 67, 68, 70, 72, 74, 76,

78, 81, 83, 96, 100, 102, 108, 114, 117, 119, 146, 148, 150, 152,155, 157, 159, 160, 162, 164, 166, 168, 172, 174, 176, 178, 180,181, 183, 185, 187, 189, 191, 196, 198, 200, 202, 204, 206, 207,209, 211, 213, 215, 217, 218, 220, 222, 224, 226, 229, 231, 233

filters 30adhoc 28advanced 28changing the order in the Analytics bar 27clearing the results of 31copying 30deleting 29editing 29overview 25running 29saved 28, 29setting a default 28

Findings description 141Findings Detail View 141Findings Folder View 141FIRST Losses description 185FIRST Losses Detail View 186FIRST Losses Folder View 186folder description, edit 20Folder View 33Folder view, add files 85folder, add 16folders, rules for naming 126Forms definition 87, 125forms, using 88, 125

GGenerate reports 41, 99global search 23

Hhiding

Advanced filter panel 30Analytics bar 27filters in the Analytics bar 27

home page 7Home page 8

IIncidents description 159, 205Incidents Detail View 160, 207Incidents Folder View 159, 206Issue and Action Items definition 80Issues and Action Items Folder Views 81Issues and Issue Action Items Detail View 82

JJob, add a link 89job, adding link to 94job:submit from filtered list 45Job:submit from folder view 46job:submit from grid view 45job:terminate 46Jobs definition 93Jobs information 44, 93jobs, view and monitor 94

KKey Performance Indicators (KPI) and Values Detail

View 163, 175, 210Key Performance Indicators and Values Folder View 163, 175,

210Key Risk Indicators (KRI) and Values Detail View 161, 173,

205Key Risk Indicators (KRI) and Values Folder View 161, 173,

204KPIs and KPI Values description 162, 174, 209KRIs and KRI Values description 160, 172, 203

LLaunching a program 116lifecycle information, view 37link

adding from folder view 17attach from detail view 17

link, view 37Linking objects 18links, using 88, 125list view pages 58List view, Milestones 98locale settings; change language setting 11locking objects 50Locks definition 91locks, view 36log in 5

248 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 261: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

logging out 5Loss Events description 176Loss Events Detail View 177Loss Events Folder View 177Loss Events Overview 176Loss Impact Detail View 179Loss Impact Folder View 179Loss Impacts description 178Loss Recoveries description 180Loss Recoveries Detail View 181Loss Recoveries Folder View 180

MMandates Detail View 147, 199Mandates Folder View 147, 199Mandates Overview 147menu bars description 128milestone action item, definition 95Milestone Action Items, list view 98Milestones and Milestones Action Item 97Milestones Overview 96milestones, add 96milestones, definition 95Milestones, list view 98Model Results Detail View 120Model Results Folder view 120monitor jobs 94Move object 50My Settings 11

Nnaming objects, folders, and files 126Navigate, grid view 5notifications 125

Oobject history, view 35object instances 13

adding 14object types, editing 48Object views, adding URL links to 89object, delete 48object, disassociate from task or job 95Object, moving 50object, rename 52objects

searching for 23Objects

adding 51objects, associating 49objects, locking 50Objects, removing the association 49objects, rules for naming 126Objects, unlock 21objects:unlock all 58OpenPages Internal Audit Management description 133OpenPages IT Governance 145OpenPages IT Governance terms 145OpenPages Model Risk Solution objects 237OpenPages Operational Risk Management overview 171OpenPages Policy and Compliance Management 195OpenPages Regulatory Compliance Management objects 235

OpenPages Regulatory Compliance Managementoverview 235

OpenPages Regulatory Model Risk Governance overview 237ORIC Losses description 187ORIC Losses Detail View 188ORIC Losses Folder View 188ORX Losses description 189ORX Losses Detail View 190ORX Losses Folder View 190

Ppassword, change; change password 11Plans description 138Plans Detail view 139Plans Folder View 138Policies description 166, 211Policies Detail View 167, 212Policies Folder View 167, 212Policy and Compliance Management terms 196Policy Overview 167, 211Policy Review Comment description 213Policy Review Comments Detail View 214Policy Review Comments Folder View 214Preference Groups and Preferences Detail View 84Preference Groups and Preferences Folder View 83Preferences and Preferences Groups definition 83primary parent association 126Primary parent object, reassigning 43printing Detail View information 38Procedures description 168, 215Procedures Detail View 169, 216Procedures Folder View 169, 215Process Evals (Evaluations) Detail View 68Process Evals (Evaluations) Folder View 67Process Evals definition 66Processes definition 64Processes Detail View 66Processes Folder View 65Processes Overview 64Program Detail View 115Program Folder View 115

QQuestionnaire Assessment Detail View 109Questionnaire Assessment Folder View 108Questionnaire Template Detail View 103Questionnaire Template Folder View 102Questionnaire template, adding a question 105Questionnaire template, adding a section 104questionnaires definition 100Questionnaires Detail View 101Questionnaires folder view 100questions definition 100

Rreassign task 42Reassigning, primary parent object 43Regulation Applicabilities descriptions 196Regulation Applicabilities Detail View 197Regulation Applicabilities Folder View 197Regulator Interactions description 224Regulators description 222Regulators Detail View 223

Index 249

Page 262: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Regulators Folder View 222Regulators Interactions RI Categories, and RI Requests Folder

View 225Regulators Interactions, RI Categories, and RI Requests Detail

View 225Regulatory Changes and Regulatory Tasks Folder View 227Regulatory Changes and Tasks Detail View 227Regulatory Changes description 226Regulatory Tasks description 226rename object 52renaming 30

filters 30renaming object from detail page 53renaming object from folder page 53Reorder column display 35report, emailing 99report; view in different format 37, 99Reporting periods, selecting 43Reports 98reports definition 98Reports information 99Reports, viewing 41, 99Requirements description 150, 201Requirements Detail View 151, 203Requirements Folder View 151, 202Resource Links description 157Resources and Resource Links Detail View 158Resources and Resources Links Folder View 157Resources description 156Revoke

signatures 44RI Categories description 224RI Requests description 224Risk Assessment Eval (Evaluation) Detail View 61Risk Assessment Evals definition 61Risk Assessments definition 59Risk Assessments Detail view 60Risk Assessments Folder View 60Risk Assessments Overview 59Risk Evals (Evaluation) Detail View 77Risk Evals (Evaluations) Folder View 77Risk Evals definition 76Risks definition 74Risks Detail Item 75Risks Folder View 75rules for naming folders 126rules for naming objects 126

SScenario Analyses Detail View 182Scenario Analyses Folder View 182Scenario Analysis description 181Scenario Results description 183Scenario Results Detail View 184Scenario Results Folder View 184search techniques

advanced 24searching for objects 23sections definition 100Selecting reporting periods 43showing

Analytics bar 27filters in the Analytics bar 27

sign off on task 43signature, add 93

Signaturesrevoke 44

Signatures definition 91Signatures information 91signatures, view 37Sub_Mandate description 148Sub-Accounts description 231Sub-Accounts Detail View 232Sub-Accounts Folder View 232Sub-Mandate description 200Sub-Mandates Detail View 149, 201Sub-Mandates Folder View 149, 200Sub-Processes definition 68Sub-Processes Detail View 69Sub-Processes Folder View 69submit job: from detail view 46submit job:filter list 45Submit job:from folder view 46submit job:grid view 45

TTask, a link 89task, adding a link to 94task, reassign 42task; sign off 43Tasks information 94tasks, completing 42terminate:job 46Test Plan or Test Results Detail View 79Test Plans definition 78Test Plans or Test Results Folder View 79Test Results definition 78text changes, compare 36

UUnlock objects 21unlock:all objects 58Uploading, new version of a file

File, uploading new version 90using files 88, 125using forms 88, 125using links 88, 125

Vview a file 37view a link 37view jobs 94view lifecycle information 37view locks 36view object history 35View pages description 127view report in different format 37, 99View reports 41, 99view signatures 37

WWaivers 164, 207Waivers Detail View 165, 208what's new 1Workpapers description 139Workpapers Detail View 140

250 IBM OpenPages GRC Platform Version 7.2.0: User Guide

Page 263: IBM OpenPages GRC Platform Version 7.2.0: User Guidepublic.dhe.ibm.com/software/data/cognos/... · IBM OpenP a ges GRC Pla tform V ersion 7.2.0 User Guide IBM

Workpapers Folder View 140

Index 251