Notifications

User defined email and REST API based notifications to manage GRC - long

  • Episodes7
  • Duration25m 13s
  • LanguagesEN
Episode 7

Notification Suggestions

This episode shares ideas for notifications

The following table gives you some ideas of common notification scenarios that can be used on most Eramba modules. Remember these are some ideas but there are endless ways how these fields can be used.

Module

Notifications Scenarios (these notifications can be created using custom Statuses and Warning notifications)

Settings / User Management

  • Account Created

Internal Controls

  • Controls without Policies
  • Controls without “Problems”
  • Controls without Audit Plans
  • Controls with Issues
  • Control mitigates High Risk

Internal Controls / Audits

  • Audit Deadlines
  • Audit Completed
  • Audit Missing Evidence
  • Audit Result (Fail/Pass)
  • Audit Duration too Long
  • Poor Audit Evidence Quality

Policies

  • Policies without “Problems”
  • Policies mitigate High Risks

Policy Reviews

  • Review Deadlines
  • Review Completed
  • Review Missing Evidence
  • Review Missing Approver Approval
  • Review Duration too Long
  • Poor Review Evidence Quality

Risk (All Three)

  • High Risk Created
  • Low/Medium risk updated to High Risk
  • Risk mitigating Control set as Failed / Expired / Issues
  • Risk mitigating Policy set as Expired
  • Risk mitigating Exception set as Expired
  • Risk mitigating Project set as Expired / Closed
  • New Risks affecting a Department

Risk Reviews (All Three)

  • Risk Review Deadlines in two weeks
  • Risk Review Completed
  • Review Missing Evidence
  • Review Duration too Long
  • Poor Review Evidence Quality

Risk Exceptions

  • Exception Deadline in two weeks
  • Exception Expired
  • Exception Created
  • Exception linked to a High Risk Created
  • Exception linked to more than 5 High Risks

Policy Exceptions

  • Exception Deadline in two weeks
  • Exception Expired
  • Exception Created

Compliance Exceptions

  • Exception Deadline in two weeks
  • Exception Expired
  • Exception Created

Projects

  • Expired Project
  • Expired Task on the Project
  • Project Deadline within 2 Weeks

Project Tasks

  • Expired Task
  • Task about to Expire
  • Task belongs to a Closed Project

Incidents

  • Incident Open / Closed
  • Incident Stage missing Approval from SIRT role
  • Incident Stage Completed

Awareness Programs

  • Compliance Rate falls below threshold

Online Assessments

  • OA Started
  • OA Submitted
  • OA Result Pass / Failed
  • OA Low / High Score

Online Assessments / Findings

  • Finding Created
  • Finding Open / Closed
  • Finding Expired
  • Finding about to Expire

Compliance Analysis

  • Non-Compliance due Control Audit Issues
  • Non-Compliance due Policy missing Review
  • Non-Compliance due Project Issues
  • Associated Compliance Exception Expired

Organization /Third Parties

  • When Third Party is Created
  • When TP passed Vendor Assessment
  • When TP has Findings Open related to Online Assessments
  • When TP is Compliant / Non Compliant
  • TP with High Risks associated
  • TP with No Risks

Organization / Business Units

  • BU has no Risks
  • BU has High Risks associated