How to add security control to a process?

Post Reply
james.nesperos
Posts: 20
Joined: 04 May 2020, 09:44

Hi Team,

Wondering how we can enable/add the security controls for the processes? Is there a way to add security controls for each levels like application and technology controls?

Thanks!

James
JohnM
Posts: 476
Joined: 17 Feb 2009, 20:19

Hi James,

Can you expand on what you are looking for with an example please.

Thanks
james.nesperos
Posts: 20
Joined: 04 May 2020, 09:44

Hi John,

I am looking at the NIST view and I see some mapping/relationships created on the business process level to the controls and assessment result and also to the assessor who did the assessment.

Here's the view I am looking at.

https://essentialviewer.com/report?XML= ... T&cl=en-gb

Now, I know this is not included in the launchpad at the moment, but let's say I wanted to use protege in the absence of a spreadsheet to populate and store my data in order for it to be reflected in the NIST view. Where should i add the details/mapping in the repository so I can published it via protege and it will be reflected in the viewer?

Thanks,

James
james.nesperos
Posts: 20
Joined: 04 May 2020, 09:44

Here is the view I am looking at:

https://essentialviewer.com/report?XML= ... T&cl=en-gb

And here is what I have done in Protege:
Protege - NIST.png
But it was not shown in the viewer after I have publish it via protege.

Hope you can guide me on this.

Thank you very much.
You do not have the required permissions to view the files attached to this post.
JohnM
Posts: 476
Joined: 17 Feb 2009, 20:19

You need to set up a Control Framework and associate the controls. See the below
Screenshot 2020-05-14 at 07.35.21.png
You do not have the required permissions to view the files attached to this post.
james.nesperos
Posts: 20
Joined: 04 May 2020, 09:44

HI John,

I have created the following as advice but it is still not showing in the viewer:

Created controls then created control assessments then created control framework.
Any idea what else is missing please?
NIST with control framework.png
Thanks,

James
You do not have the required permissions to view the files attached to this post.
JohnM
Posts: 476
Joined: 17 Feb 2009, 20:19

Hi James,

Have you selected NIST as the framework in the top right hand corner? If you want to default to NIST then add the PMA value to the end of the filename in the report instance
james.nesperos
Posts: 20
Joined: 04 May 2020, 09:44

Hi John,

Apologies, but can you please elaborate on the suggested next step? I am still new on using this. Also, here are the steps I did:

I have created controls - I filled up the name and reference number.
Create controls.png
Then I created control assessments which is mapped to the controls I have created earlier: I have filled up the following fields: Ref ID, Assessment Element, Assessed Control, Assessor, Assessment Date, and Assessment Findings.
Control Assesment.png
Then as you have instructed above, I have also created a framework(NIST), where I have mapped the controls I created above:
Control framework.png
You do not have the required permissions to view the files attached to this post.
james.nesperos
Posts: 20
Joined: 04 May 2020, 09:44

Then After doing all the steps above, tried publishing it in the viewer:
NIST empty.png
None of the mapping I have created is reflected in the viewer unfortunately.

Hope you can help me on the next steps.

Thank you.
You do not have the required permissions to view the files attached to this post.
JohnM
Posts: 476
Joined: 17 Feb 2009, 20:19

Ah, sorry James, I was talking about the new version in 6.9. - the xsl file for the URL is enterprise/core_el_standards.xsl.

If you select you framework on that view then it will show.

If you are using the 6.9 viewer then apply the Essential Updates (EUP download here https://enterprise-architecture.org/update_packs.php) and the report should be there, otherwise to amend the report path - find the report and change the filepath to the above.

This page may help if you set up manually - https://enterprise-architecture.org/doc ... g_reports/
james.nesperos
Posts: 20
Joined: 04 May 2020, 09:44

Hi John,

It works now! :D

Only error I am seeing if the wrong field mapping where the control name appears on the ID and the ID is not reflected anywhere.

Can you please provide instruction on how I can correct the field mapping between the protege and the viewer. Please note that I am not a programmer. :D

Thank you for the guidance.
You do not have the required permissions to view the files attached to this post.
JohnM
Posts: 476
Joined: 17 Feb 2009, 20:19

James, sorry for the delay. We've used the name as the control ID but you've used the ref. This file uses the ref, push this to your user folder and map the report to this file. We've had a quick test and it seems to work OK, let us know if you have any problems
core_el_standards.xsl.zip
You do not have the required permissions to view the files attached to this post.
PrasannaT
Posts: 5
Joined: 23 Jun 2020, 02:33

Hi John,

I am using Essential Viewer 6.10.2 and unable to get the core_el_standards.xsl view working after selecting the framework in the dropdown menu. I have added a control framework and linked controls to that. Any pointers?

Regards,
Prasanna
JohnM
Posts: 476
Joined: 17 Feb 2009, 20:19

Hi Prasanna,

Can you drop this file in your user folder, open the standards view with your framework selected, change the xsl part of the url to user/core_el_standards_checker.xsl and then post a screenshot of the output please
core_el_standards_checker.xsl.zip
Thanks

John
You do not have the required permissions to view the files attached to this post.
PrasannaT
Posts: 5
Joined: 23 Jun 2020, 02:33

Hi John,

Here is the screenshot.
Output1.JPG
Thanks,
Prasanna
JohnM wrote: 06 Jul 2020, 08:39 Hi Prasanna,

Can you drop this file in your user folder, open the standards view with your framework selected, change the xsl part of the url to user/core_el_standards_checker.xsl and then post a screenshot of the output please

core_el_standards_checker.xsl.zip

Thanks

John
You do not have the required permissions to view the files attached to this post.
Post Reply