Create a Risk Recommendation
Introduction
Propose a change to a Risk Control across the entire Organization or for a specific Information System
The user may make a Risk Recommendation on a Non-Standard Control for a System
If making a Recommendation on a Standard control for a System, the Recommendation is made across all Systems with that Standard Control.
Step-By-Step Guide
Open the Details for an Information System
Mark a Sub Control as ‘Non-Standard’
Open the Recommendations section of the System Accordion
Click on the ‘Create Recommendation’ button
Choose the desired sub-control that is ‘Non-Standard’
Input an Observation and Recommendation
In the Recommendation section of the form, input a Change in Cost and a Change in Implementation
Run Monte Carlo analysis on the change by pressing the ‘Refresh Calculation’ button (should be highlighted at this point)
Press Submit on the Green Recommendation Details form
Press Submit on the main Observation form