Components installed with Audit Management
Activating the GRC: Audit Management (com.sn_audit) plugin adds or modifies several tables, user roles, and other components.
Parent Topic:Audit Management reference
Properties installed with Audit Management and Advanced Audit
Properties are added with activation of GRC: Audit Management.
| Name | Description | Application |
|---|---|---|
| sn\_audit.retain\_report\_attachments | Retains the previous Word report attachments with the engagement record each time the report is generated - Type: string - Default value: No | Audit Management |
| sn\_audit.knowledge\_base | Name of the knowledge base used to publish Audit reports - Type: string - Default value: Audit | Audit Management |
| sn\_audit\_advanced.default\_adv\_notifica tion\_duedate\_duration | Default duration \(in days\) from the due date of a milestone, based on which, a notification is sent.- Type: integer - Default value: 8 | GRC: Advanced Audit |
| sn\_audit\_advanced.role\_documentation \_link | Documentation link for role requirements for enabling and using advanced planning feature \(with PPM integration\). Type: string | GRC: Advanced Audit |
| sn\_audit\_advanced.ppm\_project\_docu mentation\_link | Documentation link for project capabilities and role requirements. Type: string | GRC: Advanced Audit |
| sn\_audit\_advanced.rollup\_documentati on\_link | Documentation link for expenses and resources rollup details, from project to related engagement and plan. Type: string | GRC: Advanced Audit |
Roles installed with Audit Management
Roles are added with activation of GRC: Audit Management.
| Role title \[name\] | Description | Contains roles |
|---|---|---|
| Audit Admin\[sn\_audit.admin\] | In addition to the inherited permissions, the audit admin can delete engagements, audit tasks, test templates, and test plans. | - sn\_audit.manager - sn\_grc.admin |
| Audit approver \[sn\_audit.approver\] | The audit approver can approve an engagement and audit plan. The user with this role can be a part of approver list and the role is classified as Lite operator role. | sn\_audit.reader |
| Audit reader \[sn\_audit.reader\] | The user can view the audit-related entities such as engagements, plans, observations, audit tasks, and has exclusive read access to all the entities in the Audit Management application. This role is classified as a lite operator role. | sn\_grc.reader |
| Audit Developer\[sn\_audit.developer\] | In addition to the inherited permissions, the audit developer can add and delete audit report templates. | - sn\_audit.admin - sn\_grc.developer |
| External Auditor\[sn\_audit.external\_auditor\] | External auditors can be assigned as auditors for an engagement and can be assigned to audit tasks. They can view closed engagements, audit tasks that are assigned to them, and closed audit tasks. If the Policy and Compliance Management plugin or Risk Management plugins are installed, they can also view published policies and all controls and risks in the Monitor state. | |
| Audit Manager\[sn\_audit.manager\] | In addition to the inherited permissions, the audit manager can create audit tasks \(such as control tests, activities, walkthroughs, and interviews\), engagements, test plans, test templates, issues, remediation tasks, and entities. If Advanced Core is installed, then the audit manager can also create evidence requests. | - sn\_audit.user - sn\_grc.manager |
| Audit User\[sn\_audit.user\] | In addition to the inherited permissions, the audit user can be assigned audit tasks and create test templates and test plans. The audit user has read-only access to the Risk Management application and modules and the Policy and Compliance Management application and modules. | - sn\_compliance.reader - sn\_grc.reader - sn\_grc.user |
| Engagement Project Manager\[sn\_audit\_advanced.engagement\_project\_manager\] | The audit lead who does advanced planning and could handle plans or engagements.This role is available after GRC: Advanced Audit plugin is activated. | - sn\_audit.manager - resource\_manager - it\_project\_manager |
Tables installed with Audit Management
Tables are added with activation of GRC: Audit Management.
| Table | Description |
|---|---|
| Activity\[sn\_audit\_activity\] | Extends Audit Task \[sn\_audit\_task\] and stores audit activities |
| Audit Task\[sn\_audit\_task\] | Extends Planned Task \[planned\_task\] and is a generic table for all tasks associated with an audit |
| Base Audit Test\[sn\_audit\_base\_test\] | Base table for Test Templates and Test Plans |
| Control Test\[sn\_audit\_control\_test\] | Extends Audit Task \[sn\_audit\_task\] and stores control tests |
| Control to Engagement\[sn\_audit\_m2m\_control\_engagement\] | Stores many-to-many relationships between controls and engagements |
| Engagement\[sn\_audit\_engagement\] | Extends Planned Task \[planned\_task\] and stores engagements |
| Interview\[sn\_audit\_interview\] | Extends Audit Task \[sn\_audit\_task\] and stores interviews |
| Entity to Engagement\[sn\_audit\_m2m\_profile\_engagement\] | Stores many-to-many relationships between entities and engagements |
| Risk to Engagement\[sn\_audit\_m2m\_risk\_engagement\] | Stores many-to-many relationships between risks and engagements |
| Test Plan\[sn\_audit\_test\_plan\] | Extends Base Audit Test \[sn\_audit\_base\_test\] and stores test plans |
| Test plan to Engagement\[sn\_audit\_m2m\_test\_plan\_engagement\] | Stores many-to-many relationships between test plans and engagements |
| Test Template\[sn\_audit\_test\_template\] | Extends Base Audit Test \[sn\_audit\_base\_test\] and stores test templates |
| Walkthrough\[sn\_audit\_walkthrough\] | Extends Audit Task \[sn\_audit\_task\] and stores walkthroughs |
| Audit Report Template\[sn\_audit\_report\_template\] | Stores the defined xml, html, or script-based audit report templates |
| Assessment procedures \[sn\_audit\_asmnt\_procedure\_control\_test\] | Stores the assessment objectives of control tests. Identifier and assessment objectives field values are copied over from the Assessment procedure plan table. |
| Assessment procedure plan \[sn\_audit\_asmnt\_procedure\_test\_plan\] | Generated for the test plan. Changes made to the test plan are reflected in the control test table \[sn\_audit\_asmnt\_procedure\_control\_test\] |
| Assessment procedure templates \[sn\_audit\_asmnt\_procedure\] | Stores the assessment objectives |
| Test template to Assessment procedure \[sn\_audit\_m2m\_test\_temp\_asmnt\_procedure\] | Stores many-to-many relationships between test template and assessment procedure |
Note: All additional tables installed by the dependent plugins are also needed for GRC: Audit Management.
Tables installed with Advanced Audit
Tables are added with activation of GRC: Advanced Audit
| Table | Description |
|---|---|
| Audit Task to Milestonesn\_audit\_advanced\_m2m\_audit\_task\_milestone | Stores many-to-many relationships between audit tasks and milestones. |
| Auditable Unitsn\_audit\_advanced\_auditable\_unit | Stores auditable units. |
| Auditable Unit To Authority Documentsn\_audit\_advanced\_m2m\_unit\_authority\_document | Stores many-to-many relationships between auditable units and authority documents. |
| Auditable Unit To Business Applicationsn\_audit\_advanced\_m2m\_unit\_business\_application | Stores many-to-many relationships between auditable units and business applications. |
| Auditable Unit To Business Processsn\_audit\_advanced\_m2m\_unit\_business\_process | Stores many-to-many relationships between auditable units and business processes. |
| Auditable Unit To Business Unitsn\_audit\_advanced\_m2m\_unit\_business\_unit | Stores many-to-many relationships between auditable units and business units. |
| Auditable Unit To Departmentsn\_audit\_advanced\_m2m\_unit\_cmn\_department | Stores many-to-many relationships between auditable units and departments. |
| Auditable Unit To Locationsn\_audit\_advanced\_m2m\_unit\_location | Stores many-to-many relationships between auditable units and locations. |
| Auditable Unit To Policysn\_audit\_advanced\_m2m\_unit\_policy | Stores many-to-many relationships between auditable units and policies. |
| Auditable Unit To Productsn\_audit\_advanced\_m2m\_unit\_product\_model | Stores many-to-many relationships between auditable units and products. |
| Auditable Unit To Vendorsn\_audit\_advanced\_m2m\_unit\_vendor | Stores many-to-many relationships between auditable units and vendors. |
| Engagement Projectsn\_audit\_advanced\_engagement\_project | Extends Project table and stores engagement projects for engagements. |
| Milestonesn\_audit\_advanced\_milestone | Extends Planned Task table and stores milestones. |
| Observationsn\_audit\_advanced\_observation | Extends Triage table and stores observations. |
| Plansn\_audit\_advanced\_plan | Extends Planned Task table and stores plans. |
Note: All additional tables installed by the dependent plugins are also needed for GRC: Audit Management.