Action ITAM Fundamentals

GRC compliance image - Continuum GRC solutions for cyber security and audit AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

The Action ITAM feature in Continuum GRC is designed to provide an automated form of communicating requests with your client and visually holding everyone accountable.

At a minimum, when you enter an Action ITAM, you must be directing the client to provide something for that control requirement. If you need evidence, ask for it specifically. If you need clarification about an implementation statement they wrote, ask them specifically for what you want.

Avoid restating the control requirement because that is already present. If a part of a control response is missing, ask for that part specifically.

Action ITAMs help keep customers focused on their tasks, which helps the project move forward.

Always remember to move a Status Indicator to Red when adding a Action ITAM. If you are creating an Action ITAM that is associated with a control statement that has a companion upload field, also move a Status Indicator to Red.

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.