Creating Action ITAMs WHEN Meeting with a Client

GRC compliance image - Continuum GRC solutions for cyber security and audit AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

When discussing the People, Places, Policies and Technology with clients, identify what forms of evidence need to be collected to satisfy that control requirement.

The procedural steps are:

  • If it is a screenshot, if you are able to make it then, do it and upload it to the control testing response within the Continuum GRC system.

Update the Status Indicator to RED in the Continuum GRC system. This will signal to everyone that the client has a remediation item, or gap that requires attention.

If you are unable to capture it at that time, create a Action ITAM in Continuum GRC describing the evidence to be collected, along with a request to coordinate the screen capture, and assign it to one, or more, members of the client team. This step is vital to the accountability, efficiency, and effectiveness of our service delivery. This is not an optional step.

Update the Status Indicator to GREEN in the Continuum GRC system when the evidence has been collected, and the control requirement is fully satisfied. This will signal to everyone that the control element is compliant and complete.

  • If it is a policy, ask the client to upload it then.

Update the Status Indicator to RED in the Continuum GRC system. This will signal to everyone that the client has a remediation item, or gap that requires attention.

If the client is unable to upload it at that time, create an Action ITAM in Continuum GRC describing the document name and assign it to one, or more, members of the client team. This step is vital to the accountability, efficiency, and effectiveness of our service delivery. This is not an optional step.

Update the Status Indicator to GREEN in the Continuum GRC system when the evidence has been collected, and the control requirement is fully satisfied. This will signal to everyone that the control element is compliant and complete.

  • If it is an observation made by either a remote, or site visit requirement, try to coordinate the activity with the client then, or if it involves a site visit, with the client as needed.

Update the Status Indicator to RED in the Continuum GRC system. This will signal to everyone that the client has a remediation item, or gap that requires attention.

If the client is unable to participate in the observation process at that time, or if there is a need for a site visit, create an Action ITAM in Continuum GRC describing the process to be taken and assign it to one, or more, members of the client team. This step is vital to the accountability, efficiency, and effectiveness of our service delivery. This is not an optional step.

Update the Status Indicator to GREEN in the Continuum GRC system when the evidence has been collected, and the control requirement is fully satisfied. This will signal to everyone that the control element is compliant and complete.

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.