Findings describe adverse issues discovered when assessing a control. If you discover an issue that needs to be resolved as part of a Control Assessment then select Add Finding. From this screen you will need to specify:
The Assessment Objective that was not met resulting in the Finding.
How the issue was discovered, whether through Interview, Examination, or Testing.
The Severity Rating for the Finding. This is somewhat subjective, and your organization may have its own guidelines about how severity ratings should be used.
The reason for the Severity Rating, and any other related information.
What should be done to fix the issue and when this should be completed by.
Related documents can also be linked to the Finding to provide specific evidence, interview transcripts, or other files that may be of use.