One of CyMetric's missions is to promote and document accountability for participants in a cybersecurity program. Users document ownership of many parts of a cybersecurity program within the CyMetric platform. One of the most important allocations of responsibility is for security and procedural controls. Because most cybersecurity programs are comprised of a significant number of controls, assigning ownership and managing ownership needs to be efficient. This article outlines the process to make global changes to control ownership should a control owner leave a company or a different resource needs to take responsibility a large set of controls.
Navigation
From the left navigation area in CyMetric, within the Controls area, click on Instances.
This will display the control instances (occurrences) for each control within CyMetric, the systems the controls apply to and the current control owner.
Filtering the Grid
This process will enable Users to make global changes to approved controls within CyMetric. PLEASE BE CAREFUL to properly consider the changes and assign appropriately. CyMetric supports the filtering of the displayed grid to assist targeting the controls that need to be changed. Similar to other grid areas within CyMetric, Users can filter by multiple parameters to display the desired controls.
Filter by Key Word
To filter by key word, simply type the filter element (control identifier, system name, control owner, etc.). CyMetric will seach ALL fields for a keyword match and display the appropriate control instances that contain that search string. NOTE: This search mechanism will search ALL COLUMNS for the search parameter. For example, if a User types AC in the filter, every word that has AC in it will be displayed in in the output grid. Multiple filter entries can be included in the filter area.
PRO TIP: If you want to filter by control identifier, include the dash after the two-letter prefix (e.g. AC-).
Filter by Column Data Element
To limit the key word search to a specific column, Users need to include the column reference inthe search parameter. To use this search option, simply type the column header name followed by a colon and then the term you are searching for. Be careful to spell the column header exactly as it is shown on the screen. For example, SYSTEM: Frontline. Multiple filters can be included in the filter area following the same design.
Select the Control Owners that Need to Be Changed
Once Users have filtered the control instances to reflect the controls that need to be modified, click on the appropriate check box(es) for the desired controls. Users can decide on changing individual controls, pages of controls one at a time or all controls that fit the search criteria. See below for specific details. When the appropriate control instances are selected, click on the red check icon in the top right section of the filter area. NOTE: This Single Check icon will appear when individual control instances are selected or the Page Box option is selected. The system defaults to the Double Check icon until specific control instances are selected.
Global change for specified control instances or Page Box selection. | Global change to ALL control instances that meet the search filter criteria. |
INDIVIDUAL CONTROL INSTANCE BOXES: Selecting individual boxes will change ONLY those selected boxes.
PAGE BOX: Selecting the check box at the top of the display grid will change ONLY THOSE CONTROLS THAT ARE DISPLYED ON THE INDIVIDUAL PAGE. There may be more controls on the following page(s) that also fit the search criteria.
DOUBLE CHECK ICON: If Users want to change EVERY control that meets the search criteria, including those that extend beyond the first page of results, click on the Double Check icon on the upper right area on the filter line.
CHANGING THE CONTROL OWNER
Once Users select the control instances that need to be changed and clicked on the appropriate Red Check Box, they are prompted to change the control owner. CyMetric provides details onthe number of control instances that will be changed by the selection.
Choose the appropriate new control owner from the dropdown list. The new name is inserted into the dialog area. User can move forward with the global change by clicking on the Confirm button.
NOTE: If there is a significant number of controls to change, CyMetric will move the function to a background process enabling users to do other activities in CyMetric while it executes. Users will be informed when the process is completed by a notice in the top right corner of the CyMetric screen. Click on the Bell Icon and the Notification text to clear the notice.