The fundamentals of a control plan in Tenacy
In Tenacy, a control plan is a set of recurring tasks that ensure and/or check the correct functioning of your security measures. Carrying out these recurring tasks at a given frequency lets you verify that each measure hasn't just been implemented, but continues to protect your organization over time.
Understanding the key concepts for your control plan
Security measure
A measure is a piece of software and/or a process and/or a team that secures a perimeter. To build a control plan on a measure, it must first be implemented in Tenacy.
🔎 See Understanding the concept of security measure for more details.
Recurring task
A recurring task is an action that must be carried out at a given frequency. It's used to check the correct functioning of a security measure, and optionally to collect associated metrics.
There are two types of recurring tasks:
Operational: for example, updating the AD following a departure or arrival
Control: for example, checking that all active AD accounts correspond to active employees
🔎 Recurring tasks can only be created on implemented security measures.
⚠️ A measure can be checked by several recurring tasks, but a recurring task never checks more than one security measure.
Metric and indicator
A metric is a building block of an indicator: it's a numerical value you enter when completing a recurring task (for example, a number of monitored domains). An indicator is a separate object, built from one or more metrics, used to track a trend over time.
Together, recurring tasks and indicators make up the controls used to calculate the security measure's operations score.
Roles
The pilot creates the control and assigns it to an owner (local pilot or contributor), who is responsible for entering the data. An approver can be added to validate each completion before it's taken into account in your scores. See this article for more detail on setting up a level 2 control.
What control reporting is available in Tenacy?
Monitoring your control plan relies on several levels of indicators, which feed into your security measures' operations score:
Recurring task achievement indicators
Achievement rate of a given recurring task
Aggregated achievement rate across a group of recurring tasks
Success rate (Done OK) of control type recurring tasks
Indicators built from metrics
Customizable formulas (addition, subtraction, multiplication, division, number of days...)
Indicator with history, calculated at a fixed frequency
Activity or performance indicator
Security measure's operations score
The entry rate of recurring tasks and the achievement of performance indicator targets combine to produce the measure's operations score.
🔎 This operations score is only one of the two components of a measure's overall performance score, along with efficiency. Full details are explained in Understanding the efficiency, operations, and performance scores of a security measure.
These indicators can be displayed in a dashboard.
In practice, how do you create a new control?
Identify the measure and perimeter to check. If the measure isn't already implemented in your environment, implement it first.
From the security base: go to the detail page of the implemented measure in question, then in the Operations section, click "Add control" You'll see the recurring tasks and indicators already associated with this measure, and can view their details via the information button (the "i" icon). Check the controls you want to track, select an owner and a register to file the recurring task under, then save.
From the Recurring Tasks module: you can create your own recurring task and associate it with a measure already implemented on your perimeter.
⚠️ When creating from the Recurring Tasks module, make sure to check the perimeter identifier shown next to the measure name in the "Measure" dropdown: several perimeters may have implemented the same measure, so be sure to select the right instance.
💡 If you want to adjust a recurring task from the catalog to better match your processes (for example, changing its frequency), this is possible as long as no completion history exists yet for this task. Once an occurrence has been logged, the frequency can no longer be changed directly: you'll need to either clear the history, or close the task and create a new one if you want to keep the existing history.
Go further
Once your recurring task is created, these resources will help you go further in setting up your control plan:
For the full details on creating a recurring task (form fields, calendar-based or not, completion window, approval): Create a recurring task.
To collect a metric directly when completing the recurring task: Attach a metric to a recurring task.
To understand how your recurring tasks affect your measures' scores: Understand the impact of recurring tasks on a measure's scores.
Frequently asked questions
Can a security measure be checked by several recurring tasks?
Yes, a measure can be tracked by several recurring tasks. However, a given recurring task always checks only one security measure.
Do you have to attach a metric to a recurring task?
No, this isn't mandatory. Attaching a metric simply lets you enter a numerical value each time the task is completed, in addition to the Done OK / Done KO / Not done status.
Does a "Done KO" recurring task lower my measure's score?
No, the achievement rate that feeds the operations score only measures whether the control was carried out on time, not whether it was successful. A Done KO counts as a completion in the same way as a Done OK. To track failed controls, refer to the OK rate, which is specific to control tasks.
What's the difference between an operational recurring task and a control recurring task?
An operational task corresponds to a security operation that is either carried out or not. A control task is used to check that a process is working correctly: it can be completed with a positive (Done OK) or negative (Done KO) result.
🔎 Once your control plan is in place, find out how to optimize its day-to-day monitoring: Optimizing your day-to-day compliance monitoring: best practices in Tenacy.


