Skip to main content

Set up a control plan with Tenacy

Monitoring plan, operational maintenance, security maintenance: the control plan goes by several names. Here's how to set it up in Tenacy.

The fundamentals of a control plan in Tenacy

In Tenacy, a control plan is a set of recurring tasks that ensure and/or check the correct functioning of your security measures. Carrying out these recurring tasks at a given frequency lets you verify that each measure hasn't just been implemented, but continues to protect your organization over time.

Understanding the key concepts for your control plan

Security measure

A measure is a piece of software and/or a process and/or a team that secures a perimeter. To build a control plan on a measure, it must first be implemented in Tenacy.

Recurring task

A recurring task is an action that must be carried out at a given frequency. It's used to check the correct functioning of a security measure, and optionally to collect associated metrics.

There are two types of recurring tasks:

  • Operational: for example, updating the AD following a departure or arrival

  • Control: for example, checking that all active AD accounts correspond to active employees

🔎 Recurring tasks can only be created on implemented security measures.

⚠️ A measure can be checked by several recurring tasks, but a recurring task never checks more than one security measure.

Metric and indicator

A metric is a building block of an indicator: it's a numerical value you enter when completing a recurring task (for example, a number of monitored domains). An indicator is a separate object, built from one or more metrics, used to track a trend over time.

Together, recurring tasks and indicators make up the controls used to calculate the security measure's operations score.

Roles

The pilot creates the control and assigns it to an owner (local pilot or contributor), who is responsible for entering the data. An approver can be added to validate each completion before it's taken into account in your scores. See this article for more detail on setting up a level 2 control.

What control reporting is available in Tenacy?

Monitoring your control plan relies on several levels of indicators, which feed into your security measures' operations score:

Recurring task achievement indicators

  • Achievement rate of a given recurring task

  • Aggregated achievement rate across a group of recurring tasks

  • Success rate (Done OK) of control type recurring tasks

Indicators built from metrics

  • Customizable formulas (addition, subtraction, multiplication, division, number of days...)

  • Indicator with history, calculated at a fixed frequency

  • Activity or performance indicator

Security measure's operations score

The entry rate of recurring tasks and the achievement of performance indicator targets combine to produce the measure's operations score.

🔎 This operations score is only one of the two components of a measure's overall performance score, along with efficiency. Full details are explained in Understanding the efficiency, operations, and performance scores of a security measure.

These indicators can be displayed in a dashboard.

In practice, how do you create a new control?

Identify the measure and perimeter to check. If the measure isn't already implemented in your environment, implement it first.

  • From the security base: go to the detail page of the implemented measure in question, then in the Operations section, click "Add control" You'll see the recurring tasks and indicators already associated with this measure, and can view their details via the information button (the "i" icon). Check the controls you want to track, select an owner and a register to file the recurring task under, then save.

⚠️ When creating from the Recurring Tasks module, make sure to check the perimeter identifier shown next to the measure name in the "Measure" dropdown: several perimeters may have implemented the same measure, so be sure to select the right instance.

💡 If you want to adjust a recurring task from the catalog to better match your processes (for example, changing its frequency), this is possible as long as no completion history exists yet for this task. Once an occurrence has been logged, the frequency can no longer be changed directly: you'll need to either clear the history, or close the task and create a new one if you want to keep the existing history.

Go further

Once your recurring task is created, these resources will help you go further in setting up your control plan:


Frequently asked questions

Can a security measure be checked by several recurring tasks?
Yes, a measure can be tracked by several recurring tasks. However, a given recurring task always checks only one security measure.

Do you have to attach a metric to a recurring task?
No, this isn't mandatory. Attaching a metric simply lets you enter a numerical value each time the task is completed, in addition to the Done OK / Done KO / Not done status.

Does a "Done KO" recurring task lower my measure's score?
No, the achievement rate that feeds the operations score only measures whether the control was carried out on time, not whether it was successful. A Done KO counts as a completion in the same way as a Done OK. To track failed controls, refer to the OK rate, which is specific to control tasks.

What's the difference between an operational recurring task and a control recurring task?
An operational task corresponds to a security operation that is either carried out or not. A control task is used to check that a process is working correctly: it can be completed with a positive (Done OK) or negative (Done KO) result.

🔎 Once your control plan is in place, find out how to optimize its day-to-day monitoring: Optimizing your day-to-day compliance monitoring: best practices in Tenacy.

Did this answer your question?