The benefit of creating an automatic action plan is to be able to create actions on the requirements of a policy that have the lowest scores. This allows you to work on their compliance and therefore increase your compliance score.
Filtered display of requirements
From the "Policies" tab, a quick filter allows you to focus on the requirements with the lowest scores in your policies. In the example below, only requirements with a coverage score between 0 and 70 are displayed.
🔎 The filter is applicable to the 3 scores: declarative, coverage or measured.
Creation of an automatic action plan
It is now possible, on the basis of these scores, to automatically create an action plan for a given area.
Filtering requirements according to your needs
As mentioned above, you can focus on the requirements with the lowest scores to create your action plan accordingly.
🔎 You can also create an action plan for your entire policy.
Set up the action plan
Once the filter by score has been decided, click on the “Define an action plan” button.
Once the perimeter has been picked, the solution gives you the possibility of selecting the controls that need to be corrected. This allows you to adjust the scope of your action plan.
Tenacy, based on the scores, the implemented or implementation measure, automatically creates an action plan:
When you click on “Create an action plan”, the solution offers 3 choices:
Associate plan to perimeter: action plan managed solely by the perimeter
Handle plan centrally: manage the action plan centrally only. The perimeter will contribute to the actions without seeing or managing the plan.
Associate the perimeter and follow centrally: action plan managed by perimeter and centrally.
🔎 For your policy, if you wish to have an action plan on several perimeters, you will have to repeat the operations for each perimeter. You will then have to select one of the 2 options “Handle plan centrally” or “Associate the perimeter and follow centrally”.
The solution will then ask you to select or create an action register:
Once the choice is confirmed, the action plan is generated: a pop-up tells you what has been created:
You can then find your created register in the “Action plan” tab.
Your action plan is created!
You can now edit it: change the color of the groups, adjust the planning of your actions etc.
🔎 Groups are created based on your policy's controls groups.
Automatic instantiation of measures
Concretely, for each selected requirement, Tenacy checks whether a corresponding security measure is already instantiated in the perimeter's security baseline — that is, the set of security measures attached to that perimeter. If no measure yet exists for this requirement, Tenacy instantiates it automatically, based on the requirement's evaluation score:
Fully covered requirement (score of 100): the measure is instantiated directly as implemented, which enriches the perimeter's security baseline without requiring any corrective action.
Partially covered requirement (score between 1 and 99): the measure is instantiated as implemented and an implementation action is created in the action plan to finalize it.
Uncovered requirement (score of 0) or without a score: Tenacy creates an implementation action directly linked to the requirement, without instantiating an associated measure, and the measure is considered "not implemented" in the security baseline.
💡 This automatic instantiation of measures only applies to perimeters with a security baseline, i.e. internal perimeters. For suppliers and applications, only simple actions are generated: see the special case below.
Special case of suppliers and applications
This automatic action plan mechanism, previously reserved for internal perimeters, is now also available for supplier and application perimeters from the declarative score only. The "Define an action plan" button is accessible from the policy view associated with this type of perimeter, following exactly the same flow as described above: filtering controls, selecting them, then automatic generation.
⚠️ Since suppliers and applications don't have a security base (the set of security measures normally attached to an internal perimeter), only simple actions can be generated on these perimeters: improvement actions and implementation actions, which are linked to measures, remain reserved for internal perimeters. Each generated action reuses the name and details of the assessed control.
⚠️ Note: applications can only be created in the environment if you have the Projects security module activated.
🔎 For the full guide to managing your suppliers (mapping, evaluation campaigns, review and results), see Managing your third parties in Tenacy: a step-by-step guide.









