27 May, 2023
Expand All

Helpful Videos for You

Need help? Check out videos for quick assistance!

We are excited to introduce several updates to the Vendor Assessment and Processing Operation Assessment (POA) features, including:

  • A new Security and Systems step added to the POA form.
  • Enhancements to both logs with new filtering and search functions.
  • New tooltip added to the search bar in the POA log.
  • New options for adding notes, reviewers, and approvers in the POA log.
  • Changes to how the POA title is displayed in the log.

Enhancements to the vendor assessment and processing operation assessment logs

  • When accessing the logs, users will see Vendor Assessments or POAs based on the filters applied (which could range from no filters to multiple filters).
    • No Results Found: If no results are found and no filters are applied, this indicates that no vendor assessments or POAs exist, or the user does not have access. A message will prompt users to create a new Vendor or POA. If filters are applied and no results are found, the newly implemented Clear button allows users to reset the filters and view the full list again.
    • Search Bar Enhancement: A tooltip has been added to the search bar in the POA section, providing guidance on how to use the search functionality. If no search results are found, users can reset the search using the Clear button to return to the full list.
    • New Options in POA Log: The Add Note, Add Reviewer(s), and Add Approver options have been added to the POA Log, accessible via the three-dot menu located on the right-hand side of each POA. This updated menu layout improves usability and provides quick access to these features.
    • Editing POAs: Users will now use the Edit button, located next to the three-dot menu, to modify POAs. The POA title is no longer clickable for navigation, aligning with other areas of the platform where the edit button is used for form modification. This update prevents accidental clicks on the POA title and helps users navigate the log more efficiently.
Delete

The introduction of the security and systems section of the processing assessment operation form

  • A new step, Security and Systems, has been added to the Processing Operation Assessment (POA) form to capture detailed information about system architecture and security measures involved in the processing operation.
  • This new step is step four in the POA, positioned between 3 Safeguarding and 5 Assessment Summary.
  • It focuses on documenting key details, including:
    • Whether the processing operation uses a locally hosted or cloud-based system
    • Where the system is hosted
    • The type of system in use
    • System access and third-party involvement
    • Backup processes, encryption, and security controls in place in the event of a breach
    • System ownership and the existence of a support contract
  • This step ensures that all relevant aspects of system security, access control, and third-party dependencies are thoroughly documented. By collecting this information, users can ensure compliance with security standards, identify potential risks, and manage systems more effectively in the context of the processing operation.

Delete