Product, Application Development, and Quality Templates
|
Object Name |
Function |
Owners |
Approve Date |
|
Change Committee Review Board |
The Change Committee Review Board Template guides the completion of documentation for the purpose of enterprise or high priority/impact Change Management. |
[Name of Chief Technology Officer] |
|
|
Change Review Board Checklist |
Checklist identifies validation items before a change control can be approved or closed |
||
|
Emergency Deployment Authorization |
Emergency code change requires written approval by Quality, Development, and CTO. The Emergency deployment form represents signed approval by all necessary parties and is submitted to the Network or Data Center Operations prior to emergency deployment of code to production. Emergency change is subject to Change Management policy and is reviewed prior to and post change implementation. |
[Name of Chief Security Officer] |
|
|
High-Level Test Plan |
Template is used to document high-level aspects of a test plan |
[Name of Chief Technology Officer], [Name of Quality Assurance Manager] |
|
|
ICQ Physical Security |
Template is used to generate a new unique instance of ICQ Physical Security. Templates, when used, constitute a work product, which is processed and then stored as control evidence in the \\...\PAL\IT Process Asset Library\Process and Procedures\Security Management\Template\ folder |
[Name of Chief Security Officer], [Name of Chief Technology Officer] |
|
|
ICQ Security Policy |
Template is used to generate a new unique instance of ICQ Security Policy. Templates, when used, constitute a work product, which is processed and then stored as control evidence in the \\...\PAL\IT Process Asset Library\Process and Procedures\Security Management\Template\ folder. |
[Name of Chief Security Officer], [Name of Chief Technology Officer] |
|
|
Implementation Planning Template |
Provides documentation format for an implementation. |
[Name of Process Librarian] |
|
|
Internal Control Testing Template |
Template is used to document all aspects of testing an internal control |
[Name of Process Librarian] |
|
|
Meeting Agenda and Minutes.dot |
[Name of Process Librarian] |
||
|
Meeting Form Letter |
This letter is linked in the console as a template. |
[Name of Process Librarian] |
|
|
Meeting Minutes Template.dot |
[Name of Process Librarian] |
||
|
Network Change Identification Form |
Template is used when changes and/or security violations are found on the network, to systems, or to servers that did not go through the formal change control process. |
[Name of Chief Security Officer] |
|
|
Policy Profile |
|||
|
Process Profile Template |
Template is used to document all areas of a process |
[Name of Process Librarian] |
|
|
Program Profile Template |
Template is used to document all areas of a program |
[Name of Process Librarian] |
|
|
Project Charter |
Template is used to document the scope, assurance, and resources of a project |
[Name of Process Librarian] |
|
|
Project Plan Definition |
Template is used to document all areas of a Project Plan |
||
|
QA Planning Kickoff Check List |
Template is used to guide documents and tasks needed prior to QA Planning |
||
|
Request For Exemption |
Template is used to document all areas of risk associated with requested exemption |
[Name of Chief Security Officer] |
June 23, 2005 |
|
Request For Removal of Media |
Template is used to generate a new unique instance of Request For Removal of Media Template. Templates, when used, constitute a work product, which is processed and then stored as control evidence in the \\...\PAL\IT Process Asset Library\Process and Procedures\Security Management\Template\ folder. |
[Name of Chief Security Officer], [Name of Chief Technology Officer] |
|
|
Requirements Completeness Checklist |
Template is used to guide the review of requirements to assure completeness across all areas. |
, [Name of Product or Project Management Director] |
|
|
Risk Criteria |
Template is used to generate a new unique instance of Risk Criteria Template. Templates, when used, constitute a work product, which is processed and then stored as control evidence in the \\...\PAL\IT Process Asset Library\Process and Procedures\Security Management\Template\ folder. |
||
|
RunBook Security Section What to Describe |
Template is used to generate a new unique instance of RunBook Security Section What to Describe Template: (For financial/high-risk servers). Templates, when used, constitute a work product, which is processed and then stored as control evidence in the \\...\PAL\IT Process Asset Library\Process and Procedures\Security Management\Template\ folder. |
[Name of Chief Security Officer], [Name of Chief Technology Officer] |
|
|
Secure Email and File Transfer |
Template is used to document electronic security regarding email and file transfer. |
[Name of Chief Security Officer] |
|
|
Security Infrastructure Plan |
The purpose of the Security Infrastructure Plan is to establish strategic, tactical and annual information security plans for COMPANY. |
[Name of Chief Security Officer] |
|
|
Security Program and Program Test Profile |
Template is used to generate a new unique instance of Security Program and Program Test Profile Template. Templates, when used, constitute a work product, which is processed and then stored as control evidence in the \\...\PAL\IT Process Asset Library\Process and Procedures\Security Management\Template\ folder. |
||
|
Situation Evaluation Form |
Template is used to used to capture and fully develop and analyze security risks. |
[Name of Chief Security Officer] |
|
|
Software Requirement Specifications Template |
Template is used to document all requirements for software |
Thom Gray, [Name of Product or Project Management Director] |
|
|
RunBook Template |
The RunBook or System Documentation book contains information necessary to run and maintain a core business system. In the event of emergency staffing change, this document serves to guide a new employee through the support of this system. |
||
|
System Operational Requirement |
Template is used to document all operational requirements for a system |
||
|
Test Plan Template |
Template is used to document all areas of a Test Plan |
||
|
User Access Program Checklist |
Template is used to generate a new unique instance of User Access Controls Work Program Template. Templates, when used, constitute a work product, which is processed and then stored as control evidence in the \\...\PAL\IT Process Asset Library\Process and Procedures\Security Management\Template\ folder. |
[Name of Chief Security Officer], [Name of Chief Technology Officer] |
|
|
Employee Warning Notice |
Template is used to warn an employee when they do something inappropriate and how to improve. |
||
|
Job Analysis Questionnaire |
Job Analysis Questionnaire template is used to describe employee's responsibilities and duties among other things. |
||
|
Job Description Template |
Template is used to provide a brief description of the general nature of the position, an overview of why the job exists, and what the job is to accomplish. |
||
|
[Name of the core product or service] R# Internal Release Notes |
The purpose of these release notes is to describe the feature enhancements and fixes that were included in [Name of core product or service] Release ###. |
Which Tool Stores Process and Work Instruction information?
Process Engineering manages a list of all Work Instructions and Processes in the Facilitated Compliance Management Object table. There are a variety of reports that summarize the function for all processes as well as provide an overview of all process flow diagrams.
Figure 22. Facilitated Compliance Management provides summary reports for many object types
Figure 23. Facilitated Compliance Management Allows Process Librarian to capture and catalog all process objects
Flow Diagram
EnterpriseGRC Solutions, Inc. Consultants are famous for documentation

When Do I Use a Flow Diagram?
Flow Diagrams are developed to provide a high-level summary of steps in any process or procedure. They are "High Level", not vague. Controls are also listed in Flow Diagrams, further demonstrating constraints that either prevent error or reinforce correct movement. Key control template objects are created by process engineering in response to the current controls in scope for audit. These items detail all aspects that control a process.
Following are my favorite choices for simple Process Objects and some suggestions for using Visio to capture and automate their properties
See or download "Sample of A Business Process" in Word 2016 (please virus scan all downloads)
Visio Shapes and Custom Properties for Evidence of Process Controls
|
|
![]() |
Document Title, Scope, Revision, Release Date, Editors, Affirmation Team |
|
|
![]() |
Reference to other process documents and to full processes outside of the scope of the current document. |
|
|
![]() |
Identifies process activity, noting control issues and potential gaps, owners and event sequence. |
|
|
![]() |
Decision point and criteria for movement |
|
|
![]() |
Grouping allows representation of simultaneous events |
|
|
![]() |
Loop limits usually reflect key controls |
![]() |
Data Management: What data is used, how is it classified, retained, transferred, accessed | |
![]() |
![]() |
Data Management: What data is used, how is it classified, retained, transferred, accessed |
![]() |
List of external documents used to complete the process, the status of use in controls evidence, creation frequency, description of use Sequence is always 9.9 so that all data sources are clustered to the bottom of the process report. |
|
![]() |
![]() |
Exit and entrance criteria for movement from one activity to the next. Where criteria for movement is monitored by a system and is critical to control activity, this should be filled in. Where this is true, there would be an expected control. |
![]() |
![]() |
Trigger and Exit criteria |
























Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics