The Regulations area manages which laws and standards apply to the
organization, and assesses their objectives individually.
Activate a regulation
Clicking a regulation under Available Regulations activates it; it then
appears under Active Regulations, whatever its type. Deactivate at the
bottom of an active regulation’s tile deactivates it again.
Deactivating deletes no data. Assessments, justifications, review dates, and
relations to controls and documents are kept — a tile that was previously
installed shows this through the number of complete and applicable objectives
from before deactivation and the date of the last activation. Reactivating only resets the status to active and does not
re-import the objectives; only a first-time activation does that, which makes
it noticeably slower.
After deactivating, Docusnap365 closes any open detail tab of that
regulation. Do not deactivate a regulation you are currently working on.
Assess an objective
You assess every objective in the tree in the assessment editor in the
sidebar. It consists of the blocks Applicability, Implementation Status,
Review, Description, and Relations.
The groups in the tree are the regulation’s root sections, not the level
directly above an objective — the same sections the filter buttons above the
tree also show. Structural sub-headings do not count toward a group’s number
of complete objectives; only leaves are assessable.
Applicability toggles between Applicable and Not applicable. A
Justification is required with Not applicable. Conversely, a
Justification requires a decision: while an objective is still Not
Assessed, an entered Justification can only be saved together with a
decision.
As long as no decision has been made on an objective, the toggle also shows
the state Not Assessed. It disappears for good with the first saved decision — as
with protection need on an asset, a decision once made can only be changed,
not reverted. See
Determine Protection Needs.
When an objective is Not applicable, the Implementation Status block does
not appear. Otherwise you choose Pending, Not implemented, Partial, or
Complete. With Not Assessed, the block stays locked until you decide on
applicability.
In the Relations block you link controls, documents, and assets with Link,
including for Not applicable objectives. Control lets you create a new
control directly from the editor and link it. The Journal link at the bottom
of the editor shows the change history of the assessment.
Deleting a relation removes only the relation — the control, document, or
asset itself stays. With multiple rows selected, this runs in a batch:
successful rows disappear even if some fail; a summary message names the
ones that failed.
Use the Description block to expand the full regulation text. It is worth
doing whenever an objective’s short label is ambiguous.
The editor only saves on request. Closing it with unsaved changes prompts a
confirmation — confirming discards the assessment. An invalid date in the
Next Review field also blocks saving.
Assess several objectives at once
With multiple objectives selected, Edit opens Bulk Edit with the fields
Applicability, Justification, and Implementation Status; Applicability
and Implementation Status can also be left at ”— No change —”.
Justification is locked while Applicability is ”— No change —”, and
required once you choose Not applicable. A justification alone is not
enough: you can apply only once Applicability or Implementation Status is
set. The apply button carries the number of selected objectives and, once run,
reports full success, partial success with the number of failures, or complete
failure.
If you set an Implementation Status for a selection that contains objectives
that are not applicable or not assessed, Docusnap365 saves nothing. Set
Applicability to Applicable in the same pass, or remove those objectives
from the selection.
This is the entry point for a newly activated regulation: mark everything
that does not concern your organization as Not applicable in one pass.
The number of applicable objectives then reflects a realistic base.
Review
The block shows the date of the last review and the Next Review field.
Complete Review requires a comment and adds an entry to the table below.
Understanding Compliance explains
regulation types and objective statuses.
Check Compliance Status shows the metrics across all
active regulations.