Skip to main content

Assessments

Hyperproof supports control, requirement, and risk assessments.

Assessments help you review, evaluate, and improve controls, risks, or requirements across your organization. Some common compliance frameworks that encourage control-based assessments are NIST and SOC 2.

Controls, requirements, and risks can be audited for attributes including design, language, effectiveness, and reliability. When your organization’s controls, requirements, and risks are sufficient, internal audits based on a Document Request List (DRL) run much more smoothly because the bulk of the work is already done.

Many organizations perform assessments for the following reasons:

  1. Early detection - Routinely checking your controls, requirements, and risks for exceptions helps you find them more quickly.

  2. Continuous improvement - Looking critically at your controls, requirements, and risks is the best way to ensure you’re not wasting resources.

  3. Minimize risks - Quickly find exceptions and non-functional controls, requirements, and risks to minimize risk exposure.

  4. Audit preparation - If you find and fix issues with your controls, requirements, or risks, there will be fewer for your auditor to report.

Assessment Process

A typical process that an organization might use to perform an assessment could include:

  1. Choosing objectives

  2. Selecting controls, requirements, or risks to evaluate

  3. Deciding how to evaluate those controls, requirements, or risks

    1. Writing tests for operational effectiveness

    2. Selecting a framework to evaluate the design

  4. Managing the project

    1. Assigning work

    2. Collaboration

    3. Following up

  5. Tracking and remediating issues

Understanding the assessment window

The Assessment window displays all active and completed assessments in your organization.

You can view assessments in the following styles:

  • Card view - Provides a kanban-style display of assessments, with each assessment represented by a card. Cards include assessment name, type, list of members, percent complete, and number of closed evaluations.

  • Grid view - Displays assessment records in a table where you can view and bulk edit them.

Assessment fields and options

Field/Option

Definitions

New

Create a new assessment.

filter.png

The Filter icon opens the Filter panel, where you can filter assessments by the following fields:

  • Name

  • Description

  • Status

  • People

card-grid-views.png

Use the view icons to switch the window between the Card view and Grid view. The Card view icon is on the left, and the Grid view icon is on the right.

Card view

Active

Groups the active assessments at the top of the window.

Completed

Groups the completed assessments at the bottom of the window.

Show/Hide archived

Displays or hides archived assessments.

Sort by

The Sort by field allows you to sort your assessment cards by the following fields:

  • Name

  • Completed evaluations

  • Total evaluations

  • Percent complete

  • Created on

Grid view

Show/Hide archived

Click the Show/Hide archived link below the grid view to display or hide a list of archived assessments.

Grid view - Menu bar

Use the Menu bar options to complete bulk updates to the list of assessments.

Select the checkboxes for the records you want to edit. Options and fields you can edit include:

  • Clear - Clears selected checkboxes

  • Members

Grid view - Columns

Click the column headings to change the sort order of the grid. The Members column doesn't sort.

Name

User-specified name of the assessment.

Description

User-specified description for the assessment. Hover over the Description field and click the pencil icon to edit it.

Type

Displays the assessment type. Assessment types include:

  • Control

  • Requirement

  • Risk

Status

Shows the status of the assessment. Statues include: Active and Completed. Hover over the Status field and click the pencil icon to edit it.

Primary contact

The primary contact is the user who created and owns the assessment. This user can be modified at any time. Hover over the field and click the pencil icon to edit it.

Members

Users who are members of the assessment

Completed evaluations

Number of evaluations with a status of Closed.

Total evaluations

The total number of evaluations in the assessment, regardless of status. This number excludes archived evaluations.

Percent complete

The percentage of completed evaluations in the assessment. This number excludes archived evaluations.

Created

Date the assessment was created.

Did this answer your question?