Attestor Configuration

The Attestor functionality is crucial because it allows our Attestor customers to configure their custom assessment.  The assessment will be unique to each organization and based solely on the Nymity PMAF standard.

NOTE: You must have Attestor 2.0 configured in your account and an Attestor Admin role to configure an attestation.

To access the Attestations page, hover your mouse over the PrivacyCentral  icon (1), click Settings (2), then select My Attestations (3).

Attestations Page

You can change the appearance of your attestations list by clicking the Configure Column icon. Tick the checkboxes next to the data you want to see in the columns.

Under the Action column, you can edit, remove an existing attestation, clone an attestation, or even view the audit log by clicking the respective icons.

Add New Attestation

To add new attestation, do the following steps:

  1. Click the Add New Attestation button to start the attestor assessment configuration.

  2. Take the necessary steps to set up your custom assessment.

NOTE: In the attestor edit mode,  you can click on the top steppers to navigate between steps. However, you must go step-by-step the first time you create the Attestation.

Step 1: Set Initial Information

  1. Choose an attestor response option (1). Once set, this cannot be changed. Hover over the more info icon to learn the distinction between Control Effectiveness Responses and Maturity Model Responses.

NOTE: If you later change your response option configuration while editing the questions, you will see a warning message to confirm the reset.

  1. Select the type of scoring (2) for the selected attestation.
     
    • When Accountability Mechanism Model Scoring is selected, the scoring for the question is dependent on the response and evidence selected.
Response Value Percentage Definition
Non-existent 0 0% No known measure in place
Ad Hoc 1 20% Initial or reactive
Repeatable 2 40% Documented sufficiently such that the same steps may be repeated with potentially consistent results
Defined 3 60% Standard processes are established
Managed 4 80% Standard processes are established, monitored, and measured
Optimized 5 100% Standard processes are established, monitored, measured, and continually improved
N/A     No control effectiveness associated
  • If no accountability mechanism is added to any of the responses, the value will default to 1 or 20%.
  • When Question Response only is selected, the scoring for the question is dependent on the response selected.
If Generate Task == Yes
Yes 4 80%  
No 0 0%
  • Task is generated
  • When evidence is added and task is closed score moves to 60%
N/A No value    
If Generate Task == No
Yes 4 80%  
No 0 0% No task is generated
N/A No value    
  1. To create an Attestation that generates a task or bases scoring on evidence (Accountability Mechanisms), enable/disable the Generate Task toggle (3).
  2. Set a custom name for the attestation (4).
  3. Add Org Units (5) by clicking the drop-down list. 
  4. Click Next (6).

Step 2: Select Control / PMA

  1. Choose the Privacy Management Categories (PMC) and Privacy Management Activities (PMA) to assess. 
  2. Click on the PMC from the left panel to show all the associated PMAs. 
  3. Click Next.

NOTES

You can select or deselect all the PMCs and PMAs you want to include. 

The Privacy Management Categories (PMC) is a container for a collection of related PMAs. Each one represents a larger goal of the privacy office and lists all the activities that can be worked on to achieve that goal.

The Privacy Management Activities (PMA) is a single activity in the creation or maintenance of a privacy program. It is similar to a control, but with a more "actionable" focus.

Step 3: Edit Questions & Tasks

This step allows you to create and edit the questions. This is the most involved part of the process because the Admin can see all of the PMCs and PMAs that have been selected underneath them.

  • You can change the Attestation name on the left side (1).
  • By clicking the trash bin icon (2), you can delete the control group as well as the PMCs and PMAs that were added by mistake or that no longer needed to be assessed.
  • Click on each segment (3) to rename the Control Group/PMC Name and Control/PMA Name along with its description (4).

  • Click on a PMA to open the question creation modal containing a pre-populated PMA question. You can, however, use the out-of-the-box questions or create your own.
  • Start editing the required information by filling out each field, i.e the Control/ PMA Name, Type, and Description.

  • All PMAs added to the Attestor are mandatory by default for both new and existing customers.

NOTE: Admin can change the type of each PMA and select Optional for both attestor configuration types while creating new attestors and while updating existing published attestors.

  • Click the Respondent Type drop-down menu to select a respondent for all questions.

  • To set up and add questions, click the Add Question link to display the question modal and click the Add Follow-on Question link following a primary question. Ensure to add conditional logic to trigger the follow-on question.

NOTE:  You will be able to add primary and follow-on questions if you have Admin access.

  • Assign a task for the response choice as needed. Control Effectiveness Responses include Yes, No, or N/A response choices.

  • You can rearrange the set of questions by dragging and dropping the control up and down using the draggable dots icon.

  • Use the corresponding trash bin icon if you wish to delete a primary/follow-on question. 

Step 4: Set Weightings %

The Privacy Management Category (PMC) tab lists each PMC with associated PMA's and allows you to set a weight for each PMC and PMAs within a PMC. PMC and PMA weighting is set at the account level and applies similarly for each reportable unit within PrivacyCentral.

By default, all PMCs and all PMAs under a PMC will have equal weighting (e.g., If there are three PMCs, each will have 33.3% weight, and if there are four PMAs under a PMC, each will have 25% weight).

  • You may click the Equally Distribute PMC Weights option to equally distribute the weights across all PMCs. 


     
  • You may reset the scoring to the default values by clicking the Reset Weighting button.


     
  • You may also download a XLS file of the weightings by clicking Export Weightings (*xls).

Note that weightings all PMCs and all PMAs under a PMC must equal to a total of 100%. Weightings not equal to 100% disables the Save Changes button.
 

Step 5: Publish

This step allows you to publish the attestation questions. Make sure to review before publishing
 

When publishing the attestation, this becomes available to assess on the Program Overview page. To view the attestation as part of all the Laws and Frameworks, select the Attestor in the Applicable Standards page for the Org unit associated and proceed to the Program Overview page.
 

Managing Attestations

You may unpublish an attestation by clicking the Edit Attestation option, then the Unpublish and Edit button in the pop-up window.

To track multiple custom attestations in a single account and updates, click the View Audit Log icon (1) on the attestation list page. Customize your view by applying filters (2) according to the Date, User, and Action committed.

You can also arrange the columns however you want. You can check the timestamp which records the event’s time and date, attestor name, entity type, user, user role, and action committed (3). 

Conditions Applicable for Maturity Model Calculation (Approval Process)

When approving a control in the Maturity Model, change the CE score according to the responses:

NOTE: Any open task will be closed automatically.

Responses Scores
Non-existent 0%
Ad Hoc 20%
Repeatable 40%
Defined 60%
Managed 80%
Optimized 100%
N/A N/A

Before approval with AM (Task will be closed):

NOTE: Non-existent and N/A cannot have AM. No task is defined for Managed, Optimized, and N/A.

Ad Hoc 20%
Repeatable 40%
Defined 60%
Managed 80%
Optimized 100%

Before approval without AM, when the task is still Open and Closed (for Non-existent, Ad Hoc, Repeatable, Defined):

NOTE: No task is defined for Managed, Optimized, and N/A.

Non-existent 0%
Ad Hoc 20%
Repeatable 20%
Defined 20%
Managed 20%
Optimized 20%
N/A N/A