A hospital GRC lead wants generated access-review controls to appear only on applications classified as Critical Applications. How should the control objective be scoped?
Select an answer to reveal the explanation.
Short Explanation
Entity types are the mailing list for who gets which controls. Point the control objective at Critical Applications and generation drops the right controls on matching apps. Global-then-delete, one-off CI hacks, and exception templates are not how scoping is supposed to work.
Full Explanation
Control objectives are scoped to entity types (or related conditions) so Policy and Compliance generates controls for matching entities. Scoping to the Critical Applications entity type ensures only those applications receive the access-review controls. Leaving an objective global and deleting extras afterward is error-prone and reintroduces drift each generation cycle. Binding to a single CI or misusing exception templates does not implement entity-type–driven control generation.