Information Systems Controls & Remediation Manager (ISCRM)

Make IT-controls assurance a live, connected model — from the information system and its control objectives, through the controls and their periodic assessment, to the deficiencies those assessments find, the remediation that fixes them, the retest that proves it, and the authorised decision to close.

Its central question:

For each information system, are its controls designed and operating effectively — and where they aren't, is the deficiency being remediated, independently retested, and closed on a clean, authorised basis (or held open by a blocking gap)?

It sits beside the agency's IT asset register, IAM and change systems and the audit office's control library — it owns the assessment → deficiency → remediation → retest → closure lifecycle and the assurance relationships around their records.

The assurance spine

Entity / Information System → Control Domain / Objective → Control → Assessment Cycle → Control Assessment → Control Deficiency → Remediation Plan → Remediation Action → Retest → Risk Acceptance / Assurance Decision → Closure Request → Closure Approval, with Evidence across the assessment steps and a Status History trail on each deficiency.

The documents

Page What's in it
00 — Overview What the app is, the domain, the 18 models by area, the demo scenario
01 — Quick Reference Menu map, every model, key status vocabularies, the demo data set
02 — System Diagram The controls-and-remediation data model as a diagram (+ interactive viewer)
03 — Phase 2 Scope The runtime not yet built: the deficiency state machine, closure guards, retest/risk-acceptance gates and the DomainEvents outbox

Status

Phase 1 (built): all 18 models render as an AI-Safe CRUD register with a dashboard, seeded with one coherent QAO-style IS-controls assessment (32 rows) — one deficiency remediated, retested PASSED and CLOSED, one that fails retest and sits open with a pending risk acceptance.

Phase 2 (scoped, not built): the deficiency lifecycle state machine, the closure guard rules (retest passed, no blocking deficiency, completion declared), remediation-plan versioning, and the DomainEvent outbox — see page 03.

Prototype system; draft. All entities, systems, controls, deficiencies, evidence and decisions in the demo data are fictional; values demonstrate structure only and are not real audit findings.