Documentation and Attachments

Documentation for Inventory and Other Objects

There are a number of objects in Isora GRC that accept documents as attachments. You can attach documents to a host, an app, or a vendor product in Inventory, and an exception request in Compliance. In the future, additional objects may also support document attachments.

Documentation save area at the bottom of the inventory page for a an app

The following document types are accepted by Isora GRC:

'image/png', 'image/jpeg', 'image/gif', 'application/pdf', 'text/csv', 'text/plain', 'application/vnd.oasis.opendocument.text', 'application/vnd.oasis.opendocument.spreadsheet', 'application/vnd.oasis.opendocument.presentation', 'application/rtf', 'application/msword', 'application/vnd.ms-excel', 'application/vnd.openxmlformats-officedocument.wordprocessingml.document', 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet', 'application/x-iwork-numbers-sffnumbers', 'application/x-iwork-keynote-sffkey', 'application/x-iwork-pages-sffpages', 'application/vnd.ms-powerpoint', 'application/vnd.openxmlformats-officedocument.presentationml.presentation', 'application/vnd.apple.keynote', 'application/vnd.apple.pages', 'application/vnd.apple.numbers', ]

If you attempt to attach an unrecognized file type, the upload will fail.

Where are the documents stored, and who has access to them?

All uploaded documentation is saved in your S3 bucket in AWS. Uploads are private to your individual instance of Isora GRC. Anyone Isora GRC user with appropriate permissions to view the object with which the documentation is associated can view them. Anyone with edit permissions on the associated object can view or remove them.

Documentation for Questions on Assessments

All questions on all types of assessments support the ability to attach supporting documentation. Only superusers can change the configuration of an individual question to support documentation upload and under what conditions to do so. Any attachments to a specific survey are stored in the S3 bucket in a private area. Isora GRC users who are authorized to view the completed assessment can also download and view the attachments from the associated surveys. See also: https://saltycloud.atlassian.net/wiki/spaces/TES/pages/1275463617 .