TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Organization

Estimated reading: 6 minutes 657 views

Organization

The Organization Page in TrustCloud provides an interactive and structured way to define, visualize, and manage an organization’s GRC (Governance, Risk, and Compliance) structure. With a dynamic org chart view, users can efficiently configure their compliance framework by organizing business units, products, and locations while maintaining relationships between standards, controls, policies, and systems.

Key Capabilities:

  1. Edit & Define GRC Structure: Users can create and customize their organization’s GRC hierarchy, including drag-and-drop functionality for business units, products, and location-based segments.
  2. Org Chart Visualization: The hierarchical structure displays the compliance framework, showing which standards, controls, policies, and systems apply to each segment.
  3. Segment Nesting & Scalability: Supports two levels of nesting, with additional levels dynamically hidden.
  4. Global Segment Management: Users can assign controls, policies, standards, and frameworks at a global level, ensuring consistency across the organization.
  5. Inherited & Customizable Objects: Initial setups inherit objects from the global segment while allowing CRUD operations on compliance elements (users can select from the existing program but cannot add new items).
  6. Segment Renaming: Flexibility to rename segments for clarity and alignment with internal structures.
  7. Cascading Changes: Parent-level modifications automatically impact child segments, streamlining compliance updates across multiple business areas.
  8. Missing Segment Support: If a required segment type is unavailable, users can quickly request additions via the “Contact Us” option.

This functionality ensures that compliance teams can seamlessly organize and adapt their GRC structure, aligning governance requirements with business operations.

What is a segment?

A segment represents a defined collection of controls, policies, systems, integrations, and risks associated with a specific Business Unit (BU), product, or location within an organization. Segments help structure compliance and risk management by grouping related components based on operational needs.

Defining segments is particularly useful for organizations that manage multiple BUs, products, or locations, each with distinct compliance requirements. For example, an organization may have three separate BUs, each maintaining its own SOC 2 certification, systems, and policies. Alternatively, a company may have one parent BU with two subsidiaries that share common controls and systems while maintaining distinct operational structures.

Configuring organization structure

You can configure your organizational structure from here.

  1. Select the most suitable structure from the three options and click on “Next” button. If your structure is not mentioned, then you can click on “My company doesn’t match any template.”
    Organization
  2. If you select “Geography Based,” you will be provided with a basic structure. You can drag and drop locations, business units or products as per your organizational structure. Click on “Next.”
    TC Segments 02
  3. Review your provided structure and click on “Publish.”
    TC Segments 03
  4. Similarly, you can select “Business Unit” or “Product Based” and follow the steps.

Final Segments View

Depending on the structure you have provided, the final view of the organizational structure will look something like this.

TC Segments 04 1

Defining global segment properties

If you have not defined your “Global” properties like controls, policies and systems, you will be displayed a message and a link to define them.

TC Segments 05

  1. Click on “Define Global Properties.”
  2. Drag and drop the standards and certifications and click on “Next” button.
    TC Segments 06
  3. Select and add controls, and click on “Next” button.
    TC Segments 07
  4. Select and add policies, and click on “Next” button.
    TC Segments 08
  5. Select and add systems, and click on “Next” button.
    TC Segments 09

Your global properties will be saved and published. You can view them on the “Organization” page.

Creating a segment

To create segment with TrustCloud,

  1. Go to your TrustCloud program and select “Organization” from the left-hand side menu.
    TC Segments 10
  2. Click on the “Add New” button.
    TC Segments 11
  3. Enter the segment name, type of segment and the parent segment.
  4. Click on “Add New Segment’ button.
    TC Segments 12
  5. Verify the parent segment and the organizational structure and click on “Save New Segment.”

Editing a segment

To create segment,

  1. Go to your TrustCloud program and select “Organization” from the left-hand side menu.
  2. Click on three-dot menu in front of the segment and select “Edit Segment.”
    TC Segments 13
  3. You can select and add or exclude controls, policies and systems to the particular segment.

Deleting a segment

To delete a segment,

  1. Go to your TrustCloud program and select “Organization” from the left-hand side menu.
  2. Click on three-dot menu in front of the segment and select “Delete Segment.”

The segment will be deleted from the respective parent.

Segment use cases

Segments help organizations structure their compliance and risk management programs by grouping related controls, policies, systems, and risks according to business needs. The following use cases illustrate how organizations can apply segments:

  1. Multiple business units with separate certifications: An organization with three distinct Business Units (BUs), each maintaining its own SOC 2 certification, can use segments to manage compliance independently for each BU while ensuring clear separation of policies, controls, and security practices.
  2. Product-specific security and compliance: Organizations offering multiple products that require unique security controls can define segments for each product. This ensures that security questionnaires receive accurate and product-specific responses, reflecting the distinct compliance requirements of each product.
  3. Regional compliance management: Organizations operating in multiple regions, such as America and Europe, may need to comply with different regulatory frameworks. For example, the European business unit must adhere to the Digital Operational Resilience Act (DORA) compliance, requiring separate segment management to track and enforce region-specific regulations.

Standardizing and consolidating controls across business units: An organization looking to improve efficiency by consolidating common controls across different BUs can use segments to create a global parent BU with child BUs inheriting shared controls and policies. This approach allows for streamlined governance while maintaining flexibility for individual business needs.

Using segments in TrustOps

To view segments in TrustOps,

  1. Go to your TrustOps program
  2. Click on “Select View” link in the top-right corner of the screen.
  3. Make your selection of organization and scope.
    TC Segments 14
  4. Your view selection will be displayed at the top of the page and results are displayed as per your selection.
    TC Segments 15
  5. You can also change or clear your view using the “Clear View” and “Change View” links.

Using segments in TrustShare

To use segments in TrustShare,

  1. Go to your TrustShare program and select “Questionnaires” from the left-hand side menu.
  2. Click on “Add New Questionnaire” button and fill in the company details.
  3. Click on “Proceed” button.
  4. Select segments and click on “Add Questionnaire Details” button.
    TC Segments 16
  5. Complete your questionnaire creation as instructed. You can view the segments from the “Questionnaire in Progress” page. You can view segments of completed questionnaires as well.
    TC Segments 17

Using segments in TrustLens

To view segments in TrustLens,

  1. Go to your TrustLens program
  2. Click on “Select View” link in the top-right corner of the screen.
  3. Make your selection of organization and scope.
    TC Segments 18
  4. Your view selection will be displayed at the top of the page and results are displayed as per your selection.
  5. You can also change or clear your view using the “Clear View” and “Change View” links.

Join the conversation

You might also be interested in

Excluding a Test or Assessment (Updated UI)

Excluding a test or assessment allows you to remove certain tests or assessments from...

Hybrid Data Fabric

Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a...

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Control Attributes

Every control has many attributes that help us understand it better for mapping and...

Editing Controls

Control customization is a pillar of TrustCloud’s platform, effortless crafting of custom controls. With...

Adding Controls

TrustOps gives you the ability to add a custom control to your program, add...

Testing Controls

Once you have set up your integrations, you can leverage automated tests. Automated tests...

Self Attestations

The Self Assessments page in TrustOps provides users with a streamlined, centralized workspace to...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue