The NDA obligation stays open
Ticking the "NDA required" box gets nothing done. Until a signature is recorded, the project keeps flagging the party as open. Why that is the whole point, and why a rejected security approval is worth more than an empty field.
An external service provider joins the project. Someone adds them as an involved party and ticks the NDA required box. The tick feels like something got done. It did not.
In the project registry the party stays flagged as open until a signature is recorded. Not as done with a note, not as in progress. Open. The tick records that an NDA is needed, and precisely thereby creates the visible gap nobody would have noticed otherwise.
The difference between agreed and signed
In practice a quarter of a year often sits between the two. The NDA was discussed at kickoff, legal sent a draft, and after that the project simply carried on. If somebody asks six months later, the hunt through mailboxes begins.
The point is not that software could force anyone to sign. It can only make sure the gap stays visible where it arose, instead of disappearing into a contract archive nobody looks at while the project runs.
Protection requirements come first, not last
Security considerations arrive late in most projects, usually shortly before go-live, when the decisions are long since made. The registry reverses the order: the project carries a protection requirement, and that determines whether a risk assessment and a security approval are needed at all.
Both are documented with status, date and approving person. The risk assessment moves through pending, completed and approved. The security approval knows four states, and the most interesting of them is rejected.
Most systems know only approved or not approved, which in practice can mean anything: never requested, forgotten, refused. An explicitly rejected approval, by contrast, is a documented decision with a date and a name. Anyone overruling it later does so visibly.
Alongside sits not required as a state of its own. A project that needs no approval is not the same as a project whose approval is missing, and the distinction is lost the moment both appear as an empty field.
What else hangs off a project
Measures carry status and due date, with open and overdue ones shown separately. You can link IT systems, software, networks, processes, information, rooms, sites, people, service providers and risk analyses. A field marks projects that touch personal data.
Assets are referenced, not copied. An IT system stays centrally maintained and can sit in several projects at once. Changes to the master record take effect everywhere it is linked.
The rest is unremarkable: a project number in the format PRJ-NNNNN, assigned sequentially. Type internal or external, which drives the cockpit view. External projects more often involve outside parties, which brings us back to the NDAs.
More on the project registry module page.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.