identify items (or clusters) that require attention.
During the evaluation P4 said: “I want this [Risk
Clusters visualization] in the tool I use.” The Risk
Overview features multiple Sunburst diagrams that
represent taxonomies used to organize risks. Each
node in a taxonomy summarizes the rating of the
risks associated with that taxonomy node and its
children. Furthermore, each taxonomy occurs on
three separate Sunburst charts: one that is colored by
the inherent rating (top), one by the residual rating
(middle), and one by the change magnitude between
the inherent and residual rating (bottom), which
takes into account the final mitigation position.
During the evaluation P2 emphasized: “this [Risk
Overview] is really useful.”
The visualization that participants identified as
the least useful was the Control Treemap. The
Control Treemap represents control ratings and
displays creation and maintenance dates that
highlight controls whose ratings may need to be
reviewed or controls needing to be tested. When
participants needed to interact with controls, they
used the Risk Clusters or Sankey diagram, since they
are focused on connections with other elements
(e.g., risks and taxonomies) that provide context for
the controls rendered at the display.
The successful completion of tasks, as well as
the overall task completion time, was adversely
impacted by tasks where participants had to recall
the overall GRC data structure in order to focus on a
certain perspective. Thus, a possible improvement
for the system would be to show an overview of the
GRC data structure, perhaps as the initial
visualization, which would help users choose the
appropriate perspective. This problem was identified
during tasks 6, 7 and 8, when participants P3 and P4
looked quickly at all the visualizations and were not
able to accomplish the tasks.
The main limitation of the study was the limited
number of specialists involved in the study.
However, bearing in mind that GRC is a highly
specialized and restricted domain, this study
provided useful insights, corroborating the value of
the multiple perspective approach for the visual
analytics system developed. Future works will
consider involving more specialists and a case study
involving multiple displays in a control center-like
environment.
Finally, the system addresses an existing gap
found in current GRC platforms, since it provides
reports beyond standard and risk-centric reports, and
instead leverages how GRC elements are
interrelated. We detailed the system's technologies,
the knowledge engineering and design approach, the
proposed visualizations, and the user study
performed to validate them. The user study
considered multiple data sources: eye gazes, user
impressions, observations, and audio/video
recording.
ACKNOWLEDGEMENTS
We thank all participants for taking time to
participate in this study and also for the valuable
feedback provided.
REFERENCES
BWise, 2015, http://www.bwise.com/solutions/integrated-
grc/bwise-grc-platform.
Compliance 360, 2012. http://www.compliance360.com/
D3 – Data Driven Documents. 2016. http://d3js.org.
IBM Open Pages, 2015. http://www-03.ibm.com/
software/products/en/openpages-grc-platform/
jQuery.js, 2016. http://jquery.com.
Lewis, C. and Mack, R. 1982. Learning to use a text
processing system: Evidence from “thinking aloud”
proto- cols. In Proceedings of the 1982 Conference on
Human Factors in Computing Systems (CHI '82).
ACM, New York, NY, USA, 387-392.
MetricStream Enterprise GRC, 2015. www.metricstream
.com/industries/banking/enterprise-grc-solutions.htm.
N. Y. Times. 2015. Former Petrobras Executive Held in
Brazil Corruption Probe. http://www.nytimes.com/ap
online/2015/01/14/world/americas/ap-lt-brazil-petrobr
as.html?_r=0.
OneSumX GRC, 2015. https://www.wolterskluwerfs.com/
onesumx/risk/GRC.aspx.
Pernice, K. and Nielsen, J. 2009. How to Conduct
Eyetracking Studies. NNGroup.
RequireJS – A module loader. 2016. http://requirejs.org/
RSA Archer GRC Platform, 2015. http://uk.emc.com/secu
rity/rsa-archer-governance-risk-compliance/rsa-archer-
platform.htm.
Rubin, J. 1994. Handbook of usability testing: how to
plan, design, and conduct effective tests. John Wiley
& Sons.
SAP GRC, 2015a. http://go.sap.com/solution/platform-
technology/governance-risk-compliance.html.
SAS GRC, 2015b. http://www.sas.com/en_us/ software/
risk-management/enterprise-grc.html.
Shneiderman, B. 1996. The eyes have it: A task by data
type taxonomy for information visualizations. In
Visual Languages, 1996. Proceedings, IEEE
Symposium on (pp. 336-343). IEEE.
Stasko, J. and Zhang, E. 2000. Focus+Context Display and
Navigation Techniques for Enhancing Radial, Space-
Filling Hierarchy Visualizations Proceedings of the
IEEE Symposium on Information Vizualization.
Tarantino, A. 2008. Governance, Risk, and Compliance
Handbook. John Wiley & Sons.
The Eye Tribe Eye Tracker. 2016. http://theeyetribe.com/
ICEIS 2017 - 19th International Conference on Enterprise Information Systems
52