Manage controls using the Compliance Workspace
Summarize
Summary of Manage controls using the Compliance Workspace
The Compliance Workspace in ServiceNow enables organizations to effectively manage and streamline their controls, which are specific implementations of control objectives. This functionality is crucial as it helps organizations adapt their controls to evolving business needs while ensuring compliance with various regulatory frameworks.
Show less
Key Features
- Control Rationalization: Before defining controls, it is important to assess their relevance and effectiveness in mitigating risks. Organizations are encouraged to refine their control set rather than upload all controls in bulk.
- Entity Association: Each control must be associated with an entity. Missing entities can lead to unreliable results in calculations, so it is essential to review and correct any controls lacking this association.
- Control Consolidation: Look for opportunities to consolidate redundant controls across different regulations to create a unified control framework, which is critical for audits.
- Control Requirements: When enabled, control requirements are automatically generated alongside controls for each entity type, ensuring comprehensive oversight.
- Attestation at Control Requirement Level: Admins can enable attestation for individual control requirements, allowing for more detailed compliance tracking and management.
- Entity Based Access (EBA): This feature provides a granular approach to managing data access, allowing administrators to control user permissions based on entity associations.
Key Outcomes
By utilizing the Compliance Workspace effectively, organizations can expect to improve their risk management processes, ensure compliance with regulatory requirements, and enhance overall IT performance. The ability to consolidate controls and manage access based on entity associations enables more efficient audits and compliance assessments. Additionally, the attestation features help maintain accountability and transparency in control implementation.
Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.
Rationalize your controls
- How does this control affect my business objective?
- Is this control actually preventing or detecting risk?
- Is there a different control you can place that better protects your business?
- Is there a control you can put in place that reduces process overhead and improves IT performance while also mitigating risk?
- Can a complicated control be replaced with a simpler more effective control?
Consolidate your controls
Define controls and business rules
- Identify controls and control owners
- Define control tests and expected results
- Establish test and control frequencies
- Identify risks: impact and likelihood
- Prepare attestations, assessments, questionnaires, and required evidence
- Compose likely use-cases (who needs to interact with or view the contents of the GRC system and for what purposes)
- Map authoritative sources to policies, to procedures, to controls, and to risks
Control requirements
When Create control requirements option is enabled for a control objective, for every control generated under an entity type, control requirements are also created automatically. Previously, only controls were created for entity types. The number of Control Requirements equals the number of control objective requirements.
Attestation at control requirement level
The Attestation at control requirement level feature allows attestation at a granular level for individual control requirements within a control. Admins can enable requirement-level attestation, assign respondents, and generate assessment tasks for each control requirement. Respondents then attest to requirements by indicating whether they are implemented or not, providing evidence or explanations as required. Failed attestations automatically generate issues, mark the parent control as non-compliant, and roll up the status to the associated entity and control objective.
Entity Based Access (EBA)
- Control
- Attestation
- Policy exception to control
Entity Based Access (EBA) rules
When entity based record access rules are enabled on the Entity Based Access Configuration Properties page, any newly created controls, control attestations, indicators, and indicator tasks associated with a configured entity will automatically inherit the entity-based access (EBA) value from that entity. Previously, users had to run bulk access updates to apply EBA restrictions whenever new objects were created.