---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Tables

# NIST CSF tables {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of NIST CSF tables

The NIST CSF tables in ServiceNow's GRC application provide structured tracking and management of cybersecurity activities, controls, risks, issues, and remediation efforts aligned with the NIST Cybersecurity Framework.
These tables enable customers to perform gap analysis, monitor compliance, and manage associated risks and action plans efficiently.
Show full answer Show less  

## Key Tables and Their Purposes

* **Target \[sngrctarget\]**: Serves as a core shared entity to track attributes specific to various GRC use-case content packs. Each target uniquely references an entity to maintain data integrity.
* **NIST CSF Activity \[snirmnistcsfnistcsfactivity\]**: Tracks cybersecurity activities related to targets, facilitating gap analysis by identifying gaps, non-compliant controls, risks, issues, failed indicators, and action plans.
* **Gaps \[snirmnistcsfm2mpolicystatenistcsfact\]**: Records unimplemented control objectives as gaps, supporting reporting and detailed analysis. This is a many-to-many (m2m) table associating gaps to targets.
* **Non-compliant Control \[snirmnistcsfm2mcxontrolsnistcsfact\]**: Tracks controls that are identified as non-compliant according to NIST CSF control objectives. Also an m2m table linked to targets for reporting and drill-down.
* **Risk \[snirmnistcsfm2mrisksnistcsfactivities\]**: Captures risks associated with implemented controls, enabling detailed risk management and reporting. It links risks to targets via an m2m relationship.
* **Issue \[snirmnistcsfm2missuesnistcsfact\]**: Tracks issues related to controls and their risks, contributing to comprehensive metrics and reporting. This m2m table associates issues with targets.
* **Action Plan \[snirmnistcsfm2mremediationnistcsfact\]**: Manages remediation tasks or action plans addressing identified issues. Supports reporting and detailed tracking through m2m associations with targets.
* **Failed Indicators \[snirmnistcsfm2mindicatorsnistcsfact\]**: Tracks failed indicators linked to targets and controls or risks, useful for monitoring and reporting compliance status. This is also an m2m table.
* **Related Control Objectives \[sncompliancem2mpolicystmtpolicystmt\]**: Facilitates relationships between control objectives at the same hierarchical level, enhancing control management beyond parent-child structures.

## Practical Benefits for ServiceNow Customers

* Provides a comprehensive data model for managing NIST CSF aligned cybersecurity controls and activities.
* Enables detailed gap analysis and compliance tracking through interconnected tables.
* Supports actionable insights via tracking of non-compliance, risks, issues, and remediation tasks.
* Facilitates advanced reporting and drill-down capabilities across cybersecurity governance data.
* Improves visibility into control relationships and status to better manage cybersecurity posture.  
A few tables are impacted by the NIST CSF guidance.
{#nist-csf-tables__table_ghx_v4z_g2c__entry__2}

| Table | Purpose |
|-|-|
| Target \[sn_grc_target\] | Target is a core table of design to be shared component among the ServiceNow GRC application and GRC use-case content packs.Target is like entity in its purpose, but is used to track any attributes specific to use-case content packs. No two target records can reference the same entity at any time. |
| NIST CSF Activity \[sn_irm_nist_csf_nist_csf_activity\] | NIST CSF Activity table is used to track cybersecurity activity relevant for a target. The activity also helps in performing gap analysis that identifies the gaps, non-complaint controls, risks, issues, failed indicators and action plans for a cybersecurity activity. |
| Gaps \[sn_irm_nist_csf_m2m_policy_state_nist_csf_act\] | Gaps table in NIST CSF is used to track control objectives that aren't yet implemented as gaps. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Gaps to Targets. |
| Non-compliant Control \[sn_irm_nist_csf_m2m_cxontrols_nist_csf_act\] | Non-compliant Control table in NIST CSF is used to track controls that are identified as non-compliant. Only cybersecurity control objectives as defined by the framework core which are implemented as controls and non-compliant are tracked. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Non-compliant Controls to Targets. |
| Risk \[sn_irm_nist_csf_m2m_risks_nist_csf_activities\] | Risk table in NIST CSF is used to track risks that are associated with controls that have been implemented for cybersecurity control objectives as defined by the framework core. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Risks to Targets. |
| Issue \[sn_irm_nist_csf_m2m_issues_nist_csf_act\] | Issue table in NIST CSF is used to track issues that are associated with controls that have been implemented for cybersecurity control objectives as defined by the framework core. Issues of risks associated with these controls are also included in the metric. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Issues to Targets. |
| Action Plan \[sn_irm_nist_csf_m2m_remediation_nist_csf_act\] | Action Plan table in NIST CSF is used to track the action plans that are identified for the issues. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Action Plans (remediation tasks) to Targets. |
| Failed Indicators \[sn_irm_nist_csf_m2m_indicators_nist_csf_act\] | Failed indicators table in NIST CSF is used to track the failed indicators of the target and the control or risk. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Failed Indicators to Targets. |
| Related Control Objectives \[sn_compliance_m2m_policy_stmt_policy_stmt\] | Related Control Objectives table in NIST CSF is used to track the associations between control objectives. In base implementation, parent and child control objectives are supported, but this table introduces a concept to relate the control objectives at the same level. |
[ ]

{#nist-csf-tables__table_ghx_v4z_g2c}

