Linking issues to multiple objects using Many-to-many table relationship
Summarize
Summary of Linking Issues to Multiple Objects Using Many-to-Many Table Relationship
This feature allows ServiceNow customers to link issues to various objects such as risks, controls, policies, and engagements using many-to-many relationship tables. This linkage is essential for determining the impact of issues across different compliance objects.
Show less
Key Features
- Ability to link issues to multiple objects through corresponding many-to-many (m2m) records stored in specific m2m tables.
- Visibility and consolidation of all related issues for impact analysis, reducing duplicated efforts.
- Role-based access management allows specific roles to create and delete records in m2m tables, with updates requiring GRC admin privileges.
- Various m2m tables include:
- sngrcm2missueitem – Issue to control
- sngrcm2missuecontent – Issue to control objective
- sngrcm2missueengagement – Issue to engagements
- sngrcm2missuedocument – Issue to policy and authority document
Key Outcomes
By utilizing these features, customers can effectively manage issue impact analysis, streamline compliance processes, and achieve a comprehensive overview of compliance objects linked to issues, facilitating better decision-making and compliance management.
Issues can be linked to different types of objects such as risk, entity, control, control objective, engagement, policy, authority document, and others to determine issue impact. Use the many-to-many relationship tables for each of the objects to link similar issues to an object.
For example, issues are configured as a related list in the Controls form and you can link the issue to the control parent object. When you add an issue to a control, a record is created associating the item that is the control with the issue, in the Issue to Control [sn_grc_m2m_issue_item] table.
- visibility of viewing, and consolidating all related issues raised on the control
- determining the impact analysis of all related issues
- reducing the effort in working on duplicate issues and manage issue impact analysis
A user with sn_compliance_ws.corporate_compliance_analyst, sn_compliance_ws.corporate_compliance_manager, sn_compliance_ws.it_compliance_manager, or sn_compliance.admin roles can create and delete the records in the many-to-many tables. However, users with these roles cannot update an existing record in the m2m tables. To update a record, you require GRC admin (sn_grc.admin) role.
- sn_grc_m2m_issue_item – Issue to control
- sn_grc_m2m_issue_content – Issue to control objective
- sn_grc_m2m_issue_engagement – Issue to Engagements
- sn_grc_m2m_issue_document – Issue to Policy and Issue to Authority document
- Tables installed for descriptions of the m2m tables.
- Create GRC issues for the different compliance objects that are linked to the issue.
- Create a control using the Compliance Workspace to link issues to a control.
- Linking automatically generated issues to a control in Many-to-many relationship to know how multiple issues linked to a control are categorized as automatically generated or manually created.
- Create an authority document using the Compliance Workspace to link issues to an authority document.
- Create a control objective using the Compliance Workspace to link issues to a control objective.
- Create an audit engagement in Audit Workspace to link issues to an engagement.
- Create a policy using the Compliance Workspace to link issues to a policy.
- 360° view of compliance objects and issues for a comprehensive and detailed overview of all object data that the issue is linked to in a many-to-many relationship.