---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Assess controls, risks, issues, and remediation tasks

# Assess controls, risks, issues, and remediation tasks {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Within the NIST RMF
application, the Assess section involves performing security control
attestations, evaluating the control effectiveness, managing associated risks and issues, and
performing remediation tasks.
Note:  
Starting with version 10.1.0, the NIST RMF Use Case Accelerator will be supported only for customers who currently use the product. New and existing customers should consider using the GRC: Continuous Authorization Monitoring application. For details, [Continuous Authorization and Monitoring](https://servicenow-prod.fluidtopics.net/s5uGqPgL9j543l_fdj99WQ "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.").  
Broadly, assessment also involves managing the controls, risks, issues, and remediation tasks that stem from the implementation of the security controls.  
Note:  
The NIST RMF application provides read-only access to the content. Update the content following the standard GRC procedures, as outlined in the Policy and Compliance Management, Risk Management, and/or Audit Management applications.  
Users can:

* review and perform control attestations currently in the system relating to NIST RMF security attestations
* view all control tests, highlighting the control and current effectiveness of each control test in place
* manage and address any risks stemming from risk statements having a content source of NIST 800-53.r4
* identify risks and perform their assessments
* view a list of issues and remediation tasks stemming from the implementation of security controls and related risks having a content source of NIST 800-53 r4
{#rmf-assess__ul_s3x_r4x_3hb}
* **[Review and perform control attestations](https://servicenow-prod.fluidtopics.net/kaHJBqsUrKf2lq6pW39BSA)**   
  Review and perform control attestations relating to NIST RMF security attestations.
* **[Review and evaluate control effectiveness](https://servicenow-prod.fluidtopics.net/jMtUZy7twERP2Mw4nulBGw)**   
  Review and evaluate the effectiveness of the controls through the execution of control tests related to NIST-800.53.r4.
* **[Manage and address risks](https://servicenow-prod.fluidtopics.net/iWtefU_RElKG~4REn60_Kg)**   
  Review and manage all risks stemming from risk statements having the content source of NIST 800-53.r4.
* **[Review and perform risk assessments](https://servicenow-prod.fluidtopics.net/HyBNMgfbi92~w~04DXB~Iw)**   
  Review and execute the risk assessments relating to NIST RMF security assessments.
* **[Manage and address issues](https://servicenow-prod.fluidtopics.net/MWFAAidFKLWadJABQmybNg)**   
  Review all issues stemming from controls and risks with NIST 800-53.r4 as the source and address them.
* **[Manage and address remediation tasks](https://servicenow-prod.fluidtopics.net/OHn0Zux7JvUfYDloPbcnTw)**   
  Review all remediation tasks stemming from controls and risks with NIST 800-53.r4 as the source and address them.
* **[Monitor the NIST RMF Assess dashboard](https://servicenow-prod.fluidtopics.net/I~zM7njXbD_ye7qU2oUbTQ)**   
  The NIST RMF assess dashboard provides insights into the overall status of the target.

