---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Implement security controls

# Implement security controls {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Within the NIST RMF
application, the Implement section focuses on the physical implementation
of the baseline security controls. The NIST RMF application may also include other
standard security controls, already used by the targets or its environment of
operation.
Note:  
Starting with version 10.1.0, the NIST RMF Use Case Accelerator will be supported only for customers who currently use the product. New and existing customers should consider using the GRC: Continuous Authorization Monitoring application. For details, [Continuous Authorization and Monitoring](https://servicenow-prod.fluidtopics.net/s5uGqPgL9j543l_fdj99WQ "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.").  
Users can view a list of all controls that originate from a NIST 800-53.r4 policy statement, update any implementation details, and update the controls.  
Note:  
The NIST RMF application provides read-only access to the security controls. Update these controls following the standard Policy and Compliance Management application procedures.  
An important aspect of implementing controls is testing them appropriately. Users can view a list of all control tests that were created for security controls with a policy statement source of NIST 800-53 r4.  
Note:  
The NIST RMF application provides read-only access to the security control tests. Update these tests following the standard Audit Management application procedures.
* **[Manage and implement controls](https://servicenow-prod.fluidtopics.net/ZpraLFCUC53zyxAHPRQANg)**   
  From a list of security controls stemming from NIST 800-53.r4 policy statements, review the controls and update implementation details.
* **[Manage and implement control tests](https://servicenow-prod.fluidtopics.net/amzW~BpmDHuTYibZB7T~3g)**   
  From a list of security controls stemming from NIST 800-53.r4 policy statements, review the control tests and update implementation details.

