Tracking Regulatory Compliance (SOX, PCI, PII etc.) in CMDB/CSDM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yesterday - last edited yesterday
Hi,
I am looking for architectural recommendations on the best way to track and enforce regulatory compliance (such as FRA, SOX, SWIFT, and PCI) within our CMDB and ITSM processes. We want to ensure our approach aligns with the latest CSDM best practices.
Our business requirement is to track which app or service or infra CI falls under regulatory compliance and if yes then alert user and compliance team.
My specific questions:
- Data Model: Within the CSDM framework, where is the ServiceNow recommended location to store these regulatory flags? Should this be handled via a custom attribute on the Application Service/Business Application classes, or should we be leveraging Information Objects?
- Data Inheritance: What is the best practice for associating this compliance risk with downstream infrastructure CIs? We want to avoid hardcoding compliance data directly onto every hardware CI to prevent data maintenance overhead.
- ITSM: What is the most efficient, out-of-the-box method to surface this regulatory impact on the Change and Incident forms (e.g., leveraging the 'Impacted Services' related list or Risk Assessment conditions) without causing performance issues querying the CI relationship tree?
- Without IRM/GRC: If we do not currently license the Integrated Risk Management (IRM) module, what is your recommended tactical approach using core ITSM and CMDB capabilities?
With IRM/GRC: If we are entitled to use Integrated Risk Management (IRM) module, what is your recommended tactical approach?
I appreciate your guidance and architectural recommendations on the best path forward.