Control Attestation vs Continuous Controls Monitoring

KrithikaV
Tera Expert

Hi,

From the ServiceNow documentation, I see that control attestation is to just confirm that the control is in place.

However, it seems to me at times that  control attestations are made to  perform the same functionality of continuous controls monitoring.

 

Let us take an example: 
Control: Access Reviews are performed quarterly
Here, what would be the control attestation ?
1. Attest that there is a control (procedure) to perform access reviews every quarter or 
2. The  manager confirming that access review is complete for the specified quarter (as explained in the post: https://www.servicenow.com/community/grc-forum/how-attestation-and-indicators-are-different/m-p/3365...

Thanks,
Krithika