- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-02-2019 09:46 AM
Hi Kim,
I teach the Risk and Compliance Implementation course and Profiles are an entire chapter/module in that course. We talk about different ways that you might approach setting up Profile Types. How should you define them. Here are some of the questions/thoughts we discuss:
- Profile Types are comprised of Profiles. Each Profile has a Profile Owner. That Profile Owners will become the Control Owner or the Risk Owner when a Profile Type is applies to a Policy Statement (for Control generation) or a Risk Statement (for Registered Risks).
- Understanding how Profiles are used in the GRC application leads you to how to set them up.
- I suggest asking the customer - who should be the risk owners or control owners? The answers may be specific people or you may get an answer like "all the application owners". Whatever the answer is, use that information to figure out how to build the Profile Type.
- Another method is to ask - how do you manage controls and risks in your current environment? Again, looking for who is doing what and then translating that information into a ServiceNow table.
- I have also heard someone suggest that you ask "how do you scope an audit?" "Who do you determine what to include in an audit?" Ex: All the critical SAP Applications or all the critical financial applications, etc. Remembering that in ServiceNow, the way we build an Audit engagement is to identify individual profiles (not Profile Types).
Depending on the maturity of a customer's CMDB you may have to create a new table to use to build profiles. But it is better if you can pull from an existing table - one that is already being maintained because of another non-GRC process.
And don't forget that when building the filter for a Profile Type you can pull from multiple tables. The filters (I think this started in Kingston) are now held in a m2m table. So, I could pull data from the Location table AND the Department table if I needed both to complete a Profile Type.
And don't forget - you can Profile Types like these - where a profile is in more than one Profile Type.
- All locations
- All warehouse locations
- All distribution locations
- All applications
- All critical applications
- All financial applications
- All servers
- All PCI servers
One other thing to consider is primarily doing this for Policy Compliance - look at the Authority Doc (COBIT, SOX, etc) and try and figure out who within an organization they want to be addressing compliance with their requirements.
Hope this helps.