Should entities be mapped to Service Instance or Offering level
Hi, A customer I'm working with is using "legacy" GRC and the Policy & Compliance module where the application owners attest their applications (entities) against defined security controls (control objectives). CMDB is aligned with the ServiceNow CSD...