Join the #BuildWithBuildAgent Challenge! Get recognized, earn exclusive swag, and inspire the ServiceNow Community with what you can build using Build Agent.  Join the Challenge.

GRC indicators

Syed14
Mega Guru

Hi.

I want to know about the Indicators and indicators templates inside Governance, Risk and Compliance (GRC). I know from the documentation that Indicators monitor a single control or risk and Indicator templates allow the creation of multiple indicators for similar controls or risks. 

 

What I want to know how we can effectively used the indicators in GRC ? and why the indicators are used.

 

Thanks

1 ACCEPTED SOLUTION

Shiva Thomas
Kilo Sage

Hi Syed,

Indicators can be automated (= Scripted result) or manual (= Task assigned to someone, ending with a state of Passed or Failed). 

Examples of automated indicators would be check that all Servers in the CMDB are up to date, or that all LDAP passwords are less than 3 months old.
One example of manual indicator would be to ask the network admin that annual Network Penetration Test were conducted and the results attached to the task.

Indicator Results are used to trigger the creation of GRC Issues (Task to determine if some remediation is required), if a result indicates Failed or Not Passed. Assessment also can be used to achieve the same usage, but in the form of a questionnaire.
Indicator Templates can be linked to Policy Statements, or to Risk Statements, to automatically create Indicator for your Controls, or Risks.

Controls' status is also automatically calculated by the linked Indicator Results... And that may affect any linked Risks.
Risk's Calculated Risk Score is adjusted automatically by the Risk's Indicators results. There is a Indicator Failure Factor field in the Risk table that display the impact of those.

Please note that Indicators are not weighted. So, when looking at their impact on a Control or Risk they will all be considered equally. Indicators are not executed when Risks and Controls are in Retired state.

I hope this help!

Best regards from Switzerland
Shiva, ServiceNow Architect and GRC Expert :¬,

If this reply assisted you, please consider marking it 👍Helpful or Correct.
This enables other customers to learn from your thread.

View solution in original post

5 REPLIES 5

Marriam
Tera Contributor

Hi Paula-did you find the answers to those concerns? The way OOB is setup, the Control or System Owner issues the PASS/FAIL--I'm trying to change that so the SCA makes that determination. 

Q2- Indicator task remains open until the SO closes it.