How Should IRM Model Shared Control Effectiveness?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
an hour ago
What is the most defensible architecture in ServiceNow IRM when a single enterprise control is intended to mitigate multiple risks across multiple entities, but the control's actual effectiveness is materially different depending on the entity, process, technology, or risk context?
Duplicating the control can destroy the concept of a common control and create maintenance problems. Reusing one control everywhere can create the opposite problem by imploying that one effectiveness result accurately represents every implementation context.
How should control objectives, controls, entities, risk relationships, assessments, test results, issues, and residual risk be structured so that control reuse is preserved while effectiveness remains context-specific and auditable?
Where is the architectural boundary between appropriate OOTB configuration and customization that creates long-term IRM governance debt?
