New to Risk and Compliance? Start Here Before Learning ServiceNow IRM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
an hour ago
If you're learning ServiceNow IRM but don't come from a traditional Risk or GRC background, the terminology can feel like a lot at first. Risk statements, controls, control objectives, assessments, issues, and remediation can start to blend together. Before trying to memorize what, these records do, start with the business problem. Understanding the “why” makes the platform much easier to understand.
At a basic level, think about GRC in three areas.
- Governance is how an organization establishes policies, responsibilities, and oversight.
- Risk is how an organization identifies and manages uncertainty that could impact its objectives.
- Compliance is how an organization makes sure it's meeting policies, laws, regulations, standards, and other requirements.
You don't have to work in Risk or Compliance to have experienced GRC. Think about annual training, acknowledging a policy, having your system access reviewed, providing evidence for an audit, or completing a corrective action. Most of us have participated in some of these activities without thinking of them as GRC. These familiar experiences are a good place to start.
Now connect that to ServiceNow IRM. A policy sets expectations, controls help manage whether those expectations are being met, and assessments help determine whether those controls are working. When something isn't working, an issue may need to be addressed. Instead of memorizing each record, ask: Why would the business need this?
Put it into practice
Pick a business process you already understand and follow it through ServiceNow. Mandatory annual training is an easy example. Think about why it's required, how completion is tracked, what evidence is needed, and what happens when someone doesn't complete it. Then look at how those concepts are represented in IRM and how the records connect.
A few resources to get started
ServiceNow — What is GRC?
https://www.servicenow.com/products/governance-risk-and-compliance/what-is-grc.html
OCEG — What is GRC?
https://www.oceg.org/ideas/what-is-grc/
NIST — Risk Management Framework
https://csrc.nist.gov/projects/risk-management/about-rmf
Learn the business problem first. Then learn how ServiceNow IRM helps manage it. If you're new to IRM, you may be newer to the terminology than you are to the concepts.
