Only one control is allowed for each pair of entity and control objective

bhayanichandan
Kilo Contributor

Hi,

We have business  scenario  where multiple controls to be created for one pair of control objective & entity.

For E.g.

Control objective = "Review event logs, Intrusion Detection System reports, security incident tracking reports, and other security logs regularly". ( relates to two different citations ). 

Entity = IT ( say department )

There are two adhoc controls required against each citation for same entity & control objective however ServiceNow control form has validation of " Only one control is allowed for each pair of entity and control objective".

 

The business data have more of same scenarios blocked due to the validation.  Please assist on moving further.

 

Thanks & Regards

Chandan Bhayani

  

 

1 ACCEPTED SOLUTION

Nicklas Jepsen
Giga Guru

Hi Chandan,

 

I would suggest keeping your control objective "Review event logs, Intrusion Detection System reports, security incident tracking reports, and other security logs regularly", as a parent control objective, and then create seperate child control objectives for each of the controls you wish. You can then connect the entities to the child control objectives.

This approach uses the OOB design and should fulfill the business goals.

 

Best regards,

Nicklas Jepsen

 

 

View solution in original post

7 REPLIES 7

Hello Prashanth, I believe in Utah release it will be possible to tie multiple entities to a single 'common' control. So if you are upgrading regularly to the newest version, I would suggest that you should wait until this feature is released. 

 

Lana

Thanks @Lana3 . We just upgraded our plugin instance to v16.0.3 GRC: Policy and Compliance Management which has the ability to create Common Controls & associate reliant entities. I could see that this version is compatible with Tokyo & Utah. But, I can't find any articles where it will suggest on how to configure these Common Controls. Any support or related articles that you have share would be great.

 

Thanks,

Prash.      

Hey Prashanth, I have also installed our instance to 16.0.3, however - I havent found a way to make a standard control a Common Control yet. I am still trying to understand the logic behind it. 

Once I have figured it out I will let you know, if you could do the same we can help each other 🙂 

Keep you posted, thanks!

Lana