- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-04-2023 08:44 AM
Hello,
My internal GRC Audit team needs to perform semi-annual audits and we need a way to make these requests recurring or to re-initiate the request. Here are some details on our use case:
- Need to collect user access lists for each application
- users provide an attachment to our audit team
- request sent to approximately 200 or so applications/IT owners
- Process needs to be able to be reproduced every 6 months to the same applications/IT owners
Is there a way to automate this process within the system?
Solved! Go to Solution.
- 1,963 Views
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-25-2023 09:03 PM
@brandoncalero the use case you have described is what control indicators have been designed for.
The process for creating them is:
- Create a single control objective (make sure "Creates control automatically" is true)
- (Optional) Create an entity type for all applicable applications with an entity filter pointed to the Business application table to automatically create controls for the applicable applications
- Create an indicator template off of the Control objective. This indicator template can be manual to start off with and provide some guidance to the user of what they need to do and what you expect them to upload
- (Optional) Create a test template for the control objective and click generate test plans. This will create a copy of the test template as a test plan for each control
This is a once off activity and then will then run throughout the year and send tasks to users to upload data.
When it is time to test you can do the following:
- Create an engagement
- Bring the applications in scope
- (Optional) you can configure control tests to not require test plans by removing the mandatory flag. This will allow users to create control tests directly.
- Create the control tests either from the test plans or manually create individual control tests. This can be done in bulk. You can also config this list to allow you to select all test plans if you want to make this even faster
Once you create a control test it will automatically bring in the manual indicators or the uploaded evidence in the control test for the audit user to review (see below screenshot example of an indicator result on a control test)
Once you do this once you can copy the engagement following the below guide and it can copy all the set up for you each time so you dont have to repeat these steps
I hope this is helpful, if you still have questions I would suggest to reach out to your ServiceNow account team and they could connect you with your local Risk Specialist to help you through the process.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-25-2023 09:03 PM
@brandoncalero the use case you have described is what control indicators have been designed for.
The process for creating them is:
- Create a single control objective (make sure "Creates control automatically" is true)
- (Optional) Create an entity type for all applicable applications with an entity filter pointed to the Business application table to automatically create controls for the applicable applications
- Create an indicator template off of the Control objective. This indicator template can be manual to start off with and provide some guidance to the user of what they need to do and what you expect them to upload
- (Optional) Create a test template for the control objective and click generate test plans. This will create a copy of the test template as a test plan for each control
This is a once off activity and then will then run throughout the year and send tasks to users to upload data.
When it is time to test you can do the following:
- Create an engagement
- Bring the applications in scope
- (Optional) you can configure control tests to not require test plans by removing the mandatory flag. This will allow users to create control tests directly.
- Create the control tests either from the test plans or manually create individual control tests. This can be done in bulk. You can also config this list to allow you to select all test plans if you want to make this even faster
Once you create a control test it will automatically bring in the manual indicators or the uploaded evidence in the control test for the audit user to review (see below screenshot example of an indicator result on a control test)
Once you do this once you can copy the engagement following the below guide and it can copy all the set up for you each time so you dont have to repeat these steps
I hope this is helpful, if you still have questions I would suggest to reach out to your ServiceNow account team and they could connect you with your local Risk Specialist to help you through the process.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-26-2023 06:20 AM
Thank you Connor.
I appreciate you going through this and I will definitely be using this in the future.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-26-2023 05:19 PM
No problem Brandon!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-01-2024 01:54 PM
Hello @brandoncalero Did you find a Solution? I have a similar use case. I am searching for a Solution where the Evidence/ Document can be dumped by the application/ control owners.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-20-2023 06:02 AM
@brandoncalero, I recommend that you use the Control (CTRL) + Indicator Template to automatically generate the Indicators (IND) that will then create the Indicator Tasks (IDT). You will only need to set this up once and then the system will automatically generate the indicator tasks at the frequency you have set. I use this process to generate tasks for the IT Managers (Control Owners) to upload the evidence for about 500+ tasks a month. I found the audit evidence process to be too cumbersome and had way too many clicks as well.