UCF Implementation Common Controls

tw1920
Tera Contributor

Is there a way to bring the "Implementation" UCF Common Controls into IRM along with the "Mandated" and "Implied" common controls?

5 REPLIES 5

SANDEEP DUTTA
Tera Patron
Tera Patron

Hi @tw1920 ,

From UCF you bring  GRC authority documents, citations, controls, and control objectives as Shared List.

 

To support multiple shared list, the system property sn_comp_ucf.deactivate_deprecated_docs that is by default true, must be set to false.
  • If the system property is set to true, then the existing validation is done to check if the authority documents imported are already imported in the ServiceNow instance.
  • If the system property is set to false, then the imported authority documents are not validated at all.

Set the property as false and import the UCF content in multiple shared list. If the authority documents, citations, and control objectives that are imported in the shared list are deprecated, then such documents will not be deactivated in the ServiceNow instance. Instead, the user must manually validate the documents and the links between the citation and control objectives. An email is sent with the links to the mapping between the citation and control objectives.

 

Thanks,
Sandeep Dutta

Please mark the answer correct & Helpful, if i could help you.

tw1920
Tera Contributor

@SANDEEP DUTTA you didn't mention the difference between the difference between the implementation, implied, and mandated controls from the UCF. How can we bring in the implementation controls from the UCF baseline?

Hi @tw1920 ,

ServiceNow imports all controls including what UCF describes as implied common controls in addition to the mandated common controls.

And if you want to make any changes as per your organization, then turn off the "All the fields from UCF should be read-only" UI Policy.

Now, How you want to map it from UCF to ServiceNow, you can read this doc : Konfigurieren Sie die UCF-Integration mithilfe des UCF Common Controls Hub

 

Thanks,
Sandeep Dutta

Please mark the answer correct & Helpful, if i could help you.

@SANDEEP DUTTA will turning off that setting allow our organization to import the "Implementation" common controls, which differ from the "Implied" and "Mandated" controls?