Why we have control objective in citation

Priya Shetty
Kilo Contributor

Why we have control objective in citation. can anyone give me an example and explain

1 ACCEPTED SOLUTION

Scott Ferguson
ServiceNow Employee
ServiceNow Employee

Simply, the authority document is the parent (header) type record that describes the document itself, the citations are the paragraphs or bullets that make up the authority document, the control objectives are the specific details on what needs to be done.  

For example, auth doc is NIST 800-53 cyber security framework, citation is you should have a strong password, control objective is configure the password policy to use mixed cases and 2fa. 

The other benefit is that the control objectives can be harmonized across multiple citations and multiple regulations; giving you the ability to test a single control and show compliance to multiple regulations.  This is what we do with the UCF integration. 

View solution in original post

4 REPLIES 4

jing3
Mega Guru

This discussion should get you in the right direction. 

Understanding the relationship between policies, statements and citations

Priya Shetty
Kilo Contributor

Hi Jing,

Thank u for the reply but I am unable to open that link

Scott Ferguson
ServiceNow Employee
ServiceNow Employee

Simply, the authority document is the parent (header) type record that describes the document itself, the citations are the paragraphs or bullets that make up the authority document, the control objectives are the specific details on what needs to be done.  

For example, auth doc is NIST 800-53 cyber security framework, citation is you should have a strong password, control objective is configure the password policy to use mixed cases and 2fa. 

The other benefit is that the control objectives can be harmonized across multiple citations and multiple regulations; giving you the ability to test a single control and show compliance to multiple regulations.  This is what we do with the UCF integration.