When to use which audit type?

prussrobin
Tera Contributor

Hi all,

I'm exploring the possibilities of the Compliance module. When creating Certification templates we have the 3 options for audit-types: Desired State, Architecture Compliance and (regular) compliance.

I've read the wiki and the docs but can't figure out what the difference is between these 3 types and for which purpose I should use the specific audit types

Thank you in advance!

1 ACCEPTED SOLUTION

Alec Hanson
Tera Guru

FYI the updated definitions are held here: CMDB Compliance (servicenow.com)

View solution in original post

4 REPLIES 4

gwolfkill
Tera Contributor

Did you ever figure this out? I'm facing the same question. I'm not finding very good examples of these along with examples of the usages of Health Window, Threshold Count and Stability Count values.

I was thinking I would schedule a Compliance Audit to run daily to check for Disabled Users in the Supported By field, but it replicates the Follow On task each time it runs. I can't figure out if I need a different type, or I need to modify those three numbers some how to prevent that.

We never got a concrete answer but the info we've gathered is:

- Compliance is the default and has the basic functionality

- Desired state is for cmdb_ci extended tables and adds some extra functionality like checking for relationships

- Architectural compliance is the only one where I don't know when to use. This option is limited to cmdb_ci extended tables but seems to have the same functonality as compliance.

However, we ultimately didn't implement the compliance module so I don't have any experience in how the types relate to the created tasks.

Saurabh singh4
Kilo Guru

Hi prussrobin,

please check these three link this will give you clarity about all three audit types

Desired state

https://docs.servicenow.com/bundle/orlando-servicenow-platform/page/product/compliance/reference/r_D...

Architecture Compliance

https://docs.servicenow.com/bundle/orlando-servicenow-platform/page/product/compliance/concept/c_Arc...

(regular) compliance

https://docs.servicenow.com/bundle/orlando-governance-risk-compliance/page/product/grc-common/refere...

 

Please mark my answer correct and helpful, if it helps you in any way

Saurabh

Alec Hanson
Tera Guru

FYI the updated definitions are held here: CMDB Compliance (servicenow.com)