Built something you're proud of? Tell the story. A quick G2 review of App Engine or Build Agent helps other developers see what's possible on ServiceNow. Share your experience.

Custom control objective impacts other control objective status?

pverni
Tera Contributor

Hello community,

 

Recently I import all cyber control objectives of my companie into servicenow, and I notice that servicenow already have many control objectives from frameworks.

 

I would like to know if there is a way OOTB to attest my cyber controls and with this results impact the compliance status of control objectives from frameworks.

 

For exempla, my cyber control CA02 have a relationship with SOX-AP-11. It is possible to attest my CA02 and the result raise awareness in the SOX Police?

 

The principal outcome here, is attest company controls and saw the frameworks/polices level of compliance.

 

Thanks!

1 REPLY 1

Marek Remi_
Tera Expert

Hello,

From what you describe, it looks like you have a duplication of control objectives. You can either choose to work with just one of them, or if you want to achieve what you described, you can leverage a parent–child relationship between control objectives.

For example:

SOX-AP-11 would be the parent control objective linked to the citation.
CA02 would be the child control objective, with SOX-AP-11 as its parent.

The key idea is to use SOX-AP-11 as a container for the overall compliance score, while CA02 is the control objective you actually associate with entities or entity types and attest.

This way, attestation results on CA02 can roll up and impact the compliance status of the parent SOX-AP-11.

However, even if this is technically achievable, I would not recommend this approach as the first option. In GRC, multiple related records can be created from or linked to control objectives, such as issues, risks, attestations, test results, and other related records.

If you represent the same control objective in two different records, you may end up with related information stored only on some of them. Over time, this can make reporting, traceability, and maintenance more complicated.

A cleaner approach is usually to maintain one operational control objective, such as CA02, and map it directly to the relevant citations or policies. This supports the “test once, comply with many” approach and avoids unnecessary duplication.

Please hit Like and mark as Helpful if this helped you.

Regards,
Marek