<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Risk Assessment Questionnaire in GRC forum</title>
    <link>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/1323934#M9578</link>
    <description>&lt;P&gt;Hi David&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you say "... the risks they are raising" it makes me want to verify if your team is&amp;nbsp;raising risks or issues. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;A simple difference is issues are current (something that is happening now, like Log4Shell, etc.) while Risks are more forward-looking (i.e. Risk of Unauthorized access) - Risks Statements are generally defined&amp;nbsp;at an enterprise level while Issues are created by end-users. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm hoping it's not the case, but we sadly often see teams struggle with that difference which then impacts implementing other aspects of GRC and the complexity just increases from there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Quick answer is your actual questions would be to create your assessments using the Risk Assessment Designer. &amp;nbsp;&amp;nbsp;https://docs.servicenow.com/bundle/sandiego-governance-risk-compliance/page/product/grc-risk/task/create-assessment-using-assessment-designer.html&lt;/P&gt;
&lt;P&gt;However, you may want to reach out to an implementation partner to verify if your roadmap of implementing Risk, Controls (with Issues) and Entities is sustainable.&lt;/P&gt;
&lt;P&gt;Hoping you find that helpful.&lt;/P&gt;
&lt;P&gt;Roy &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 18:48:07 GMT</pubDate>
    <dc:creator>Roy Verrips</dc:creator>
    <dc:date>2022-05-31T18:48:07Z</dc:date>
    <item>
      <title>Risk Assessment Questionnaire</title>
      <link>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/1323933#M9577</link>
      <description>&lt;P&gt;We are partly into configuring our GRC instance and I will be completely honest, not 100% up to speed at the moment. But we currently use a risk questionnaire to help us understand the risk that they are raising.&lt;/P&gt;
&lt;P&gt;Are there any good guides or videos on a step by step?&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:06:19 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/1323933#M9577</guid>
      <dc:creator>David347</dc:creator>
      <dc:date>2022-05-31T15:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment Questionnaire</title>
      <link>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/1323934#M9578</link>
      <description>&lt;P&gt;Hi David&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you say "... the risks they are raising" it makes me want to verify if your team is&amp;nbsp;raising risks or issues. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;A simple difference is issues are current (something that is happening now, like Log4Shell, etc.) while Risks are more forward-looking (i.e. Risk of Unauthorized access) - Risks Statements are generally defined&amp;nbsp;at an enterprise level while Issues are created by end-users. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm hoping it's not the case, but we sadly often see teams struggle with that difference which then impacts implementing other aspects of GRC and the complexity just increases from there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Quick answer is your actual questions would be to create your assessments using the Risk Assessment Designer. &amp;nbsp;&amp;nbsp;https://docs.servicenow.com/bundle/sandiego-governance-risk-compliance/page/product/grc-risk/task/create-assessment-using-assessment-designer.html&lt;/P&gt;
&lt;P&gt;However, you may want to reach out to an implementation partner to verify if your roadmap of implementing Risk, Controls (with Issues) and Entities is sustainable.&lt;/P&gt;
&lt;P&gt;Hoping you find that helpful.&lt;/P&gt;
&lt;P&gt;Roy &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 18:48:07 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/1323934#M9578</guid>
      <dc:creator>Roy Verrips</dc:creator>
      <dc:date>2022-05-31T18:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment Questionnaire</title>
      <link>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/1323935#M9579</link>
      <description>&lt;P&gt;Thanks, that is helpful.&lt;/P&gt;
&lt;P&gt;It is the former. The users will be people like Project Managers or Service owners who are looking to make changes in their environment, so we need a certain amount of information to make these assessments.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is that what you would use these questionnaires/Assessments for?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 08:07:26 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/1323935#M9579</guid>
      <dc:creator>David347</dc:creator>
      <dc:date>2022-06-01T08:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment Questionnaire</title>
      <link>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/2544583#M14583</link>
      <description>&lt;P&gt;I understand how to use these but how are they triggered? When a new risk is identified, I want the questionnaire going out to them.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 15:24:52 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/risk-assessment-questionnaire/m-p/2544583#M14583</guid>
      <dc:creator>David347</dc:creator>
      <dc:date>2023-04-25T15:24:52Z</dc:date>
    </item>
  </channel>
</rss>

