Request control tailoring
Summarize
Summary of Request control tailoring
Request control tailoring enables ServiceNow customers to modify baseline controls within an authorization package after the Select step without reverting to earlier workflow stages. This capability avoids resetting and reworking all controls by allowing incremental, targeted changes only to affected controls.
Show less
This feature supports several control types including Baseline, Inherited, Hybrid, Fully Inherited, Not Applicable, Overlay, and helps maintain unaffected controls in their current state while applying updates.
Key Features
- Supported Users: CAM administrators, system owners, ISSOs, and ISSMs can create control tailoring requests for packages in the Implement step or later.
- Request Interface: Displays two panels—Current Records (existing configuration) and Requested Records (proposed changes)—to assist in comparing and building modifications.
- Incremental Changes: Allows adding new controls or updating existing controls without impacting unchanged controls, preserving their states.
- Approval Workflow: Requests are routed to the Authorizing Official (AO) who reviews only the delta changes, can approve, request more info, or reassign the request. Notifications are sent via email.
- Control State Transitions: Supports creating controls in Draft state, retiring controls, updating allocation types, modifying hybrid configurations, and applying overlay behaviors upon approval.
- Package Status: While approval is pending, changes are not applied. Only one new control tailoring request per package is allowed at a time to maintain process integrity.
Key Outcomes
- Enables efficient, controlled modifications to baseline controls without undoing prior implementation progress.
- Supports governance by routing changes through a defined approval process ensuring oversight.
- Records all tailoring activities in package work notes for audit and traceability.
- Ensures only affected controls transition states, minimizing disruption and retesting effort.
- Maintains authorization package integrity and accelerates response to changing control requirements.
Control tailoring requests enable you to modify baseline controls for an authorization package after the Select step without reverting the package to earlier workflow steps.
Without control tailoring requests, modifying baseline controls after the Select step requires moving the package back to Select, which resets controls and requires reimplementing and retesting all controls even when changes affect only a small subset. Control tailoring requests allow incremental modifications by applying only delta changes to the package.
Control tailoring requests let you add new controls or update existing control configurations while maintaining unaffected controls in their current state.
The following control types are supported:
- Baseline
- Inherited
- Hybrid
- Fully inherited
- Not applicable
- Overlay
CAM administrators, system owners, Information System Security Officers (ISSOs), and Information System Security Managers (ISSMs) can create control tailoring requests for packages in Implement step or later. The request interface displays two panels: Current Records (left) showing existing package configuration and Requested Records (right) showing proposed modifications. Review current allocations as reference while building requested changes.
Approval workflow
After you submit a control tailoring request for approval, the system assigns it to the Authorizing Official (AO) configured for the authorization package. The AO receives an email notification. The AO reviews only the delta changes in the Requested Changes tab and can approve, request more information, or reassign to a different AO. If more information is needed, the request returns to the submitter for modifications before resubmission.
After approval, changes are applied to the requested controls. Only modified controls transition to new states while unchanged controls retain their current state. All control tailoring activities are recorded in the authorization package work notes.
Control state transitions
The control tailoring process manages several types of control changes:
When you add a baseline control to the package, the system creates the corresponding control in Draft state. When you change a baseline control from Not Applicable to Applicable, the system creates the control. When you change a baseline control from Applicable to Not Applicable, the system retires the existing control.
When you change a hybrid control to inherited or fully inherited, the system updates the existing control with the new allocation type. When you update the hybrid configuration for an existing hybrid control, the system updates the control requirements to reflect the new configuration.
When an overlay control modification in a control tailoring request is approved, the system applies the overlay's configured behavior and actions to the authorization package.
Package status during approval
While a control tailoring request is pending approval, the proposed changes don't take effect until the AO approves the request. After approval, the system applies the changes to baseline controls and updates related controls accordingly. Only one control tailoring request in New state is allowed per package at a time.