Integrate with UCF Common Controls Hub to manage compliance frameworks
Summarize
Summary of Integrate with UCF Common Controls Hub to manage compliance frameworks
ServiceNow enables compliance administrators to integrate with the Unified Compliance Framework (UCF) Common Controls Hub (CCH) to manage compliance frameworks effectively. This integration allows downloading and importing UCF content—such as authority documents, citations, controls, and control objectives—into the ServiceNow GRC (Governance, Risk, and Compliance) system. The imported data is periodically updated to ensure compliance accuracy.
Show less
To use this capability, organizations must have a UCF CCH subscription, which is available for purchase via the ServiceNow Store or directly from Unified Compliance. The prior free access arrangement ended in 2018. All imported UCF data is read-only within ServiceNow to maintain data integrity and must not be customized.
Integration Setup and Usage
- Create and customize a UCF CCH account with API access enabled.
- Activate Compliance UCF within ServiceNow.
- Submit a Now Support Case to initiate UCF-CCH account integration.
- Configure the integration using the UCF Common Controls Hub interface.
- Download and import UCF shared lists into the ServiceNow instance.
Importing authority documents requires that all previously imported documents exist within any shared list used for import, preventing inconsistencies between UCF CCH and ServiceNow data.
Handling Multiple Shared Lists and Limitations
Since a single shared list can contain a maximum of 100 authority documents, importing more than 100 requires multiple shared lists. It is recommended to group similar authority documents logically to avoid interdependencies across lists.
To support multiple shared lists, the system property sncompucf.deactivatedeprecateddocs must be set to false. This setting disables validation checks on duplicates during import but requires manual validation of deprecated documents and their citation-to-control objective mappings. An email notification facilitates this review process.
Terminology Alignment
UCF and ServiceNow GRC use slightly different terminology for compliance elements. Key mappings include:
- Authority Document (UCF) = Authority Document (GRC)
- Citation (UCF) = Citation (GRC)
- Control (UCF) = Control Objective (GRC)
Best Practices and Considerations
- Ensure all authority documents and shared lists are kept up to date to maintain synchronization with UCF content.
- Do not customize imported UCF data within ServiceNow to maintain data integrity.
- Use shared lists to eliminate duplicate citations during import, simplifying compliance management.
- Leverage Now Support for integration assistance and account management.
Compliance administrators can download content from Network Frontiers Unified Compliance Framework (UCF) to use as GRC authority documents, citations, controls, and control objectives. The documents can be updated on pre-defined intervals. You must have a UCF Common Controls Hub account to create shared lists and import them into the ServiceNow® instance.
If your organization wants to use UCF Common Controls Hub as the source for your controls library, you can purchase a subscription from the ServiceNow Store or see Common Controls Hub. For more information, see Unified Compliance Framework.
- Sign up for a UCF CCH account and customize your basic subscription to include API Access.
- Activate Compliance UCF.
- Create a Now Support Case for UCF-CCH account integration information.
- Configure the UCF integration using the UCF Common Controls Hub.
- Download a UCF shared list.
Import authority document using single shared list
An error is rendered since SOX is not being reimported within this Shared List.
Import authority documents using multiple shared lists
If you need to import more than 100 authority documents then you must import them into multiple shared lists, as there is a limitation that a shared list can contain only 100 authority documents. You can create multiple shared list (SL), for example SL1 to import 100 authority documents and SL2 for the rest of the authority documents. Group similar authority documents as one group when you import the authority documents into multiple shared list, so that there is no dependency of the documents between the multiple shared list.
- If the system property is set to true, then the existing validation is done to check if the authority documents imported are already imported in the ServiceNow instance.
- If the system property is set to false, then the imported authority documents are not validated at all.
Set the property as false and import the UCF content in multiple shared list. If the authority documents, citations, and control objectives that are imported in the shared list are deprecated, then such documents will not be deactivated in the ServiceNow instance. Instead, the user must manually validate the documents and the links between the citation and control objectives. An email is sent with the links to the mapping between the citation and control objectives.
UCF and GRC terminology differences
Authority documents in the UCF content are organized and mapped to their proper citations, which in turn are mapped to a common set of controls. The terminology between UCF and the GRC applications differs slightly as explained in the following table.
| UCF | GRC application |
|---|---|
| Authority Document | Authority Document |
| Citation | Citation |
| Control | Control Objective |