---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Defining a control's requirements at the level of control objective

# Defining a control's requirements at the level of control objective {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can break down a control at a more granular level as requirements when you generate the control at the control objective level.  
Defining control requirements helps:

* Security Control Assessor (SCA): To assess each requirement of the control individually if there are different aspects to the control testing.
* Authorization official (AO), Information System Security Officer (ISSO) and Information System Security Manager (ISSM): To understand the requirement that failed, which lead to the non-compliance of the control, instead of evaluating the failure of the control as a whole.
* Attestation respondent identified for a control: To respond at the control requirements level, which is at a more granular level, rather than the control level.
{#cam-control-req-sca__ul_c1l_pfb_pzb}

As a CAM user you can break down the controls to control requirements, manage the requirements more efficiently, attest them individually, and have the package authorized. You can also define the
requirements and create them at the control objective level when controls are generated.

For details, see [Control requirement details in the CAM view of Control objective and Control forms](https://www.servicenow.com/docs/eDmTh9BoyVz_yKkY8I6yuQ "The CAM view of the Control form has fields that have been added to capture the control requirement details.").

## Creating NIST content from control objective description as control requirements {#cam-control-req-sca__section_zs2_p4r_szb}

The base system ships the control requirements generated from the NIST 800-53 revision 5 control objectives to CAM users. The Description field of the Control objective form lists the requirements broken down as sub-points with sub-numbers. The Reference of the control
objective is clubbed with each sub-number or the clause in the Description field and referenced as a Requirement number in the Control objective requirement. For example, if the Control
objective reference is IR-9, and the description of the control objective starts with a sub-number (a.), then the two are clubbed together to generate the first control objective requirement as IR-9.a, with further sub-numbers added
to it if available. Therefore, if there are about seven sub-descriptions, then seven control requirements are generated.


