Manage controls using the Compliance Workspace
Summarize
Summary of Manage controls using the Compliance Workspace
This content explains how to effectively manage controls in ServiceNow’s Compliance Workspace, emphasizing the importance of rationalizing, consolidating, and defining controls to align with your organization’s risk and compliance objectives. Controls represent specific implementations of control objectives and must be carefully maintained for accuracy and efficiency.
Show less
Rationalize and Consolidate Controls
- Rationalization: Instead of bulk uploading controls, refine control sets by evaluating their impact on business objectives, risk mitigation effectiveness, and operational efficiency. Regularly update controls to reflect changes in business, IT processes, and technology.
- Entity Association: Controls must be linked to an entity. Missing or disabled entity associations can cause calculation errors and require retiring such controls.
- Consolidation: Identify common controls across different regulatory frameworks to avoid duplication. Cross-mapping controls helps create a streamlined, consolidated control framework critical for audit readiness.
Defining Controls and Business Rules
Establish business rules early to configure Governance, Risk, and Compliance (GRC) settings effectively. Prepare to:
- Identify controls and assign control owners
- Define control tests, expected results, and test frequencies
- Assess risks including impact and likelihood
- Prepare attestations, assessments, questionnaires, and collect required evidence
- Map authoritative sources to policies, procedures, controls, and risks
- Understand user roles and interactions within the GRC system
Control Requirements and Attestations
- When enabled, control requirements are automatically created for each control under an entity, matching the number of control objective requirements.
- The attestation feature at the control requirement level allows granular validation where respondents attest to individual requirements, submit evidence, and explain as needed.
- Failed attestations trigger issue creation, mark controls as non-compliant, and update status roll-ups to related entities and objectives.
Entity Based Access (EBA)
- EBA allows granular access control to records associated with specific entities by assigning users or groups, or configuring user fields.
- Users qualified by EBA settings and with proper roles gain access to key tables such as Control, Attestation, Policy Exceptions, and related records.
- New controls and related records automatically inherit EBA restrictions when entity-based access rules are enabled, eliminating the need for manual bulk updates.
Practical Benefits for ServiceNow Customers
By following these guidelines, customers can streamline their control management process, maintain accurate risk assessments, simplify compliance audits through consolidated controls, and enforce strict, role-based access to sensitive compliance data. The granular attestation and automatic inheritance of access controls improve security, compliance tracking, and operational efficiency within the ServiceNow Compliance Workspace.
Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.
Rationalize your controls
- How does this control affect my business objective?
- Is this control actually preventing or detecting risk?
- Is there a different control you can place that better protects your business?
- Is there a control you can put in place that reduces process overhead and improves IT performance while also mitigating risk?
- Can a complicated control be replaced with a simpler more effective control?
Consolidate your controls
Look for opportunities to consolidate controls. Look for common, repeated controls across multiple regulatory authorities of frameworks (for example, SOX and GLBA and AML). Avoid operating a single control multiple times for each regulation, by cross-mapping controls and eliminating the redundant ones. This process establishes a single consolidated set of controls: control framework, performing and preserving the cross mapping of controls is critical for audits.
Define controls and business rules
- Identify controls and control owners
- Define control tests and expected results
- Establish test and control frequencies
- Identify risks: impact and likelihood
- Prepare attestations, assessments, questionnaires, and required evidence
- Compose likely use-cases (who needs to interact with or view the contents of the GRC system and for what purposes)
- Map authoritative sources to policies, to procedures, to controls, and to risks
Control requirements
When Create control requirements option is enabled for a control objective, for every control generated under an entity type, control requirements are also created automatically. Previously, only controls were created for entity types. The number of Control Requirements equals the number of control objective requirements.
Attestation at control requirement level
The Attestation at control requirement level feature allows attestation at a granular level for individual control requirements within a control. Admins can enable requirement-level attestation, assign respondents, and generate assessment tasks for each control requirement. Respondents then attest to requirements by indicating whether they are implemented or not, providing evidence or explanations as required. Failed attestations automatically generate issues, mark the parent control as non-compliant, and roll up the status to the associated entity and control objective.
Entity Based Access (EBA)
The Entity Based Access feature provides a framework for more granular approach to management of data access to objects associated with an entity. Administrators can grant access to an entity's related records by adding users or user groups, or by using entity user fields for entity-based access configuration. For more information, see Entity Based Access.
- Control
- Attestation
- Policy exception to control
Entity Based Access (EBA) rules
When entity based record access rules are enabled on the Entity Based Access Configuration Properties page, any newly created controls, control attestations, indicators, and indicator tasks associated with a configured entity will automatically inherit the entity-based access (EBA) value from that entity. Previously, users had to run bulk access updates to apply EBA restrictions whenever new objects were created.
For more information, see Entity based record access rules to secure new records.