logo

NJP

4/29 Last THURSDAYS with ITBM: ITBM + GRC: Even Better Together!

Import · Apr 29, 2021 · video

past the hour so right it's good to me lisa thank you deborah all right so thank you everyone for joining us today my name is deborah mcgrath i'm a senior technical product marketing manager with servicenow and i'll be hosting the webinar today and today's webinar you're going to hear about servicenow itbm and grc or integrated risk management and how they work better together joining me to do the presentation are greg kahn a grc advisory solution consultant and doug page senior principal product manager for itbm so doug if you wanted to advance to the next screen so what we're going to see today greg and doug will be showing you how the new apm to grc integration app reduces the amount of effort required to manage application risks and how it helps ensure operational resiliency for business applications by helping you apply the right assessment identification of controls and attestation of remediation we'll then take a look at how project managers and enterprise risk managers can assess project risks using an advanced risk assessment form so they can calculate any inherent and residual project risks and view those accessories on a dashboard and a risk heat map and then finally we'll see how the grc advanced audit app makes it easier for audit engagement managers to manage the object to manage the audit as a project for a better audit execution experience so doug i'll hand it over to you now to kick it off yeah thanks debra so we're we're going to start with how uh servicenow can help organizations use apm and irm together to manage the risk life cycle but first let's start with three major problems that organizations are dealing with the first is the growing number of applications all organizations see this different parts of the organization are purchasing their own applications now so we see a large increase in the number of apps we also see a growing number of threat actors people who are trying to get access to information that is housed within these applications and because of that there's also a third problem which there is more regulatory guidance or governance around these applications and how organizations have to end handle this information what's also happening at the same time because of this increase in number of applications is actually the increase in application spend so in 2021 that went up by 8.8 percent and gartner's assessment is that in 2022 this is going to go up by more than uh 10 so we're just going to ask greg to come on now and talk about the life cycle yeah absolutely doug so having said all that that you said about you know the impact and you know the privacy concerns around data and everything associated that you have to manage the risks and the controls and the compliance and everything around those applications and what servicenow does really well is to bring those workflows right to the end users and we're going to use this lifecycle around this where you know in normal days we would do this with phone calls and emails and spreadsheets you know putting things out on sharepoint and to get visibility around all that and get that workflow together was often difficult sometimes and so we want to do that starting right away with an application questionnaire that gets triggered right when an application comes on board or you can do it on an annual basis right to understand what's going on from confidentiality and integrity and availability impact or privacy we take that and do a business impact analysis over in the security world to say what is it that what what is this application bringing to my risk landscape and risk posture right let's look at that business impact and see how risks are impacting this environment based on what this application owner is telling me about this application and the data behind it right that data is what's important and then we go into those controls and looking at those controls and every now and then we're going to have second or third line doing their control assessment and this process really brings that first second and third line of defenses together into one workflow in one application when we when we talk about this you know getting that benefit you talked about that cost right bringing that effort down for those risk managers uh providing information out to that business unit the stakeholders that are involved you know where is my compliance today we'll show you that dashboard that real-time reporting that we've got done on the platform that we utilize that performance analytics and get insights into that business criticality around that and where my risks are within my applications and there are really three key personas that are part of this process that craig just showed at a high level the first is the it risk manager and they're the person who is really responsible from the risk side for application risk they're going to decide uh the business impact analysis score for the application they're going to identify and implement the necessary controls for those applications so it's really from an enterprise risk perspective to say based on the information we have around these risks what do we need to do to ensure that they're governed properly at the same time we also have the application owner they're going to be the primary point of contact for these applications and they're the ones providing the information to the risk team to say hey this is what this application does um and and here's what we do with it today and then finally there's the business owner uh they're the sponsor who's responsible for the application and they're gonna monitor it on a on a periodic basis so this is a high level flow that we're going to walk you through you don't have to look at this all at once we're actually going to build this out and this is a detailed view of the flow that greg had just showed in that circular view but we're really going to start here with the the creation of a business application within servicenow and we have out-of-the-box catalog items that allow us to register a business application so if we go into then what happens next is and greg sorry i'll i'll hand this over to you yeah absolutely so right when that business application was created it triggers a workflow within servicenow right that automatically starts reaching into the grc the irm world to create that entity and we're going to throw over a questionnaire to the application on the right within the application right so if you go to the next you can see as we start to move through this here i'm in apm right and i've got all this feature-rich data within apm that tells me all kinds of things about this application you'll notice that this risk questionnaire is part of this as soon as this gets associated to but plus your district second you notice i've got up there where it says contains pci on it i've got controls already associated with this i've got an attestation this is just baseline stuff that can be brought into an application without even going through a risk questionnaire so these are baseline controls that says hey any application you're going to have these baseline controls so let's start there and provide that visibility right away but this application questionnaire is going to start driving some of this risk identification so go ahead and step through the next and this is where we become that application on it right to answer these questions uh around that so this is where you doug as an application owner you're going to answer those questions and these questions can be dynamic based on your environment what you want to ask we have some out-of-box questionnaires around it but think about this being on anything that's happening within your environment not just an application but it could be if i'm implementing changes within my environment send out a questionnaire based on changes and what's the impact of that if you go to the next slide you'll see that you're going to start seeing some of these questions and i think for the application or one of the real benefits is that they're doing this in context of where they're already viewing their applications they don't have to go to another system or somewhere else to do this this is all in context for them right we had a question and a really great question from an attendee that asked about how that entity is created over there that an entity is created through the combination of this better together between atm and iron and so we leverage that workflow to create that entity over there it's really cool stuff so now application x is created and i've got an entity over in my grc world application x and i start to get these details about this application because doug's filling this questionnaire now you know what are the customers involved whether there's uh where's the data located how long am i having this there if you go to the next slide back you'll start to see more around this questionnaire and you notice i i've picked on privacy a little bit because we're going to talk about that privacy privacy is really important to a lot of people right now whether it's pii data phi data whatever it might be i'm going to look at payment card information today and talk about that card number called early name so what i'm saying here is this application manages card holder data right that's really important to understand that that's theirs so if that's the case i've got some pci requirements around this right if it was uh health information i might have some hipaa requirements around it if it was pii data i may have some california privacy or gdpr requirements around it right from a privacy perspective but this this risk identification questionnaire helps drive uh the information that we're going to get out of this so now that we've done that let's go in as that risk analyst and and look at this so this is the old days where you know doug you i would be calling you on the phone and saying answer these questions but you know i've been bugging you for weeks to answer these questions i really need these questions answered and i call you by emailing you and you're out of office you know it's just it's a back and forth that gets frustrating this is on the platform and so the work you did i get to view it that's a really cool part so let's take a look at what that looks like you can see here the first is here i am i'm karen i'm logged in i'm this risk person i get visibility into my workflow and what's being done and what's not being done using you know these feature-rich dashboards using performance analytics and bringing information in the key to a lot of this is that visibility into it my boss isn't asking me where my work is done my boss is you know seeing it in a dashboard that's live actionable that's updated all the time so go to the next slide the next step more into this process so here i am doing this assessment and you can see the lifecycle everything in servicenow has a life cycle you'll hear that a lot that that life cycle right now i'm in a review state right so i can view the responses for that application on it and you see i have an inherent assessment here and i could turn in the control assessment a residual assessment that workflow is flexible so i can do a lot of different things but what i'm looking at here are those responses right and right from here i can see some of what doug has responded to within this application and take action on what doug has responded to i can even reject this and say you know what doug uh i think uh these ques these answers don't seem right let's reject this and send it back to you i can even do that if i wanted to because i don't trust you all the time doc you don't seem like that not trustworthy so go ahead let's let's now move through the process right i looked at your responses now let's assess that inherent risk because you i asked you a bunch of other questions too about it right that confidentiality integrity and availability so let's see what that looks like on that inherent assessment and you can see on this inherent assessment that i've triggered uh some scores already automatically because i use what's called automated factors that build out that confidentiality availability and integrity impact so based on your responses my identification has already started my risk analysis has already started for me automatically based on configurations that i've set up on scores that i've agreed with with everybody in the organization this is me reaching out to compliance and everybody else the application owner saying look if you answer these questions this way this is going to be your score right and so i move through that an assessment and i answer a few more questions on my side right that threat impact that threat capability all the different pieces you know what's the probability and i get this computed criticality score right this high score that talks about why this application is the risk that's providing me based on what you told me i'm not going to give you something and have you say you know greg i don't understand why you're giving this i mean this score why is this a high score i'm giving you this because you told me you saw what you told me based on what you told me this is a score and you start to get that agreement back and forth there's no battle in between the business unit and the risk team you're bringing all on the same page with it so let's finish down through this lifecycle deck and see what some more of this where i'm going to come in and review get some sign off on this inherent risk i need to go back to the business unit and say do you approve of this risk right and based on that risk rating i'm going to map some controls and recommendations i'm going to use a state-of-the-art recommendation engine that i absolutely love and we'll see some of that and map some of those controls and risks and policies and everything back to that control owner so let's see what that looks like you can see here i ask you questions around credit card data and you responded that there were card holders card holder name right and based on your response i automatically mapped these information objects to this application right and these information objects reside over in your world right in apm is that right yeah exactly that's part of our data model for apm and part of our structure around technology portfolio management the application portfolio management the business capability and that fourth one is really that information management within application portfolio management yeah so think about this could be driver's license number this could be value information around privacy a lot of different things could be mapped to this and the reason i like this is i'm as a as a risk officer as a compliance officer i'm going to take advantage of what you just told me by using those same information objects and map those information objects to policies to controls to citations to risk and now i allow myself to be able to look in your world because you have this data i have the state-of-the-art recommendations that's going to recommend to me as an informational security officer implement these risks implement these controls doesn't mean you have to but if it's pci there's a good chance i want to implement pci controls around this right so let's see what that looks like if i take this into this this is where i'm bringing those information objects in and i'm going to do my risk mapping and my citation and policy mapping and control mapping based on the application and based on the data that you've brought into me into that world so if i step through i'm going to do the wrist mapping and i'm going to do some you know association with citations and here what i'm doing is the system itself is recommending these citations to me because of that information object right so i'm not going out and trying to hunt and peck and you know willy-nilly picking out different controls the application the irm application is doing this for me utilizing those recommendation engine and those that that information object that you told me that there's credit card data if there was phi data behind this this same citation would be associated to hipaa right or high trust or whatever it might be that you're working within your environment or even privacy citations associated with this as well and i can do the same thing from a policy standpoint so if i've got a bunch of control objectives that are tied to policies i'm going to choose certain policies right a change management policy intrusion detection policy whatever it might be remote access right so these policies have control objectives that have controls and citations associated to them so i can map these policies directly to this particular application what we call an entity over in our irm world that i build around this application and then when i do this this is for me i used to be an application on it right my background i was a developer i wrote applications i go way back in the day i won't tell you what language i developed in but what what this does for me is it gives me a warm feeling because i'm pushing these controls down to the controller right you know that i'm sure in your life at some point someone an auditor somewhere is beating you up to asking you you know give me give me [Music] give me the idea that you have a firewall implemented or give me the idea that you have encryption implemented right and how you're going to provide that evidence right i can initiate these attestations directly from here yeah and i think the real advantage here is also displaying that within the context of the application as well so that the application owner who's more focused on looking at it from that lens they have direct access to these same controls yeah absolutely right so there was a question about those entity types with ngrc and whether this eliminates it it does not it it enhances those entity types so based on the risk i'm going to have an entity type that this is a critical application based on the score and i'm going to put it in that entity type right and this is where i can start to map those controls and everything associated with that so now let's move into those controls and what those controls look like and what those attestation looks like and the automation about this i joke around you know i spent 20 25 years doing this uh in a large financial firm working in different ways as an application guy a network guy never security firewall guy working knocks and socks and all that stuff and i would go to lunch with everybody right you and i doug would go to lunch together but then when i became an auditor people stopped taking me to lunch i'd walk in a room and conversations would stop right you would stop talking to me duggan in the old world and i joke about servicenow knocking these silos down between this first second third line of defense that you can start taking your auditors to lunch and i'll show you how this works so these attest stations what you're looking at here doug is your attestation associated to this application in your view right this is your application view yeah absolutely we've got an application you can see on the top there and if i go in as the application owner to actually complete one of these i might say i'm compliant and i can attach evidence of how i'm complying answer some questions in this case i'm responding that i'm not compliant and then greg maybe you can walk us through the results yeah so think about that you've said you're non-compliant with this particular control i get immediate visibility in my compliance world because i've tied those controls to a compliance framework i can see that i'm non-compliant with a particular framework and i can immediately from here trigger off exception process right so if you say you're non-compliant let's set up a policy exception or controlling exception with a life cycle around it right so look this is a new application i haven't got all my ducks in a row i don't have that encryption you talked about you know i don't i'm not salting my password with a hat you know whatever it might be but i can do that in three months so give me three months to do that but let's make it visible to everybody and see what the risks are because this control is tied to a particular risk and if i do a risk assessment against an application and i tie controls to it and i say i'm great but then i put my head in the sand and i'm not monitoring those controls in real time when a control fails i want to argue with you that you aren't achieving that residual risk or that you might think you are because these controls become non-compliant or compliant over time and at servicenow we have the idea of monitoring these controls in real time as things happen and so you can start to see the life cycle around this and not just from a business owner but an application owner you know a line of business but a risk officer a compliance officer get that same view into this we're sharing that information across the enterprise great so let's just take a look at the overall process just and we won't walk through all the steps again but basically we've walked through this entire process to show how it can be supported uh using both apm and irm yeah absolutely this is one of my favorite better together stories we have a lot of these better together stories we're going to talk about a couple more here in just a second but but this one really resonated with me because i was an application developer for a long time having this automated in the way that it is and bringing those different first second third lines of defense together is really a lot of fun really resonating with our customers when we show this 100 yeah and greg i'm going to chime in here um speaking of that better together i'm sure i can speak for doug and say we'd be happy to take you to lunch so appreciate you joining us today um this lab i understand that we have a great knowledge 21 lab that will be available in 11 days 11 hours and 6 minutes i'm watching on the website um that actually walks through what you discussed with yeah so a couple of my peers took this and made an absolutely phenomenal uh lab that you'll get some hands-on where you can register for and actually walk through this yourself in an instance uh walking through the different lab guides that they've got around this and they've done a phenomenal job uh i'm playing one of the gurus on it but yeah it will definitely resonate if you are living in this world at all whether you're an application owner and you don't know anything about risk or if you're a risk or compliance officer and don't know anything about application development it brings those two together in a phenomenal way um and i'm going to post in the chat in case anybody didn't get it i have a list of um i think i just posted it and lisa if i didn't i just posted a list where you can actually get a link to that lab so you can watch it register for it as well as um some of the other resources that i'll be talking about in a second great i'll do that right now thank you lisa appreciate it yeah so knowledge kicks off um in 11 days we encourage you to to register for that and i think before we move on uh if i could real quick answer a question on this um so deborah that they're asking about and this is a phenomenal question this is our bread and butter what we do they're asking about the opportunities to automate control tests and asset stations right around change management yeah that trigger that doug and i talked about right from a trigger perspective it's a new application that's going in but think about if you're an application owner and you're going to make a change on that application i can take that same opportunity to ask you those questions again because you opened up a change record right you may have certain amount of data behind this application but now you're going to change those information objects and i can capture that in a change it's a really great opportunity to do that in both the change world but also for new applications as well awesome thank you so that is it go ahead deborah started saying thank you absolutely but the the better together story does not end there so that's a great use case next we're going to talk about another really use case is assessing project risk using uh integrated risk management advance risk assessment so the capabilities here is really uh the integration of project risks with enterprise risks there's a standard project risk library there's flexible risk assessment workflow and scoring and risk aggregation and visualization and that's them um and the key personas that are here project managers so they're basically the ones who are identifying risk but from this case they're actually doing it from a project lens identifying these risks and we also have the project risk owners the people who are actually responsible for these risks and then we have enterprise risk managers who need visibility into risks from projects especially if they end up being enterprise risk a good example that i think of often is you know at a project level we might identify hey this is a new vendor that we're working with we don't know what it's like to work with them that's a bit of a risk on this project but that's actually an enterprise risk the fact that we've got this this new uh vendor um about this like bringing those people together right that better together bringing those different first second third this is another example of doing that bringing all those people into that visibility for that exactly yeah this is exactly right and i i i can't tell you prior to coming to service now in my ppm world how many times people would ask us that is like how do you associate project risks to enterprise risk and i never had a good answer for them but coming to servicenow uh you know there was always the ability to relate these together and now we're helping customers do this out of the box which is fantastic so some of the things that you'll be able to see on this screen is some of the visualizations that exist now in the project world so that people can see things like inherent risk heat map or there's a new dashboard with project risk overview and but leveraging this advanced uh content that we get from irm and then here what we're looking at is a project and we're specifically looking at the a specific risk on that project and they can select that risk to look at more details and here you can see there is an option to elevate this to an enterprise risk and that is going to allow us to do a few things it's going to allow us to workflow that based on the irm workflows it's going to allow us to leverage any libraries from the irm team around types of risks and it automatically provides visibility to that enterprise risk team so this that that check of that button is basically instant visibility to the risk team to bring these together so that was a very powerful integration greg were you going to say something on that i was just going to say yeah this is where now that you've mapped it over to there i get visibility and i can apply those controls that we talked about right in that application over in that application i can start applying those controls to this risk right from day one so right right in the project area yeah absolutely there's also a third use case we want to touch on quickly today as well which is how irm or grc teams can improve audit engagements by managing them as projects literally leveraging our project management capabilities from itbm so what we're seeing here is an engagement but we can see that this is actually linked now to say we're using this from a project capability um and that's going to provide a really good experience for them to manage this from within here you can see we have dates now that are related from a project perspective we also see within this engagement you'll see at the top now below we have all the project management capabilities so very often we have customers saying for that engagement i want to be able to manage costs around that or i need to do better resource management or i need to do better status reporting what's also powerful here is now these are visible within our project management views whether that's a program portfolio or roadmap view that work now becomes visible with other project work that we're doing at the same time yes if you think about the number of audits that are going out within my enterprise right i've got my socks on it i've got my pci audit there's no internal audits you may have 200 to 500 audits going on throughout the year and that resource planning and understanding the visibility you know i need a i.t specialist or an application specialist auditor who is on my team that i can assign that you know are they going to be out on vacation what's going on what's that resource planning what are the costs associated with all these audits right because audit is a cost structure around that i don't know that i've ever seen an environment where you make money out of doing audits but you're saving so much time and showing the resources you've got by bringing this project piece to it it's really pretty amazing on what the visibility brings to this now deborah and i are gonna have to capture that lunch that we're taking you out for in there in the cost of this as well the cost of course absolutely yeah um and i just have to say thanks so much greg and doug for that great presentation on how apm and ppm work so um so much better together with integrated risk management and just as a recap just wanted to point out we saw how itbm integration with grc or irm helps a variety of personas across the organization from risk managers all the way to business leaders we saw how it enables application owners to manage the application risk life cycle with improved efficiency and better communication and insights and we saw how project managers can better assess and track project risks with advanced risk management and how audit engagements can be better managed as projects for better user experience for engagement managers and other stakeholders and in our last few minutes i'd just like to point out our resource list which we've also lisa posted in the chat and it includes links to the three applications doug and greg discussed today as well as all supporting materials and these are all available on store.servicenow.com you'll see information about the application as well as several links documentation and training there's also a link to docs.servicenow.com where you'll find documentation on these um applications doug and i did a three minute very high level video that just kind of recaps what we went over today at a very high level if you want to check that out on youtube and finally um there's a link to the lab that we talked about we do encourage you to check that out um i think it'll be very informative and very helpful it'll hit home what we went through today and that'll be available again in 11 days and then finally i'd like to invite you all to join us on the last thursday of every month when we'll present a webinar on new itbm capabilities or enhancements to existing applications and our next webinar features doug again it's itbm product roadmap on may 27th and doug will present this along with pradeep bonsai who's our itbm um director product management and that's going to provide an overview of what our customers can look forward to on itbm product roadmap and with that unless we have any more questions if you do have some questions pop them in right now um if not just wait a minute [Music] and if not i think that's pretty much all the time we have anyway so again thank you doug and greg um appreciate it and hope to see you all next month one second please show the links again thanks again oh we do have yeah i had a question there from someone that would like to see those links again oh sure and we did post them in the chat window so you should one more time right there perfect yeah and uh i have it live this is going to be posted so there's proof that they owe me lunch just keep that in mind we do this is great thank you for inviting me appreciate it doug thanks thanks greg that was great

View original source

https://www.youtube.com/watch?v=EZq-XWhl0E0