GRC IRM Office Hour 18 GRC IRM – Session 2 – Entity
hello everyone my name is charles rayburn i'm a customer success advocate here at servicenow we started these office hours earlier this year to kind of help cover topics that you as customers have expressed to us your success advocates and monthly check-ins or quarterly health check-ins so definitely keep providing with us those type of topics you want to hear and we'll try to put together these type of sessions based upon that feedback also too any feedback that you provide within the survey links that we provide after this call helps us to continue to put together these type of sessions as well as pick out new topics in the future so this will be for those who are attending and also to those who are also to listening to the recordings which we're having a lot of customers uh reviewing the recordings as well who are unable to attend these so thank you all for listening and as well as attending today is a session number two of grc governance risk and compliance we have our awesome rock stars uh subject matter experts rick and jargon who are going to talk to us about entity components are related to that so without further ado um just kind of the big format here is the first 15 20 might even go to 30 minutes just however long it takes for the subject matter experts to talk about the actual topic and to level set um so that we all understand from servicenow speak what does this topic mean and how does it apply and with some of the best practices related to it the remaining portion of the hour is open for any customers to ask questions so uh once that occurs uh feel free to either unmute yourself and ask a question or jot it in the chat window i'll monitor those questions and relay those back to the team that's here to kind of ask those as well any other questions or comments if not dragon and rick take it away it's all yours thanks charles good morning to all um i'm from santa clara california early morning to us happy to be on the call so uh myself and rick we represent product success for uh risk and checkups you know we specifically focus on you know talking to customers like you in terms of what other customers are doing what are all the special features of the product that will help you to you know continue your grc journey and get the benefit today's topic is last last time we covered a little bit about and it is today we are going to deep dive into entities how do we create why do we create entities and what is the what are all the different components that are available in you know creating entity and their scoping okay are you able to see my screen we are saying it perfectly thanks thanks okay before we start uh all of us know most of you know that this is a service no architecture for grc especially right high level components that are available uh we have you know authority sources we have policies we have risk frameworks and you will see the word called profile and entity interchangeable because the older version of the word called profile the current new version if you are not updated you will see the word called profile if not the word will be entity right so entity type or profile types then controls risks which will have you know control test plans indicators issues associated with that risks will have indicators and issues and risk assessments then audit management overall right so this is the high level architecture for servicenow grc now you may be wondering that you know how all of these are tied together right there are multiple components so what we did just for ease of use is we created a cheat sheet right this will be available this will be very handy for you some of the terminology that is used in grc right you know we have policy authority document control objective entity scoping types entities individual controls owners attestation so on and so forth today specifically we are going to talk about only five items right entity scoping entity type entities class and here right so this is handy for anybody who wants to know learn uh servicenow grc in a little bit more detail these are some of the terminology that we use okay having said that why we need entities right typically you know that when you start implementing years you'll get a lot of questions right you know from your senior management or other groups saying that you know i want to see that where does my risk lies whether there is a compliance issue which department which group has compliance issue now having controls having risks or risk statements is just having those end policies is not enough you need to tie that to a particular department or a group or a process so on a trophy same thing is applicable for audits if you look at this example right so what do you want to do what is your policy right policy has you know policy statements or policies which will have control objectives in the previous uh version we used to call it as policy statement currently it's called control objective next is do what you say right is everything following the policy right you know the hr department is following the policies the sales department is following the policies these processes are in place for this particular product so on and so forth and that is verified by a third line of defense typically called in you know three lines of defense called audits they verify this uh all the work that is done by either business users or second line right to answer these questions the important component is we need to try either risks or controls to different items and those items in service now are called entities right now all grc is all always about managing risk and compliance right how do we manage risk and compliance we need to tie either controls to particular policies authority documents or to a person or a process and we also need to measure that you know how much is a impact and when is it going to get impacted so answer all these questions we get into entities right today what we are going to cover is we are going to cover overall you know architecture that we covered we talked about entity architecture entity types entity filters and entities itself and entity class and tiers okay now having said that typically the traditional approach that we had is in the legacy world people used to do things bottom up right you know you will have different systems will be tied to different controls or risk statements they are same thing without structuring people working silence either different uh excel sheets or share points or different tools service now with the irm tool we have a top-down approach right you know wherein we start you know combining everything together and start dividing the items so that you can reuse some of these components if you look at these examples right the types what you see here is you know the types of entities that you want to create if you will or profiles right now let in a little bit more details the important aspect why we need to create entity and why we need to create entity types and processes right as i said typically you'll get a question from either a cio or cso or a cro saying that why does that where do i see my top product lines or top departments who are having high impact or high high issues of compliance right if you want to model that type of you know reports or dashboards or outcome you need to map there's a mapping exercise that has to happen that's where this entities will come into picture it that's one question second question let's take an example that typically in a security world right you have access management right access management policies or controls are there now if you want to apply this access management to each and every application assume that you have thousands of applications right now creating that association becomes very difficult it's a lot of tedious copy paste work that needs to be done i mean service no that's where the magic happens right when you try what we call it as control objective for example access management policy is a control objective which is tied to an entity type whenever there is a new application that gets created automatically that particular control objective will be tied to that application and individual control statements will be created or instance of control will be created this automation that happens using entity scoping process and uh creating entity types same thing is applicable for risk statement right you may have a risk let's take an example there's a security risk or a detailed statement of risk is this is uh we want to tie it up to each department or each processes now making that work is very complex that you need to copy paste and you need to keep maintaining that that automation happens when you tire this risk statement to entity detect that will create individual risks then it can be used for assessments and controls can be used for registration this will be also used for you know either evidence collection for your external auditors or you are getting ready for software software kind of a certification okay this is scoping process that's why we need entities this is one example from the older russian people are using london right so there are different components that are that profiling is as we discussed its entities policy and compliance risks audits and you know global so this is one example i mean the newer version we have something called grc workbench where you will see all this okay this is the second example the complex example right where does the type type entity types now i know that some of you are using cmdb effectively right the beauty of service now is if you are having your cmd be mature by creating entity types and filters the individual entities and association happens automatically now if your cmdb is not mature you can still go ahead and create entity types and create manual entities if you will like that attribute and the association and automation as we discussed that will happen automatically this is one of the examples that we have in the system okay now this is a very very important slide right there are three or four components that i want to discuss again as i discuss i kept this for you know kind of backward compatibility profile is named as entity now we have profile class or entity class profile tier or entity tier and profile class rules or entity class rules then we have no entity types and entity filters so one two three four five items and profiles themselves already themselves let's go one by one right let's discuss one by one now the simplest way is to think through that profile type is grouping of items processes or things together right you can give a name saying that all my financial systems all my socks applicable system that can be a profile file the filtering helps to create these entities automatically if you have a cmdb right that is filtering is nothing but the filtering criteria from a particular table for example if you have cis in a table which has thousands of cs if you want to filter that on a specific criteria you can use profile filters that's where this i two things come into picture entity classes or profile classes are nothing but tagging right if you want to tag to a particular entity this entity for example this and it is called department there's an entity called business processes or entity called applications right we want to tag it again there is the automation that happens when you create a class rules class rules that will tie up to a particular table whenever there's an individual entity or profile that gets created that will be tagged with that profile classes right now the third one or the one more item that is nothing but profile tiers or ntdts assume that you know you have business processes there are multiple types of business processes if you will or suppose let's take an example that you have applications applications are tied to you know let's say windows application applications are there that will class tied to a class of you know windows class that is tied to a particular department or a processing that is tied to a particular group if you will we want to maintain that hierarchy of entities you need something called profile theory or entity theory now this will also help you in you know when you get into details in getting to help you to you know associate there is something called upstream and downstream entities that will be done using profile classes and profile tiers i know this is a very busy slide and complex terminologies but you know there are i'll give and once we go through example you will get this idea and you will clarify this idea much better right so we have profile types or profile filters entity type entity filters entity class entity tier and empty class rules okay once this linkage that happens all other things gets created automatically if you have cmdb if not whenever you create a entity type that association happens and tagging happens automatically okay now also the advantage of this is you know that if you are using the risk or complex for scoring rollups this classes and class rules and tiers are very helpful i mean you can set up if you are using advanced risk it's a new feature that we have in service now for risk roll-up uh this architecture is being used right now this is one more example again older example right now getting into detail let's say entity type called global office locations there's entity type called north america office locations there's entity type called european union office location right and this is determined by profile filters where we discuss filters whenever in the cmdb table you have a table and a filter these entities gets created automatically right now if you look at a same table and the same item can be of multiple entity types look at berlin office the european office location also it's a global office location right you don't need to create this duplication of work system will automatically take care when you have this you know types and types and filters that are set up okay this is one more example that we have right how policy statements or control objectives are tied and automatically controls getting created right uh this is the last example of classes as we discussed right you know there is a class called department there's a class called business services a class called project there can be multiple departments there can be multiple business services there can be multiple processes multiple projects now department business service and project classes finance sap finance and account integration these are your entities now the hierarchy of these entities are defined by entity tiers look at this right project is tier three business services sphere two department history are one right so this kind of association that is possible when you create entities rick before going further do you have any comments here no no this is really good i don't have anything thanks let's get you this is one very good latest example we have been discussing with many of the customers i want to go through this details right you know if you look at let's take a practical example today right assume that we do this pandemic scenario you want to check that all the employees have remote working equipment right now if you want to do that using grc tool it's very difficult to do it manually right that's where the example of our entity entity type that comes into picture now if you create all employees have remote working equipment as a control objective which is tied to a policy of code 19 right remote work safety and productivity now what happens right if you want to tie this up to individual employees i can create entities of individual employees which pulls the data from user table then this particular objective will be associated and system you can configure the system to find a survey or attestation for each of the individual employees and they can click on that saying that you know things are working fine or things are not working fine based on that example you can show a scoring around that that's one you know current scenario example now let's take the second example here right this i think this will clarify all your kind of thinking around all these four or five discussions that we have look at this right let's assume that you created tiers as business as tier one application entity scr two ids tier three correct now you have created entity types as departments and vendors applications and business services databases and servers these are entity tags moment to create entity type and filtering from cmdb these individual entities gets created right customer support is an entity that gets created finance is an entity that gets created hr is an entity that gets created same thing with this particular entity thanks we will have workday sap line x so on and so forth since you have created entity class rules means from this particular cmdb table whenever the item gets created map them to a particular class called department based on the class rules then whenever this custom support or a finance or hr entity gets created that will be automatically tagged to a class called partners same thing is here now the beauty of service now is entity types can be associated with multiple tables from cmdb right and workday is a business service but you know sap linux and windows application are business applications same thing is here now tagging of entities to a particular class and you know assigning the test happens automatically based on your class rules and whenever the entity gets created as we discuss when you create a ndp filter when it gets created they will be automatically attacked to a class and a clear now as we discussed the whole automation the the beauty of service now is around automation of creating this this has to be done only once during the setup you can modify that if required and that will help you to you know create data automatically uh break any comments questions here or suggestions based on your experience no this is laid out pretty nicely the way that we're explaining this thank you okay now what should you do next right my my suggestion is this like you may ask what is that that i should be doing if you are not created entities and things like that right identify the data source for entities this is very important right typically what happens is yeah servicenow gives these tools and techniques but how do i go ahead and you know start implementing this identifier data source it can be cmdb or some excel sheet list of processes list of applications lists of departments legal entities product lines so on and so forth right then you document your entity tears which is nothing but hierarchy and classes and types as we discuss then run your scoping exercise workshop this is one of the very critical success factors for gs implementation in service now a lot of other tutorials that are available in community you know um charles i'm pretty sure all of you have subscribed to the community there are a lot of tutorials done by me and some of my colleagues that are available and a lot of discussion that happens go and start looking into that right so i'll stop here that's all i had from my side uh very open for any questions comments charles or you great okay all right i'm gonna check the chat window so far no questions from the chat window but now it's actually open to any customers who have any questions for rick or jogging about uh kind of the entities that were just covered any questions from the teams that are out there right now any points of clarification as well yeah i'll keep this cheat sheet handy this is very helpful according to me right so again i know that you know some of you may be thinking that um why service now is uh specifically thinking around an identity and automation right differentiation right here is a lot of this let's take an example of ucf right unified complaint frame unified unified compliance framework or maybe some of the other data sources from thompson writers or you know some of the other sources that are available now the feed comes but how do you map and manage that that is very very critical and that's why entity types are very require required and all the thinking around design is around entities and any times here so you may be in a different stage of the journey right you know you can start you know looking into some of this which is going to help you in long long term again right you know this is uh this needs lot of discussion within your department and your level of maturity of how and where you are any of you want to separate discussions happy to work with charles right you know in terms of you know brainstorm and we can you know discuss about how do you want to proceed further if you want to go into this direction that's a very good point too if there's any um customers that are on the line right now that are looking for like kind of a a little more deeper dive to just kind of help you get level set from an implementation perspective where you're preparing for one or you're working with a partner that type of deal these two gentlemen are very great at just answering a couple key questions walking through some of the high level and best practices to help get you that much better prepared for it feel free to reach out to myself if i am your assigned csa uh reach out to your associated csa so we have a couple of them on the line right now and then they'll be actually able to set up a good call for you guys to kind of talk with them and kind of go through your use case to make sure everything is kind of vetted that way as well so i appreciate that that opportunity and that offering there dragon sure thank you any questions so far the only question was about if it's going to be recording definitely it's going to be recorded and disseminated out to those who are attending in in person as well as also to those who were unable to attend um to listen to so any other questions or comments um from a grc perspective for these in the for these gentlemen also you know i will take this opportunity to make sure that in all of your you know part of the community we also are releasing a lot of new features right as we discussed you know we have been recognized uh well by many of the analyst firms five analysts from specifically right we are in uh different quadrants uh and we are investing a lot in grc also we are releasing a lot of new features in this october store release we have three store release per year uh marked sometime in feb march and june sometime in october so these three releases these are backward compatible with you know n minus one family release right whatever we are releasing now is you know available for orlando and orlando release also right now also we are releasing two more products uh we are releasing something called regulatory change management which is in uh coming in sometime in november we're releasing a privacy product sometime in march next year right there's a lot of enhancement that is done in audits policy compliance risk so on and so forth and the last one is you know i know that some of your attended some of the roadmap discussions uh uh we are working on complete revamping of some of the usability aspects which is our main focus next year in march and june releases right we are using modern seismic that we call it as inside for within service now which we are changing the ui of service now especially you know of some of these products where we create persona based pages specifically where this is very interactive and you don't need to navigate into multiple areas that's our main focus right so if you are interested in some of these discussions do let uh know charles and team know we are happy to blame some more on that what is coming what is there what you want to get benefit from the current sometimes what happens right you know we have released so many new features you may not be getting utilizing those features like as part of your skew itself right you know then we can have that long discussion in terms of you know how do you want to proceed further and where additional use cases that you can solve great well i do have a question that has come in um from tracy what are the access controls for viewing compliance information so access controls right today what we have is we have uh compliance officer complex manager and you know i know that you are talking about crudes here i mean create read update and delete the out of the box what we come up with we come up with you know standard roles there are three to four roles one is a generic role and which is like generic users in grc then it's complex manager uh compliance users and compliance admin these are the three particular access roles now people may want to get into granularity of access that's where you know you may have to create your own groups of access if you will great does that answer the does that help tracy yeah that that answers my question thank you perfect again if you are interested into more brainstorming we can have a separate call right we can discuss more because i know that an access control is a little bit kind of a different thinking for different companies and we can brainstorm if required yeah and i'm also really interested in the privacy piece that's going to be released later sure yeah yeah yeah if you can no we can discuss more around it's going to come in march but you know there is one component that is already there we have isolated for privacy for gdpr that is that now but we are releasing it as a product sometime in march currently itself if based on your skew what you have we have an accelerator for gdpr and come up with a content provider content that is ready okay perfect thank you great all right um i do want to make sure that all of you know and understand especially those who are listening to this recording that entity is very important it's one of the building blocks for around grc so if you have any additional questions or points of clarification feel free to email me charles and then or your csa to try to get a hold of rick or dragon to kind of talk you through some of those items i'm just to make sure that it's it's really buttoned up for you guys to help ensure that you have that great success so again just make sure that you email us and we can kind of get you in guys in contact with product success to help enable and have those good conversations all right i wanna add one point here right uh if you create this scoping right all your automation of indicators results compliance scoring right you know policy attestation and compliance or risk scoring all those becomes much simpler if not you end up creating a lot of new reports right servicenow is built around that so basic foundation is right then all the automation will be much easier great all right so outside of entity any other questions related to grc in general that you guys may have from a customer perspective while we have the two resources on the call all right any other last words record jogging about um anything you wanted to cover or any um words of what wisdom or advice that you want to par uh relate to the t to the customers that are listening as well as possibly on the line right now sure right you know my our philosophy is you know start with one or two use cases sometimes what happens right you have a tool that is purchased or you have access to you may not be you may be starting with only one use case and sometimes people think that servicenow is all about ide and itsm it's not true right it is it is beyond that we are also working with a lot of other you know kind of businesses if you will and gsc is one of them where we are you know thinking of lot of different use cases you can start working with businesses either internal audit it can be compliance team or risk team do not restrict your use case only to it or it department or you know security kind of discussions that's one use case one thinking second thinking is we have a lot of something called better together use cases right if you want to tie up with checkoffs or idsm or you know cmdb there are a lot of automation that can happen using grc you know happy to discuss that we also have you know other products that is available in grc and the risk management i know that this uh situation what we have in the world today is not that great but you are depending lord on vendors we have vendor risk management product that is available we've required one of this conversation we can have some of the discussions that are challenged right on windows risk management we also have business continuity management that is available if you will if you're interested and as we discuss regulatory change management that is one of the bigger discussion that's happening in the world where you know you are not able to cope up with all the changes of regulations requirement that's happening within the government or based on your business to manage that we have regulatory change management that is coming up and end-to-end use case of grc grc can be used for multiple use cases and even vendor management is sometimes i don't know it's a kind of a although the word vendor management is you're trying to manage vendor risks but sometimes what i've seen people are using for different use cases like you know if you're let's say that's going to happen you're getting assessment of those potential mnda that also can be done using either using vendor management or you know grc tools so do not restrict from one use case start exploring and that's when our team comes into picture where we want to brainstorm with you and you know if you have some specific use cases service now all about automation and utilizing you know all other parts of service now it can be cmdb sac ops hr csm so a lot of you know item those kind of uh thinking those kind of data that can be automatically used within service non-grc and we have things that are available and things can be automated the whole idea of jios is to make sure that your life is simpler for compliance and risk and will help in a lot of automation perfect all right if there aren't any other questions or comments or any concerns i think we could actually adjourn early i will provide the recording to everyone post this call i'll still have copies of the powerpoint act that was shared and also too we'll provide a link as soon as zoom provides me with recording i'll send that all out to you guys so thank you all so much for your level of participation and all those who are listening to this recording thank you guys for listening to that as well let us know if you have any questions thank you john thank you as always um take care everyone thank you thank you thanks guys thank you
https://www.youtube.com/watch?v=Rrjz_3B2K3Y