Managing the Policy Lifecycle
you should be able to see a compliance management workspace we're going to go through the policy and compliance solutions within service now we will be going through the new san diego environment now to get started we are going to start first and foremost with policy so i'm actually going to pull open a list of all of my policies i'm going to focus specifically on my acceptable use policy that's the example that we're going to walk through today so i'm actually going to filter and find my acceptable use now when i click into this record it's going to bring up the record the details of this particular policy so we'll start off on our overview tab now with our policy management solution we do have an out of the box workflow to help identify establish and maintain your policies you'll notice highlighted in the middle of my screen here is a state overview with five different stages so i'm currently in draft stage for this policy on my details tab i will have some high level information about this particular policy maybe a description what we're trying to achieve with this policy if there is a parent-child relationship or a hierarchy within your policies we can establish that here but this is where i can also start to identify who's going to be responsible i can start to establish a review cadence for this as well you'll notice this particular policy is valid um actually just until the end of the month that way when that due date is approaching or that expiration date is coming up the system is going to automatically identify that it needs to go back through a review and approval process now from here i'm going to move to our policy text tab so this is actually going to be a new function functionality that is available within san diego so within our san diego release we do have an integration with o365 and onedrive to enable better drafting and redlining experience for developing policies so here you see an integration with 365 and wardrive i've got my acceptable use policy pulled in i have all of the details documented out and you can see that we're actually going through some redlining capabilities right now so i have a couple areas that are commented out i have a couple comments that are added in really enabling that experience to get better back and forth conversation between the contributors to this policy enabling all that centralizing it within servicenow before we go through that review and approval process so we do have that ability to sync with word again enabling that commentary that redlining etc now this policy is currently in a draft state so before it gets published there's not too much we can do by way of compliance we want to make sure our policy is drafted approved published before we start establishing controls related to it but what i'm going to do from here is actually come back to my list view and i'm going to open up another acceptable use policy that has been completed and has been published so in this particular example you'll notice it's actually gone through all the stages of the life cycle and we're currently in that published state again the reason being once it's approved we can then start doing things like sending out policy acknowledgement campaigns identifying control objectives that need to be associated and starting to monitor compliance to those policies all right this policy is now in a published state once our pub policies are published we want to start to break it down into actionable items meaning what do we do to implement this policy across our organization how do we go about establishing it to the appropriate parts of the organization that need to comply with acceptable use and we do that through control objectives so here you'll see that we have a list of control objectives control objectives help us realize how we're going to implement these controls throughout the organization you'll see here that there are four control objectives this particular policy is broken out into and we're going to look at this particular one establishing and maintaining an acceptable use policy now our control objectives are where we start to establish compliance guidelines throughout the organization and where we can start to understand what is our compliance posture so we do have out of the box integrations with the unified compliance framework the ucf you'll notice that in the upper left hand corner here my source is indicating that ucf integration if those sources are elsewhere partner implementations or or uploaded from your own internal listing of control objectives for example that source is going to be reflective of that now on my policies tab we're going to be able to see specifically where this particular control objective is tied to and you'll notice that um the policies that this control objective is tied to is that acceptable use policy so the one that we just came from so you'll notice on my citations tab that there are a variety 13 actually different authoritative sources that this control objective aligns with now when i say authoritative sources again it's that external driver for your organization external guidelines frameworks laws and regulations here we can see that the control objective of establishing and maintaining an acceptable use policy is tied to things like nist 853 hipaa pci iso 27001 etc all these different authoritative sources specify some detail around acceptable use so we here we're showing where that overlap exists and specifically where it ties in to all of these different areas by showing this overlap when we go to test this control throughout the organization we're going to use the compliance results and map it back and show compliance for all of these different sources so we don't have to test controls for each one we don't have to go through and test for pci or test for hipaa and then test forness and iso we want to do a test once comply with many kind of mindset and really this overlap or listing of citations mapping here is identifying where that overlap exists now we're going to take a closer look at the control for our i.t department so i'm going to click into this top level control and this record that pulls up again is going to tie specifically to implementing or establishing and maintaining aup tied to rit department i'm going to move on to our details tab within our details tab we're going to be able to do things like identify a specific control owner again going back to assigning responsibility resigning assigning ownership and accountability you'll notice if i scroll down here under my assignment group this particular control is assigned to a gentleman named able tutor and we have an attestation that's associated to a grc attestation now again you'll notice this particular control is in that draft state but we're going to go ahead and move it to an attestation state so we're going to create an attestation now for the purposes of our demo i'm doing a manual creation but part of the workflow is really we want to set up a regular cadence to review our controls and to attest to them that might be a quarterly attestation maybe it's biannual once every year the frequency is really um it can be configured it's going to be driven by regulations and your own internal uh kind of desires but um you can set up that workflow to help reassess on an ongoing basis reassess on a regular basis and you'll notice that one attestation was created and i've got that indicator for it so those attestations are really great for things like quarterly reviews biannual reviews or yearly reviews but in many cases we want to have a more current and up-to-date picture of our compliance posture and that's where indicators are going to come into play so on my indicators tab i have an indicator established indicators really help us establish continuous monitoring practices so one part of this control is making sure that we do have aup established acceptable use policies established and our policy and our attestations help satisfy that requirement but we might want to take a more active approach of monitoring whether or not our employees are actually following our acceptable use policies and that's going to help us get a clearer picture of how effective the aup is that's where these indicators come into play now i'm going to come back to my control objective so we saw in my overview tab i was in a non-compliant state if i come back to my control objective we're going to see on my controls tab that i now have a non-compliant status for this particular control so of the three that have actually gone through testing two are non-compliant one is compliant now that compliant and non-compliant status gets reflected or aggregated back up to the control objective level so here on my overview tab i can see that the overall compliance rating or status for my objective is sitting at 33 one compliant out of uh three obviously 33 compliance this status overview provides an ongoing picture so as those control attestations get generated as those indicators go through and get updated that's going to move your controls from a compliant to a compliant or non-compliant state and then of course that gets aggregated reflected back to your control objective level looking at policy and compliance that's what i wanted to touch on today
https://www.youtube.com/watch?v=tI_aTeFEyBY