TechByte - What's new in Quebec - Integrated Risk Management
hello and welcome to it workflows techbyte let's learn a little bit more about what's new in quebec for integrated risk management my name is adelina richards i'm a solution consultant here at servicenow specializing in integrated risk management let's start off by taking a look at integrated risk management as a whole here i'm able to see all the different applications that are listed under integrated risk management throughout the course of our presentation here today we're going to talk about the updates to each and every one of these different applications we'll also talk about some new applications we've added in quebec such as regulatory compliance and operational risk so let's dive a little bit further and talk about those different updates first we'll run through operational resilience management with increasing operational risk from pandemics and extreme weather resilience is top of mind for business leaders servicenow operational resilience management interprets risk compliance and operational insights from throughout your organization into a single pane of glass for continuous management of changing risks using a new role-based dashboard critical notifications can be sent to employees via multiple channels collaboration with the crisis team is made easier and the details of the recovery are adequately tracked next let's run through regulatory change management in its simplest definition regulatory change management or rcm is the management of regulatory policy and or procedure changes that apply to your organization for your industry in today's complex regulatory landscape organizations are constantly on their toes keeping pace with the new regulatory developments and associated risks the enormous fines levied for non-compliance can cause a dent in any organization's finances and significant reputational damage this has led to a growing emphasis on having a robust framework to manage regulatory change our servicenow regulatory change management solution enables organizations to proactively manage regulatory changes to keep pace with today's ever-changing regulatory environment with constantly expanding obligations integrated with servicenow's risk and compliance applications it can help map the external regulations to an organization's internal controls and processes next let's run through the new cam or continuous authorization and monitoring features for nist rmf addressing security risk is a common challenge for almost every organization inadequate security measures lead to breaches loss of data reputation and customers for the federal government this could mean classified information that could put our people or nation at risk standardizing on a formal framework is one of the best ways to address this risk the servicenow continuous authorization and monitoring application was designed to address the requirements of nist rmf and other risk frameworks such as nist csf gsa fedramp etc cam automates painful processes enables risk informed security decisions with better visibility and improves the accuracy and timeliness of information resulting in faster time to value cam has a number of different features available this will include being able to define an authorization boundary with real-time infrastructure data having common controls and control inheritance defining an authorization package and automating the creation of poems now let's address overall updates to the irm products we'll start with issue triaging a critical measure of the effectiveness of any organization's risk management program is how quickly and completely it identifies and takes action to address its risk and compliance issues issued triage workflows enable customers to report and process risk and compliance issues coming from business users employees and other automated failures the goal is to eliminate noise consolidate duplicate issues focus on what's critical and exposes the organization to the greatest risk identify and prioritize remediation actions identify new issues across business operations and analyze operational weakness in policies processes and controls now let's run through issue grouping and remediation using ai and machine learning when you are creating an issue you now have the option of grouping it with other similar issues grouping issues under a parent can save you valuable time for example let's assume you have an issue related to patching windows servers since each server is a separate entity all controls associated with windows servers should be patched every tuesday will have the same issue therefore the issue can be resolved once for all of the windows servers by applying the relevant patch one time reducing the time spent and finding similar issues to be grouped leading to a faster overall resolution remediating an issue marks an intention to fix the underlying issue causing the control failure or risk exposure you can now use machine learning to predict remediation tasks that might apply to your current issue using the suggested remediation task button now added to all issues overall we're making issue management smarter we're allowing our employees and automated business rules to create specific issues ai will then predict the assignee and similar open issues to be grouped together an owner will then review the issue make any modifications needed ai will then predict similar remediation tasks your owner will then review the suggestions and initiate those tasks to users those task owners can complete their tasks and your owner can review the tasks and then close the issue once all those tasks are closed that's going to allow us to focus on three key outcomes we're going to have faster remediation of issues optimization of all of our different resources and improve our employee experience when they're handling issue remediation lastly let's take a look at evidence requests from first and second line users starting in quebec unplanned evidence requests are now supported by audit management and policy and compliance management this will help the second line and third line of defense to create and send all their evidence requests quickly you can run through this workflow either on that compliance side or on your specific audit engagements to request your evidence and then to submit that evidence and tie it either to those controls policies or engagement records now let's dive into advanced risk we can manage digital risks of business applications easily by integrating grc with business applications using application project management by integrating you get a real-time insight into the digital risk posture of business applications have improved communication between application owners and it risk managers and overall reduce that workload now let's run through project risk management similarly we can integrate with ppm or project portfolio management to identify project level risks as your organization grows it is important to perform risk assessments of your specific projects because each project is unique it is important to customize the project risk management process according to that unique project and its requirements lastly let's run through that operation risk dashboard the operational risk management dashboard enables you to view the complete risk posture for the enterprise in a single consolidated report this dashboard makes it easy to analyze the risk posture efficiently and take necessary corrective actions to ensure that there are no losses that we've run through advanced risks let's talk about vendor risk management in quebec each third-party risk score provider can now have multiple scoring services each scoring service can have a set of number ranges in ascending or descending order or have a set of ratings third party scores are automatically mapped to the normalized scores and the normalized ratings and vendor risk management giving you an overall risk score for each and every one of your vendors furthermore we now have training available for your vendors in terms of learning how to adopt and use that vendor portal we're also able to create different issues based off of specific answers to different questions to those risk assessments that you might want to send out to your different vendors so in this way we can create different indicators that will automatically open up specific issues and notify those vendor owners or vendor managers that there's a new issue on their particular vendor the quebec release will also include a technology controls accelerator you'll be able to monitor technology controls using predefined automated script indicator templates and monitor compliance status of controls and related issues using reports the technology controls monitoring accelerator is a collection of predefined indicator templates designed to ease collection of data and aid validation and continuous monitoring of technology controls this application can be run with the cyber security controls accelerator or as its own standalone application the indicator templates contained in the technology controls monitoring accelerator are linked to specific servicenow applications to allow compliance validation for standards and frameworks such as iso 2701 iso 2702 and different cis controls so now let's look at advanced audit so we have a number of new features under audit which are going to include the audit universe creating and improving annual audit plans audit engagements with basic cost and resource plans audit engagements with project management integrated with it tracking milestones and observations so let's talk about audible units we're able to link specific audit units to our cmdb so we can take a look at things like business services different parts of our organization etc so that we're able to assess risks of each audible unit next we're able to create and approve annual audit plans so you can see we're able to build out an annual plan in terms with our overall audits so we're able to set up audit engagements that'll be included in each annual plan scope out those engagements based off of risk-related audit universes and optionally create detailed resource and cost plans throughout this annual plan now we can integrate with ppm or project portfolio management to look at things like resource and cost management when we're planning out our overall audit engagements and that annual plan that we just took a look at we're able to have specific milestones to track our different audits so we're looking at these different milestones we can set specific dates and then tie it back to our overall project plan then we can add in specific tasks that we can automate to get to those different milestones lastly let's run through different observations in relation to audits we now have a single entry point for end users to report a compliance or risk issue from the service portal then based off of various questions issues can be identified as compliance issues or risk events we're then able to go ahead and track reportable observations as audit issues and assign an issue owner after that we'll implement a specific action plan and if we follow that action plan hopefully we'll be able to close out that issue and send it back to our auditor for review next let's run through updates to policy and compliance firstly we're able to associate one indicator template with multiple control objectives or risk statements we also have a number of different updates for policy acknowledgements so we're able to set up the frequency for acknowledgement campaigns per policy schedule those campaigns automatically based off frequency we can send out tasks to new added users for an ongoing campaign we can extend that due date for those new users we can also cancel acknowledgement tasks for users who have been removed from an audience for an ongoing campaign lastly we're going to be able to provide warning when a policy has been retired and then that associated campaign can be cancelled the last application we're going to run through in our presentation here is updates to business continuity management servicenow's business continuity management solution allows you to plan exercise and recover as an enterprise we have now re-platformed bcm as per now standards so it'll look very similar to your it agent workspace in itsm pro you're still going to be able to take advantage of all of the benefits of bcm you're going to be able to create business impact analyses to identify critical processes analyze the recovery objectives based on the different impacts and create and maintain business continuity and disaster recovery plans overall you're going to be ready in case of a crisis event thank you so much for taking some time to learn a little bit more about those updates for quebec for integrated risk management if you have any questions about what you just saw in our presentation here today please let your account team know and be on the lookout for new updates to integrated risk management
https://www.youtube.com/watch?v=egSMqOzNbI4