Building a Governance Framework with Policy and Compliance
hey everyone today we're going to walk through how to build a governance framework with servicenow's policy and compliance management application within servicenow's integrated risk management suite there's a number of different applications for things like regulatory change risk management cyber risk enterprise and operational risk internal audit operational resilience and so on today we're going to focus on policy and compliance which is essentially maintaining a a library of policies and controls where policies get published to a portal and are easily accessible to anyone within the organization who should have access there's four primary workflows that stem from our policy library the first one being our annual policy review cycle to ensure policies are kept up to date the second workflow being our policy acknowledgement campaigns so employees can attach the policies once a year or whenever their significance changes the third workflow is for policy exceptions and then the fourth workflow is geared towards connecting policies to controls and control framework requirements such as satu iso 27000 pci and this process help team essentially store control evidence for certification audits so that you can efficiently demonstrate to external auditors regulators that you have strong supporting policy documentation in place to support your internal controls so really the uh four steps to building a framework are first off establishing your entity structure which might consist of systems applications processes we then identify which regulations which stand which control frameworks are applicable to the business is it pci iso sac2 fedramp we then define our review and approval workflow and then lastly once the policies go through our review and approval workflow they get published to the knowledge base so that they're easily accessible to our employees so let's go ahead and take a look uh if i open up the compliance management workspace here's a really a purpose-built landing page for compliance managers risk managers policy owners what i'm actually going to do before going through the details of our workspace i want to switch over to the employee portal so i'm just accessing the system is james vitolo a regular employee and this is where they can log into a nice user friendly interface to perform a wide range of tasks to really help them with their their day-to-day work so it's all built on service now and includes tasks like booking time off completing their employee onboarding tasks for new employees requesting access to new applications or ordering new hardware attesting the policies that have been published within our our global policy library and then completing a number of different tasks for grc as well as things like you know setting your goals for the year so really a one-stop shop where employees can perform a wide range of different tasks if i switch back over to the compliance workspace this is really our home screen which has purpose-built dashboards showing our compliance towards different control frameworks so we can see our percent complete against fedramp iso 27001 pci similar metrics for policies so you can see your total compliance score total number of high priority issues for different policies compliance per entity and then other metrics tracking things like control tests so are these controls operating effectively key control indicators control attestations for things like sarbanes-oxley you typically need to do that quarterly if we open up the policy library i have access to all policies with the the user i'm logged in as so i'm just going to open up an example we'll take a look at this acceptable use policy now the policy has different tabs so there's quite a bit of information associated with this policy on the overview tab you can always see which step you're at in the life cycle so if you're going through the annual review cycle this policy has been published to our portal we have more dashboards highlighting key performance indicators and key metrics for this individual policy and then over on the right hand side we have some contextual contextual information so this policy is related to the different control frameworks again pci iso and so forth the details page shows us the high level information for this policy so really things like name type which state it's in uh we can also assign ownership to this policy so who's the approvers reviewers when's this policy valid toll and then we can automate the cadence around our acknowledgement campaign or a review cycle so that instead of having to kick these off manually you can genuinely set it and forget it and have the uh kind of annual review or in this case the acknowledgement cam campaign kicked off uh once a year i mean the system can send out those notifications based on whatever frequency you set we then get into this policy text now this is a fairly new feature in servicenow this is a native microsoft onedrive integration and what this actually allows you to do instead of attaching policies as a separate file which requires you to kind of download and re-upload the policy every time you make changes this native onedrive integration just saves those changes real time it allows multiple people to to redline a policy simultaneously just like they're working in microsoft onedrive changes are auto save so there's no having to download and re-upload the file every time you make changes um and then last thing here you'll see this will include the latest changes you have full version control so you have a full revision history which shows every single changes that made to this policy um so pretty big step in um creating a more efficient review cycle for your policies you then have a history of all review cycles so this history tab just shows us um if you know if we're doing an annual review once a year you can always see the audit trail to uh show those review steps and then uh control objectives is where we can make the connection from policies to our internal controls so this policy is connected to three controls one of those being manage change requests and then if we actually go to click on this control which the policy is associated to this control has 10 different citations so you can see the list here nist 853 iso 27001 so by virtue of testing and collecting evidence for this one control we're actually meeting uh ten separate control framework requirements so this connection point really gives us the kind of the logic of test one control and satisfy multiple requirements gives us a much more efficient um certification auditing cycle and really reduces audit fatigue internally so we're not sending control owners repeat requests for the same documentation it's really a key piece to establishing a governance framework and servicenow that really concludes our our presentation i hope this has been useful in any questions please do let us know thanks everyone bye
https://www.youtube.com/watch?v=cX62ciSAeZo