logo

NJP

Why GRC Leaders Are Moving to Integrated Risk Management in ServiceNow

Import · Mar 25, 2021 · video

all right let's go ahead and get started so welcome everyone we're so glad that you could join us today with you today you have myself jake ellsworth i'm kovestic's business development representative and i will be your host and facilitator for this session i'm joined by eric smith irm servicenow platform solution consultant and mike deandre grc advisory solution architect and before i hand it over to them i have just a few housekeeping items to get us started to begin if you have any questions throughout the presentation please post them in the chat box i will be monitoring the chat and we'll bring these questions up for mike and eric to answer as we go along please also be on the lookout at the end of the session for a quick survey on what topics you would be interested in us covering in the future next the presentation will be sent to you following our session today you can expect to see that in your inbox within the next couple of days and it will also be posted on our website within the next 24 hours and lastly if you have any questions following the session please feel free to contact myself eric or mike directly our contact info will be listed on the final slide so to kick things off i'll give you a quick rundown on covestick we're an elite servicenow services partner and began working with the platform in 2012 developing expertise across many areas of the servicenow product set something that truly differentiates kovestic from our other partners in our space is our focus on customer success not just as it relates to a given project but your servicenow instance as a whole in other words we don't just focus on the technology being implemented our consultants take the time to understand your goals people data issues and processes that drive successful outcomes we also stick around after implementation pretty often to help our clients run their servicenow environments in different capacities so there's a quick introduction to govestic and without further ado i'll hand things over to mike and eric to get into the good stuff thanks again for joining us today folks eric take it away thanks jake so a couple things that i'm really proud of that i want to point out that aren't on this slide one we don't try to be all things to all people on the left you see the areas we've specialized in we take that very seriously that's where we invest that's where we grow that's where we focus we don't try to you know lean over our ski tips and learn on your dime and also ninety percent of our customers come back i think that's really unique uh no i know it's unique uh and i think it's a product of everything you're seeing here so as jake mentioned i'm the irm's uh platform solution consultant i also run pre-sales at covestick i've been working on servicenow for 11 years now most of that time as a solution architect and business process consultant and most of that on the grc application within servicenow before that got about a 15-year it career and that was in healthcare and financial services two highly regulated industries so the way i say it i wasn't the grc practitioner but it was definitely a subject to it so you know i guess i've been lucky to avoid that but i'm also lucky that i get to work with someone who has been a grc practitioner so mike if you would give yourself a little bit more of an introduction uh yes uh sure uh thanks eric and jake um really uh really appreciate that um so indeed i've i've been a grc practitioner for many years and we'll be talking a little more about that here shortly but currently i'm the grc advisory solution architect here at cavestick and what that really means is that i use my experience as a practitioner and a long-time compliance manager to help customers and potential customers of servicenow to better understand how they can get the maximum value out of the irm suite outstanding so i've wanted to tell this story for quite a while uh one compliance manager story why they chose servicenow for irm and what happened with it and and that's you mike um you know that uh you and i have been working together for a long time and a lot of different projects and what i find is that customers always love having on their project it's it's almost like they can sense that you've been in their shoes and you truly understand the challenges they face now i know your story but today i'd like the audience to hear it firsthand so let's talk about your background your experience in grc and why you've been such a proponent of servicenow for grc sure okay thanks again eric uh well it all started with socks uh shortly after the uh sarbanes-oxley act became law i was hired by ew scripps uh the newspaper conglomerate uh to work with their id department their i.t department their internal auditing team and various business units to help try to figure out just how we were going to comply with sox and since the company owned like 20 different newspapers as well as 10 television networks this was a you know it's a pretty monumental undertaking and we only had about a year to do it to design implement and to document all the required processes and to put in place um an effective uh system of uh internal controls yeah i i remember those days it was just like hipaa it seems like socks happen really quickly it did and it immediately became a business imperative non-compliance with socks was not an option and and it's still not an option so while we were designing our compliance processes we were simultaneously trying to figure out what tools we you know we were going to use to implement those processes and of course you know how it goes we ended up using whatever tools we had on hand and these were mainly general software tools like excel and uh word and sharepoint so yeah i think i know but you know tell me how did that work out for you well somehow we actually managed to pass our first audit which was a good thing but in a sense it was also kind of a bad thing and here's what i mean because we passed our audit the tools we were using those generalized tools were perceived as being sufficient when in reality it was exactly those tools that were making our processes uh so labor intensive and inefficient and this inefficiency it really placed a very heavy burden on everyone involved so the burden of compliance on the i.t staff the auditors and my staff was absolutely huge so if i can kind of play that back the process you designed they were effective they got the job done if you will but they weren't efficient exactly so you know we ended up continuing uh to operate that way relying on these tools that you know they were kind of air prone so we had to take a lot of care had to be extra careful and we we continued operating that way until ew scripps decided to spin off their tv networks division and as you can imagine that was another really monumental undertaking we had to split out the it infrastructure components supporting the tv division from those supporting the newspaper division and this meant like you know commissioning decommissioning and repurposing hundreds of servers and other components and while we were doing this we still had to make sure that both companies the old and new uh were stocks compliant and ended up after split i ended up going with the spin op scripts networks interactive which i think most people recognize today by their uh tv network brands uh hgtv food network diy travel channel and a few others and they've since been acquired by discovery communications so you went with the spin-off what was your role in um i became the enterprise i.t operations compliance manager which meant i was responsible for ensuring the i.t organization remained continually compliant not already with all applicable laws and regulations not just socks but you're still relying on all the old technologies you kind of described right yes at first but fortunately the company was hugely successful and as it turns out uh and as it came into its own budgetary restrictions started to relax and the it division started looking around for you know more modern itsm solutions and i simultaneously started looking around for grc solutions and you know it took a while but the it team they eventually narrowed their search down to remedy and i narrowed mine down to um really just a handful of dedicated grc point solutions like archer and metric spring and i have to tell you uh some of those point solutions were very attractive and had a lot of nice features and a lot of bells and whistles but you know while they were really nice to have there were a lot of them that i i just didn't see how i would use those those extra features but the main thing that really kept me from selecting one of those tools was they didn't really align well with our processes and our processes had already proven to be effective yeah and i know you know this but you know when we display some of these platforms we see that a lot um you know a lot of those great whiz-bang features wind up being shelf wear so you know if i can keep on that train of thought though tell me you know there was a concern it sounds like about becoming less effective by by going to a more modern solution walk me through that yeah that's i know that it sounds kind of funny when you put it that way but but remember this was uh socks and compliance we're talking about here where non-compliance could cost the corporation millions of dollars in fines and violations could actually land the corporate officers in jail and any i mean absolutely any unsatisf excuse me unsatisfactory audits could really plummet the valuation of the corporate of the corporation and it's a stock price uh people could you know people could lose a lot of money so sox compliance was really nothing to uh to mess around with yeah so what did you wind up doing well i got lucky uh servicenow which was the new kid on the block at the time they showed up at our door and uh they were competing with remedy and they actually had something new and different uh they had a platform solution that actually had both itsm and grc and they were already integrated the integration was built in out of the box so you know i took a closer look i did a deeper dive into the the grc module and when i was playing with it it was like wow um the servicenow designers it was like they had been peeking over my shoulder when they designed it it maps so well and so closely to um to our existing processes so that that's when you decided that's it yeah you're done it has to be serviced now i did well i should say we did because the rest of the it division was having you know kind of the same experience evaluating the itsm modules so we went with servicenow we became a servicenow shop and we migrated all of our compliance processes into at that time it was called the the itgrc application and in fact i learned later that we were the first servicenow customer to migrate a full-fledged sox compliance program from largely legacy tools and manual processes into the uh servicenow grc platforms so once you did migrate did it did it live up to you know your expectations was it still that over the shoulder experience you described oh my gosh yes what a difference let me tell you uh we leveraged all the built-in automation features of servicenow you know we automated everything we could we we automated scheduling of control tests we automated uh pulling records for the control owners to review we automated the periodic review of our policies our procedures and controls designs and even our testing procedures to make sure that they were always current and we automated control activation and deactivation with the commissioning and decommissioning of servers and what what else oh reporting we automated our quarterly sox 404 reporting which was required by law and with all this automation i have to tell you my life as a compliance manager became a lot easier and a lot less stressful nice but you know tell me um efficiency wise and i know that was a big focus uh did you get all the efficiencies that you're looking for yes definitely we got everything we expected that and more i have to say we we we got all all those gains while really maintaining our effectiveness and so while we had always passed our audits we were now getting even higher audit scores we were getting very high audit scores and because all the information the auditors needed to plan and to conduct their audits was at their fingertips as well as at our fingertips these other durations were drastically reduced for example previously audits took months to complete and since we were audited at least quarterly those audits often overlapped which if you've been through a lot of it you know that can be a nightmare but after going to servicenow artists were now reduced to taking weeks to complete rather than months and um uh speaking of audits i know it comes next and this is my favorite part i don't want to give it away but um something really unique happened to you that following year right tell us about that yes so okay so one day i'm sitting in my office when i get a call from the ceo asking me to come over to his office so i go over and as i'm approaching the office i see most of the c-tier execs the ceo cfo cto cio and they're all standing there and like i don't know what to think so i go in and they start applauding then the cto hands me an award the annual scripps chairman's award along with a nice little bonus check and the attorney and the the chairman's award it read for innovative process improvements having a positive impact on the corporate bottom line so as it turns out and i hadn't really been focused on this but by migrating to servicenow we had not only enhanced our operational efficiency but had so drastically reduced audit durations and therefore the associated costs and you know audits are expensive right that the cost savings actually showed up as a small but notable improvement in corporate profits so who knew you know my focus had been on process efficiency on making everyone's lives easier and i had never really thought too much about the overall effect this was having on the company's profitability i love that story it's like a career changing event it was uh so over the next couple of years and i think this was because of the efficiencies we gained when we went to servicenow we ended up taking on more responsibility i got involved in business continuity planning uh championed a new lifestyle learning initiative and then moved into the office of the cio and a few years later i was invited to go into consulting and you know i'll tell you i actually jumped at the chance because i wanted to help other grc managers to help them better understand how they you know how they too could get uh the maximum value out of out of the platform and over the years since i've gone into consulting it's been really exciting watching how the platform has grown and working with all the new irm applications like like they now have regulatory change man management and business continuity management which i wish i had had back then but i think what's still most exciting to me is seeing that the core grc function that i had personally leveraged so heavily it's still there it's embedded like the you know like an evolutionary backbone of the entire uh servicenow grc irm product portfolio yep it's um it's been a journey so mike thanks for thanks for sharing your story um i i do see some questions are coming in for mike and we'll be sure to get to them in a little bit but um first if we can you know let's spend some time talking about the grc approach servicenow takes if you will and uh we'll look at some common challenges some success stories and and how all that's addressed and you know you know bluntly there there are pieces of compliance and risk and resilience in every part of your organization and they all cut across silos you know and unfortunately the silos are there because the the reality is that not many organizations are very connected uh there's bits and pieces everywhere there's some that are connected there's some that aren't and you have to rely on all this to stay in a good posture compliance wise to have the efficient audits like mike described and if you're if you don't have something breaking down those silos what you do have are high costs poor decisions and ultimately business disruptions so mike does that that previous state does that sound familiar to you absolutely and one thing i'd just like to add is that uh you know talking about breaking down the silos uh compliance actually can help drive that because uh compliance when you need to comply with the regulation um that that's the responsibility of everybody in the organization so it kind of transcends silos and we've often seen you know eric you and i have often seen that it's pretty common for different department managers to really want to know how other department managers are meeting a requirement you know what they did to comply and so this often you know it facilitates that communication and corrupt collaboration and cooperation between departments so kind of you know helps helps knock down those silos the barriers i love that it's not just about the people yeah i'm sorry it's not just about the process or the platform rather it is about the people and and you know this is almost like a forcing function to get the people talking who maybe haven't before and get their assistance communicating well you know unfortunately today uh it's not just a conversation that we have to have about silos you know the the reality is that enterprises have a lot on their mind right now um you know covet is causing massive disruptions huge disruptions it's changing a lot of things it's moving a lot of things it's bringing you know buzzwords like digital transformation into the now uh where it's not just a like to have it's an imperative but this isn't the first crisis you faced and you know it's not the first risk or disruption you've faced uh you know pandemics extreme weather regulatory change cyber security threats and all their myriad flavors and you know their their accelera their accelerating prevalence they're all risks to disrupt a lot of things to really you know stop you from doing your day job so to speak but you know during challenging times we all know that keeping your customers delighted is super important job number one if you will but making your team's work less challenging less painful that's also critical and that's kind of where you know servicenow irm comes in you know especially as it's matured from uh you know it's early days it's just kind of a simple grc ticketing platform if you will i'm quite honestly thankful that i've been a part of servicenow's grc journey you know in the early days that's really what it was it was just pretty basic tasking with some good data support i remember um probably about 2012 or so i helped oil field services company implement implement a risk management solution in servicenow and it worked it did what they they needed you know ticked all the boxes if you will but it was it was very basic but now servicenow irm is something unique uh it's it's cloud-based uh shares data across the enterprise and it's also easier to implement it's easier to use it's easier to configure and maintain than all the other uh legacy solutions and point solutions like microreferenced it's also become an engine for ensuring risk and resilience are incorporated that those disciplines are are a part of business processes and that's that's where it's become more you know integrated risk management versus just basic grc uh it's also you know just staying in servicenow world for a moment it's better together with other servicenow applications you know not just it service management like like mic reference but it operations management customer service management uh having a good knowledge base and having it readily adopted having a good user experience all those things are critical and they make irm better and irm by being around and being well implemented makes them better you know and as the industry transitions from grc to irm you have to have a truly integrated system that uses a shared database to enable that data sharing across the entire enterprise servicenow also it enables continuous compliance so unlike other solutions servicenow can scale to detect changes in real time uh all without impacting service you know system performance or services to your your end users and also compared to all the legacy grc platforms uh servicenow has a lower cost of ownership and it's just bluntly easier to configure and you don't have to take our word for that you don't have to take servicenow's word for that gartner and forrester have said the same and it seems like every year uh servicenow creeps a little bit farther up into the right in both of those magic quadrants for integrated risk management so let's look at servicenow kind of head to head with some of the alternatives you know legacy grc tools uh the point solutions if you will they weren't designed for the frontline employee so what that causes is risk isn't top of mind for anybody but the risk and compliance professionals you wind up with a lot of isolation both process tasking data across the board and it leads to a lack of transparency and without that engagement from frontline employees from the business if you will you could expose the entire organization to regulatory failures and you know you you wind up executing on an incomplete picture of the overall risk posture and then also what we see a lot is what i call spreadsheets and hope uh bluntly we we actually see it quite a bit manual processes um that initial state that might kind of describe using excel spreadsheets or you know old databasing tools or microsoft word or you know sharepoint kind of cobbled together for a solution that doesn't scale it doesn't move quickly enough it doesn't break down the silos servicenow does what servicenow also gives you is level three automation i'm going to tell you what that means so if we look at level 1 that's bringing silos of unstructured data and information together and giving it some structure and that helps you know as an example let's say a compliance attestation cycle takes 10 weeks well maybe you get that down to seven or eight weeks level two the driver is bringing the people together and driving some consistency behind process and taxonomy and and that's good too um it's it actually moves the needle you know now an attestation cycle that took 10 weeks might take five to six weeks that's good but it doesn't change the game if you will um it doesn't get to some of the uh great things that mike talked about with you know when he said we automated this we automated that we're automating everything um that's that level three automation that servicenow can bring and now you're bringing the systems and the machines together to eliminate the need for humans to be involved in repetitive tasks you just grab the data infer from it what you need to for your controls and move on get it to the auditors and move on etc uh and now that attestation cycle that took 10 weeks it's automated it could take a minute um and of course you know missing all this is level zero and that's having nothing beyond that spreadsheets and hope land and unfortunately that's a situation a lot of companies still find themselves facing so if we can look at this you know kind of in a real world use case where all of this comes together let's look at a very typical use case sox compliance you'd identify your requirements and implement your controls and monitor those controls using policy and compliance and service now then you tie that to your compliance risks and regulatory risks using risk management and this is good because now the business knows what the stakes are they know how likely those risks are that we're defending with controls and also what they might cost the company if they actually are here their inner lab and now it's not a risk it's an issue and we have to do something about it servicenow helps you with that ties it back to the policy and compliance piece and then you have to demonstrate you know prove that you're compliant with audit um servicenow also does this very well not only the the tasking and the structure uh if there's an audit that's large enough to be run as a project that's right in servicenow if there's external data that that needs to be forwarded to the auditors that can happen in servicenow and when it's time for that next quarterly or yearly audit you can copy the last one apply some lessons learned and move on uh and then there's new stuff you know like keeping pace with all the evolving regulations new regulations changes to old ones using regulatory change management and all this is in one cloud-based platform that plays nice not just with grc professionals but also the business uh mike that did i leave anything out with that um i think i would add um we should probably call it vendor risk management um you know vendors introduce risk right and if your vendor isn't compliant then in many cases you're not going to be compliant either so in servicenow vendor risk management really integrates well with the policy and compliance application so that you can tie you know for example you can tie questions in your vendor assessment questionnaire your risk assessment questionnaire to internal controls so like if a vendor doesn't respond to a question the way you expect it then that control the corresponding control for that vendor can automatically flip from compliant and non-compliant and generate an issue so you know this that integration that ability to connect between your assessments and your control environment it really tightens up your compliance program to ensure your vendors are complying with your requirements yep it's like you've you've told me you know if a vendor brings a risk to your organization it's not their risk anymore that's that's your risk absolutely all right so uh key takeaways um you know that hopefully you're leaving with uh any process automation will improve outcomes you have to be planful and thoughtful you know as i've said before um you know automation applied poorly can just get you to a bad place better we're not describing that good automation but servicenow supports it uh enterprise visibility matters there's value in a shared database you know not the least of which breaking down some of those silos also the servicenow irm solution is evolving quickly and it's worth considering if you haven't taken a look at servicenow for grc irm in a while uh now's a good time uh you know let us help you out with that and also don't go it alone when it comes to compliance experience counts been there done that counts let us help what let us help with it you know if it's if it's the asset if it's a you know assessment if it's the implementation that's where i hope we're headed but also if you've already implemented servicenow irm and you kind of wonder what's next we're really good at that we have services such as developer on demand and also other managed services that can help you with the now what do we do we have solutions for that so jake uh with that let's take a look at what questions we've gotten in yeah sure thing so the first one we have here is for mike and the question is you said servicenow grc mapped to your compliance processes very well but other solutions didn't can you tell us what was different that's uh that's a really good question thanks for asking um to be candid i haven't really looked at those other solutions recently so i suspect they may have matured but i can tell you this i asked servicenow servicenow about this one time and they told me that when they are planning a new product they go out and do an in-depth survey and analysis of the industry and all their potential and their potential customers as well as their existing customers and then they you know they identify all those needs and then they set out to design their product to meet like 90 of those needs and so when they told me this i'll tell you it was actually kind of comforting because it confirmed that what we were doing um was really consistent with what most people were doing in the industries since our processes align so well with the servicenow product i hope that answers the question yeah yeah mike and if i could pile onto that one actually um it's almost like almost like they've been applying the pareto principle if you will the 80 20 rule um you know that that world back in 2012 where it was just basic tasking and it was pretty much just policy and risk um to where we are now i've heard customers clamor for certain features in workshops you know policy exceptions was a good example um external control sources was a good example and then you know six months later it's in service now and i've seen that consistently and you know servicenow i think has done a really good job of listening and giving back but not over tailoring so it only matches a few organizations yeah they definitely have their finger on the pulse of what's happening yep any other questions yep we actually actually have another really good question so the next one is uh you focused on socks but how well do those processes map to other laws regulations and processes another great question um well you know in my story i focused on uh socks because it was definitely our our number one concern but we also looked at it for scalability to other regimes in particular uh we looked at pci iso 27000 etc um but since uh going into consultant uh we've helped eric and i have worked on a lot of projects together we've helped a lot of customers to uh set up compliance programs to meet other regimes like nist 853 r4 uh the cyber security framework uh iso pci already mentioned but more recently the the privacy laws uh gdpr and the california consumer privacy act and um others and um well while they different they also share sort of a like a common base framework especially in the process for complying with those laws so like eric showed in the earlier stock slide um i was so the answer basically the answer is yes servicenow maps very well to other frameworks and uh compliance regimes cool uh jake was that did that wrap up the questions did we have some more come in uh yep that that did wrap it up perfect awesome guys well hey you sure did cover a lot of ground today and folks like i said at the top of the session uh we'll be sending a survey following and we would love to hear which process areas that you'd like us to cover in the future and as an additional reminder we'll be sending you a recording of this session and if any questions come to mind please don't hesitate to reach out to mike eric or myself directly we'll leave our contact info up here on the screen for just a second and if you have any additional questions you'd like to ask we'll keep an eye on the chat window for a minute but if not thanks again everyone and have a great rest of your day thanks everyone yes thanks for joining hey jake eric yes i'm back okay so we had a couple more questions come in sorry sorry i bailed out early i thought we thought we were all done um okay so there's a question around um uh how does servicenow handle a unified control framework to help with audit prep for new compliance and certification so uh there's a few options there and they all have their benefits and you know things to be aware of but servicenow integrates one example servicenow integrates with the unified compliance framework that's you know ucf uh and it has for a while to track you know frameworks regimes regulations all the controls of those comprise and changes to both that does require a you know external subscription but a lot of customers use it especially if they have to comply with a big broad set we've also seen it integrate with other tools like compliance forge there there may be a little bit of work to get that that connector set up but we've done that and you know compliance forge is a great tool for that as well and then also there's another option you can forego both of those and import your own controls or create your own controls and that there's certainly benefits to that too you have a lot more flexibility especially if you want to provide a an additional wording that's a little more business consumable and get that out to the business and if you go that route you can use the regulatory change management module which is new to help identify changes to those frameworks and regimes and keep up with them hopefully that answered that um and then it looks like yet another one jake uh if you want to fully utilize the irm and grc functionality of the search now offering what components modules etc are needed at a bare minimum i would say policy and compliance so that servicenow irm policy and compliance uh and you know what you can do with that is get your internal policies set up hopefully um they are structured in frame of some of those external frameworks reference those external frameworks and get the controls that are pertinent to you set up and then you can do scoping so this applies to this line of business this applies to uh this location this applies to these servers these databases etc a little bit manual but at a bare minimum that's what's needed now to me to be successful it is very helpful if you already have a configuration management database set up in servicenow so in that world you would have already been using servicenow for it service management or it operations management then you get to scope your audits and scope your controls to things that the business understands and maintains very much a nice to have a big success factor by no means required and then to pile on uh both mike and i believe that risk management really helps bring the business in because if the business just knows oh my goodness the compliance group is asking more questions or the auditors ask me for evidence oh bother why well if they see a risk you know that's well defined that has this percentage of likelihood of happening this year and if it does oh boy it's going to cost us a couple million dollars uh you know that's a big deal uh it can get the business a little more tied in it also risk management helps you decide what to focus on the way one of my clients said to me um and and i know this isn't for everybody but i'm going to say it anyway if there's a a law that um you know the fine for non-compliance is twenty-five thousand dollars i'm not going to spend a million dollars to address that it was a pretty parabolic example but it speaks to the types of things that risk management can help you do quantify those risks and understand which ones are going after which ones should be prioritized those size types of things that's at a bare minimum so let me return that policy compliance at a bare minimum some type of cmdb in servicenow i think would say that would be the next i don't want to call it a requirement because you can get by without it but it's it's a big success factor and then then you come up to risk everything after that is kind of gravy i hope you take it all down but that's the starter approach uh were there any other questions that came in after that jake i know it looked like that was it cool i am going to i'm going to actually bail now um for those who uh stayed on to help me uh ramble through those two questions i appreciate it again and um uh please send me an email if you've got any uh any questions or mike mike you know the way i say it is well i said at the top mike's our practitioner uh he's more of the business and process side i'm more of the servicenow technical side but i've already i also got a little bit of process savvy so um let us know i can help alrighty everybody thanks again and have a great rest of your day take care

View original source

https://www.youtube.com/watch?v=rDph0Ah_aJo