logo

NJP

What's new in Privacy Management

Import · Mar 31, 2022 · video

all right welcome everyone i wish you're coming in all right we've got some people joining us all right welcome everybody hello nice to see you all we'll give it another minute because people show up we've got a lot to talk about during our session so we're really excited okay i think we've got people are starting to slow down a little bit people will continue to join i think as we do as we go along but i wanna i wanna make sure we get things kicked off but before we get into this i wanna make sure that we cover a few things um you all will see the q a button at the bottom of your screen please please interact with us we are anxious to get your questions make sure this is is interactive and engaging and make sure that you know you come away with this understanding our privacy application a little bit better um this is going to be reported is being recorded so um please be aware of that and we've got a couple more people joining us but i think we'll go ahead and get started all right thank you all um i am here with um promote and we're here to talk about learning about privacy management which we're extremely excited about promo do you want to go ahead and introduce yourself yeah hello everyone um quite excited to talk to you all um promotions of our park management i handle privacy management with the service now and um yeah i'm glad to be here and talking about uh the new enhancements that you are that we have released just very recently as part of our san diego release so uh yeah quite excited to talk to you all wonderful and i'm teresa law director of product marketing and um i want to tell you a little bit about some of the cool things that's coming up so we in case you missed it it's out on the on the youtube right now on our ask the experts channel i will be putting a link to that channel in our chat here coming up but we just did our learn about risk management webinar and that was a really exciting full hour of information today we're talking about privacy management next week we'll be talking about vendor risk management and we're lucky enough to have one of our immigration partners join us echoladas um we are talking about policy and compliance management at the end of next week and then the week after we are scheduling our business continuity management um webinar so be on the lookout for that you can find all of these on our community and after the webinar not only is the recording up on youtube but it's also up on the community in the link to the event that you no doubt found this information on for this webinar so i think without further ado i want to see some of the product so promote i'm going to turn it over to you thank you thank you sir definitely i'm going to share my screen and then we'll get started yeah so as part of today's agenda we'll be looking at what is that we have released as part of san diego release right in the privacy management however a lot of things from a highlights point of view rather than going line by line i directly get into a demo and i'll talk about functionalities but before we jump into the demo what happened to the overall solution overview or how the entire solution over here got enhanced based on the new release that we just came out with right is what i wanted to show you and then with that context we get we will get into the specifics of the enhancements that we have as part of our santiago release as you see here this is the privacy management overview and the changes that primarily came in as part of this particular list is in integration with risk management right advanced risk management to perform uh or to understand risk posture in your in the privacy aspects assets that you're dealing with in your organization and if we just go through this particular flow on the left we start with the libraries right it helps you set up your privacy assessments be it a privacy impact assessment or legitimate assessment or data transfer related specific assessments right and risk assessments as well as maintaining your personal data repositories as part of your um as part of the kind of data that you're kind of processing within your organization all of such depositors can be maintained here as personal information part of information objects and then the privacy regulations that you're following citations controls privacy policies and risk statements that are specific to privacy aspects as such can be can be maintained as a library within within the solution now with that context first step is to understand where does where does personal data live within the entire solution right that's exactly where uh uh from a discovery point of view privacy impact assessments and the discovery functionality would come into picture where you can send privacy screening assessments to understand from a business process point of view or an application point of view they're processing personal data or we can also uh business users can also come into our employee portal and raise a brand new uh implementation request and submit a privacy impact assessment for it or regular intervals in case you wanted to send privacy impact assessments to understand how personal data is being processed for the existing set of records even that can be uh can be looked at the beauty of this is when you send these privacy impact assessments ultimately what you're doing is you're updating a recorder processing activity or processing equity record which is which is the front and center for the privacy team to understand a given business process or a given business application on how and why it is processing personal data right so this particular record is what is getting updated with the right set of details and based on the assessment responses we are applying controls on we are applying controls identifying the risks managing control attestation processes and also managing the issues and policy exceptions that are specific to a given processing activity required in this case that is one aspect where we are applying the risks and controls however for us to understand there is posture what we do is we have a two level risk assessment aspects or process that we that we have introduced and though this is configurable the first aspect is whenever a processing activity gets treated or updated what we can do is we can perform a criticality assessment to understand uh processing activity from a higher level aspect to see what is the criticality associated with it if the criticality turns to be high then we get into the next level of scrutiny that is trying to understand every risk that is associated with the processing activity and try to get the uh risk score or try to arrive at the risk or to understand what is the risk that is associated with the given processing activity right so it's like a two-step process for the critical uh processing activities that are identified out of criticality assessment we get into the next level of details to go into uh for the details as such right with that uh context right uh let us look into some of the key functionalities that we have released so i've got actually a question for you to promote um i think you're probably going to be showing this but uh i'll ask it anyway to kind of get kind of prompt you is there a capability in place or this plan to document and manage gpas uh so can you come again is there is there a capability in place or is it planned to document and manage dpas yeah so we yes definitely we have a plan to have dpas in um as part of our roadmap which is uh which has been planned okay awesome so with that question coming everybody keep the questions coming yes so uh but all the all the privacy assessments what we have is kind of pretty much documented within the processing activity itself so we can we can look into those aspects as well right so here are the highlights but when we get into the details um right now you can map to a processing activated record specific risks and these risks can be mapped automatically based on the privacy impact assessments or privacy assessments that are being responded by the business users which means on a given business application or a process when you send a privacy impact assessment and that gets responded based on the responses risks can be automatically applied on the processing activity where privacy team doesn't have to manually do this but any case where privacy team wants to review them in a manual fashion we have additional functionalities and how easy for them to understand what risk that needs to be applied on a given processing activity based on the personal data that is getting processed as part of it right so we have specific reports for us to understand the criticality score so we will get into the product and see some of these things for that i'm switching to my application right here i logged in as josh warner who is the privacy manager and what i will do is i will start the entire demonstration with the crossing activity and then i will come to the home page which you have which you are currently seeing to get into more details on what we have from a home page and reports and dashboard standpoint so for that switching to the processing activated record and taking around the application right so there's the processing activity record which has uh specific workflow associated with it right now we are in the discover phase where we are trying to discover what kind of personal data that is getting processed and we get to perform uh risk assessments at this point in time based on the data that is collected right now these disk assessments can be performed by the level one or the business users by themselves or by the privacy team and it can be purely configurable on how this assessment needs to be performed and again these discussions pretty much can be automated as well based on the privacy response impact assessment responses that are coming in right based on the privacy assessment responses that are coming in pretty much these things can be automated right now i'm going to show you in a more manual fashion but pretty much these tools can be automated as well so with that said let me uh one once the processing activity has the specific details right in this case um what is the purpose of this particular processing activity where the data is being stored and what kind of personal information that is getting stored as part of the spreadsheet processing activity with this kind of context right one of the thing that we need to do is the criticality assessment try to understand what is the address that is associated with this personality let's start with the critical assessment so i'm going to go here trigger my criticality assessment and when i take it ultimately i get into the risk assessment so [Music] okay looks like there's already an assessment let me complete this quickly now let me re-initiate so i can do i can perform multiple risk assessments on the same processing activity so what i'm going to do now going to initiate a brand new discussion right in this case it is asking me where i mean who has to do this particular assessment right in this case i'm saying for now i'm just doing the assessment but like i said this can be an entirely automated approach where we do do not even have to perform a risk assessment all all the risk assessment related factors can be automated based on the privacy responses so once i take the assessment right from here you can get started and if there is a previously submitted assessment i can copy over the responses from there so that i can just review only those minimum changes right as you can see here there are various factors with which we are we are performing a risk assessment right there are regulatory factors there are factors impacting data privacy and other factors and right now you're seeing this course based on the previous responses however we can we can modify them since we copied or as a part of this particular demo step i said let's copy the previous results and then and then change the responses right here various questions over here are factors stored here asking about what is the process uh whether this particular data processing activities processing last set of data right and if you wanted to understand more details about this particular factor on what is this and what is the kind of answer that is expected here or the response that is expected here here we have kind of uh help text provided uh where these these kind of guidance would help with the users to perform the risk assessment as such in case i wanted to change this respectively answer i can click on the change answer and change as well right so various factors and all of these factors are again configurable you can add additional factors as you as per the needs however we have provided such as systemic monitoring which is being performed or any automated decisions that is being taken right sensitive data related aspects right and many other many other responding factors as you see here are kind of capture i think the thing about here i think that's really exciting is effective it's built in i mean you got to this from the click of a button on the top right hand corner and then you're able to answer everything in this form it's in it and it's very intuitive you also have you have dependencies don't you or can't you answer it a certain way it'll pop up other questions um actually so so basically what would happen is this is primarily the risk assessments that we are doing so these are specific factors not dependent factors these are directly the factors that we are assessing the dependent uh response is what your what you are looking into is the kind of privacy impact assessments where we have right when we say that we are processing specific kind of data then we might want to ask additional questions and responses and that comes as part of privacy and practices here these are specific factors that we are evaluating so these are generally answers which are saying yes or no or kind of high medium low so that we understand the risk associated with the given processing activity got it but this is also configurable i can add questions absolutely absolutely you can add questions and let's say that you have sent a privacy impact assessment which is capturing uh responsing as a part of this particular processing activity they're processing thousand plus thousand plus uh employee data right then this factor need not be manually manually selected it all we have automated factors where it kind of selects all uh it kind of does all the assessment in an automated fashion and you get this course by the time processing activity kind of gets updated with its privacy impact assessment response as such so right now i'm showing in a manual fashion but this entire this entire assessment can be purely automated as well so we've got a couple of questions here um is there a specific role that you need to have to answer these questions absolutely so we need an assessment risk assessment responder rule and that role can be given to anyone uh within the organization be it a business owner who is owning this particular processing activity or the application in the scenario or it can be done by the privacy team where they can have their own approval levels so uh it is it is up to the organization to decide how they wanted to take the workflow on this particular thing and the role can can come in handy to whom we need to assemble another question here the factors are customized they understand that factors are customizable but are there predefined factors available according to gdpr or do you have to start from scratch you do have a privacy um a template i think that you've built absolutely exactly the current template what you're seeing is the one that has been provided out of the box and as well this con can this consider some of the factors coming from gdpr from this framework and few other regulations and that's exactly where some of these factors are coming in as well so that's where these regulative factors are in place and when we get into the financial factors impacting data privacy this is more subjective aspect from a from a business user or a privacy privacy analyst point of view where they are saying the the impact due to the legitimate use of national personal data is high here or low here right so these are some of the factors that we are shipping out of the box uh what you're seeing right now as part of this demo however these things can be configured as well yeah and i think that i mean that that's sort of a standard standard practice with printless service now you know we do provide templates but we understand that every organization is different and everyone organizations different needs absolutely so although we do provide something for you that can you know that that adheres to basic standards we also have it flexible enough to be able to add your own questions absolutely absolutely okay so i think those are the two questions we've got so far got it yeah so these are some of the factors impacting data privacy and there could be other factors that you might want to access on like financial impact or market impact and reputational impact so based on that assessment once this is done then what we do is we do a control environment assessment which means in this case you are assessing your control environment in the context of this particular processing activity understanding if the design effectiveness aspects or the operating effectiveness aspects issue remediation process right so all of these things can be assessed right so what you're doing at this point in time is a risk assessment at the processing activity level at the highest level so this is where it is a criticality assessment like um like a first level assessment or a top down approach to arrive at a inherent in the residual scores for this particular processing right and once i review and submit it we have this course in place and if you go to the processing activity from here what we get is on the overview page we get to see that the risk scores are kind of captured here now that we have the criticality score over here mentioned as high now the next guidelines is to perform risk assessments for every risk that is associated with the prostate activity and this is where the entire risks relationship with the given processing activity would come into picture you can add these risk risks right here not in a manual fashion but from a from an automated fashion as well so as per as privacy assessments are getting um getting submitted uh for instance let me take this particular assessment and talk about an example so here is a assessment response that we are seeing in every question when it is getting answered we have configurations behind the scenes for every value we can map address or controls or information objects and based on that the information objects or the risks or even the controls kind of get automatically mapped to the processing activity by responses right so privacy team doesn't have to do this activity in a manual fashion they just have to review it and while reviewing these things right let's say in this case 18 risks have been um identified for this given processing activity and in in case they wanted to see any other recommended risks then we have this recommendations as well and these are coming from the mappings that we have with our information objects to the policies and the statements and all of that right so we kind of give risk uh recommendations as well based on the information objects which are being governed by specific risk statements in the scenario now coming back now that we have these many risks and if you wanted to [Music] if you wanted to perform risk assessments on any of these particular things that is where we can we can select all of them or select one of them and start assessing these lists and again these are specific to those roles that we spoke just talked about some time back saying these things can be given even to the business user the first line user r can be performed by the privacy team and can have its own approval process with the due dates assigned to it right so once i take this particular risk assessment then from the risk assessment here are the risk assessments that are kind of available for me and the data transfer related things we can be assessed from here so let me quickly understand which is the one that i wanted to take it's refreshing probably just getting created so while you're while you're looking for this we've got a couple questions here um one of more of a comment i think so you know someone has very astutely recognized this as the advanced risk assessment process that we uh introduced with uh with risk or risk application um about a year ago now actually live year and a half possibly probably possibly longer um it you know obviously is much more flexible it it is much more interactive updates the scores as the data changes within the risk dashboard so it's it's much more advanced you know hence the name than our previous risk assessment capabilities if someone wanted to perform you know the standard risk assessments that we used to perform previously that's still available in the product um they would still be able to do that the the difference is that we've actually embedded or built in like we saw from the click of a button at the top the advanced risk capabilities correct that is right that is and the the beauty of this particular functionality when it gets integrated with uh with the advanced risk assessment is we have a capability to understand from the enterprise risk management point of view also to see what is happening on the privacy side of this right so in this case privacy is not being worked on a siloed version where ara or enterprises management or advances management is being looked by enterprises team and enterprises team now also has a visibility to the kind of risk assessments that are being taken by the uh in the context of privacy and uh we're also looking at aspects such as a privacy team is not working things on a siloed fashion but it is looking into aspects uh uh overall from overall from an organization enterprise discipline as well as corporate company standpoint yeah i mean i think it's the best of both worlds you're holistically being able to manage risk across the enterprise you know privacy with all of us you have but you're also able to look at privacy very specifically and prioritize the privacy risks exactly so it gives that space for the privacy it gives the space for the privacy team to manage their privacy compliance but at the same time it has a visibility to the enterprises team and as well as the corporate contracts team yeah we have another question that came in i think it's when you were talking about the automated controls and and um and such but is there a dependency on business application table for use of recommendation engine similar to what we have in the risk identification workflow yeah it's not a hard dependency so we we kind of look into the cmdb aspect today to kind of get access to what kind of assets which are those applications or which of those business processes or services that needs to be considered for privacy aspects and that's how we create processing activities but there's no hard dependency let's say these applications are not there as a part of cmdb repositories then you can also directly import entities and then from entities you can create the processing activities and start managing them so there's no hard dependency if if cmdb is populated with the inventory of business applications and processes we can connect them if not the starting point would be entity records awesome yeah all right let's look at the inherent assessment here yeah so we've done a quick uh data transfer assessment and where what we're seeing here assessment of this particular risk in the context of um in the context of hr onboarding application and we are seeing what is the impact in likelihood and when we get to the controls here we get to see what are all the mitigating controls that are mapped to this particular risk and it is an automated factor so this is one of the factor which is automated where you see that um there are one non-compliant and two uh compliant controls which are applied as mitigating controls for this risk based on that the control effectiveness is kind of calculated automatically and we are getting an overall response right here itself so this particular again this particular assessment is given out of the box um where you will be able to make use of the privacy risk assessments and assess the risks individually given to the processing activity and ultimately when you come back on the processing activity right here we have the compliance posture but if you go to the disc overview we get to see things from a single processing equity point of view to see degree what is the criticality score how each and every risk that is associated with this processing activities kind of performing from the inherent score and residual score point of view so from inherent what we have seen is we have high fibers which are in critical nature but when we go to the residual we kind of get to see the residual map as well and these are purely configurable whether you want to have it three by three or four by four or five by five matrix all of uh all of these heat maps can be configurable um and it also highlights over here critical critical risk which doesn't have any controls right which is even more worrisome for us right so there are certain reports what uh which would help you to understand the criticalities for the risks that are doesn't have mitigating controls and all of that right here wonderful we got we got a couple of a couple of questions um so the first one is you know is the full grc suite needed to access entities or can grc profiles be provided if you want to use privacy without the grc policy control risk bcm um applications i know the answer that but i'm going to let you answer it sure yeah so uh privacy is an add-on on on the existing irm suite so minimum requirement for privacy is policy and compliance or irm standard so that is where it would start and then you can you can have you can have a privacy either on pro or enterprise but minimum requirement is standard now when i say irm standard as the minimum requirement here we know that a the risk management aspects whatever we are seeing here are coming from advanced risk assessments module and advanced disk assessment module is only available in irm pro right so that doesn't mean privacy needs to with risk assessment capability need to have uh irm pro is not a constraint so if we install privacy along with irm standard as the minimum requirement risk assessment capability further usage of privacy will come along with the privacy skew as such along with the privacy product as such so specifically yeah we just but to make to make it simple for people so they're not having to buy something they don't need i mean that's that the trying to meet the customer where they're at is what we're trying to do um another question we you know you've been showing information objects here on and off um can you spend some time and you might be doing this coming up um on the sample content captured in the information object absolutely so on the information objects so here all the information objects which have been categorized as personal information but when i go to one of the one of these information objects like let's say i take this one again these are quite configurable we can we can additional fields and all of that but we get to see what is the sensitivity that is associated with it right and which business unit started this particular or kind of have a need for this particular information object which are all those processing activities that are processing such a kind of personal information right all of those things are right here and also if we go to the 360 degree view right from here for us to understand this particular information objects in more detail so what would happen is for this particular uh information object how many processing activities we said and also the list statements that are associated right if there are policies if there are citations even those things would get kind of showed up right here so so the beauty of this is in a case where we if we identify that there is a regulatory change coming in for a given information object we know the impacted citations policies statements and crossing activities right so if i take another example just to show that if i go to the list view let me take a simple example customer email and bring up the 360 degree right here now here you see that this particular information object is associated with the citation policy and the statement which means whenever there's a change for the specific information object we get to see the impacted areas like there are six level processing activities and as well as there are specific citations policies and the statements associated with this information and i think this is really pop this is really powerful because i mean as we all know regulations are constantly evolving they're constantly changing there's new regulations being added you know the ability to proactively identify when a regulation is going to impact a certain information object and ultimately your privacy posture i think is is is so powerful and i i everybody loves this 360 review i love it because it's got everything in one place you can see all the interdependencies absolutely yeah so going back the presentation we spoke about uh risk assessments and as well as they are limited right that's exactly where privacy management is being shipped with they are a limited capability so you don't you do not need to have irm pro to use risk assessment capabilities or their risk assessment capabilities with privacy management pretty much you can use with uh you can perform risk assessments on an iron standard as a minimum requirement for privacy application yes but let's get into the other aspects right from uh uh from an overall uh product point of view and one of them is such recommended controls so what we have seen previously is recommended risks right so if i go to one of my processing activity again under controls what we have provided is recommended controls again and how these recommended controls are coming in like i said the information objects we have seen these are mapped to citations these are mapped to policies and based on those mappings and when it is associated with the business application in this scenario we are recommending what are the additional citations of related controls or additional controls related to policies that needs to be added all of those things are coming right from here in addition to that what we also have is the key stakeholders right so we have introduced key stakeholders who are where we are trained of capturing what all the other important business users whom we need to know who are working or having an ownership on this particular processing activity right so there might be i.t application owners there might be business owners there might be executives who might be owning this processing activity from various responsibilities point of view right so that's exactly where key stakeholders would come into picture and the beauty of having key stakeholders is not only from a record point of view that we are kind of having these users but now when we are sending a privacy assessment we also get to understand to whom i can send a privacy assessment right this could be an automated way or it can be a manual fashion but it can it will give us the ability to send specific assessments to the right people so that from a technical assessment point of view from functional assessment point of view if you wanted to segregate the privacy impact assessments then we can target the right people and here itself that is one benefit or an additional benefit of key stakeholders the other benefit is this right let's assume i wanted to collect a few more details on the processing activities right there are specific um data that needs to be updated on the information objects or on the details so instead of sending privacy impact assessment what i can do is i can directly assign this particular processing activity to one of the key stakeholder who has the privileges to edit the processing activity right i can directly send this to val in this case and once i assign it as you see the substate would change from a change to a pending key stake or key stakeholder updates and now if i log in as well as a business user i will be able to see the processing activity and update the details which are needed right and it and privacy team can also communicate with them using the comment section right here so when i go to val's login uh looks like i got logged out let's quickly log in in the scenario so can you you know you're sending it to val but if you if you had two or three people you wanted to send it to could you send it to a group also we can send uh we can send the processing activity to one person at a time um yeah we can only send crosstalk to one person and basically and the key stakeholder is is needs the business needs to be a business user right i mean is it absolutely yeah key stakeholders are the business users and it is also been updated by the business users itself right we have an entity owner who would start as a first identified key stakeholder and then and from then on this particular stakeholder can provide other key stakeholders for a given processing equity who needs to be participating in the entire privacy activities with the privacy message so here is the employee center view so now we have a brand new employees interview for the private for the business users where they get to see all the tasks consolidated right here so here is the grc tasks from which i can access the processing activities that are assigned to me so like i said i'm logged in as well right here i have all my tasks open so i can from here i can go to crossing activities that are assigned to me as you see even at the station or issues all of those things kind of shows up right here but this is the one that has been assigned to me by josh i was the privacy manager and i can get to the details i can get to the information objects and start providing the missing information which has been communicated by the george using comment section right here right so all of these things can be pretty much edited by the uh business user itself so we don't have to send privacy impact assessments in this in specific scenarios where we need additional details or anything we can directly send the processing activity and get these details and once the details are kind of uh provided like i said even key stakeholders can be added or updated based on the roles that have been changed with respect to this processing activity and when these updates are done it can be assigned back to the privacy team and privacy team would be able to start looking at those changes and from the history we also kind of know what kind of values that are being modified and privacy team can look into those to understand what kind of risk and control implications are there based on the updates that we're given still streamlining the process you're making it faster easier absolutely always better yeah so going back um yeah we spoke about uh sending multiple asses and assessments to key stakeholders assigning the crossing activity to key stakeholder itself and 360 degree view like i said right exactly right from here i can launch the 360 degree view as we used to see before now it also shows you the risks that are associated with the processing activity along with the information objects right upstream and downstream processing activities and from here we can navigate to the uh yeah basically to the information objects and try to understand what kind of uh what kind of relationships that this particular information object has with that yeah let's talk about some of the discovery related functionality that we have added we know that we have privacy assessments that can be sent and then entity 11 to get more to understand if the business applications or processes are crossing personal data or not but in addition to that what we have done right now is we have provided a portal form for the business users to come and proactively raise a privacy impact assessment for the new implementation that they are thinking right in this case let's assume there is no cmtp required they are not created in entity but they are just the initial phases of creating a brand new application or a business process then they can come to the portal and submit a request so let's see quickly see how this entire flow would look like so i'm going to vals employee center where i have risk and compliance uh tab right here from where i can access privacy impact assessments for the new implementation of the initiative that i'm looking at right so at this point in time like i said there is no cmdb record or business application record or a business process record so i'm just filling some of the details here on what i'm thinking about for a new application let's say this is account uh account payables is a process and i'm selecting what kind of information the personal information that i'm crossing as part of this i'll be crossing customer bank account probably i'll be processing customer email and [Music] right and if some details are missing i can also capture those things here saying let's say customer home so these things um uh pretty much can be typed here full name like we can add the information objects that are being processed as part of this particular or are being thought through right as part of this particular new business process that is being initiated so i can provide the justification and say that this is part of which business unit and further down with part of which um department who might be processing here as data subjects customers right data storage type is going to be a digital format data subject range which might be beyond specific limit and i can fill in all the details like data storage locations and additional comments and i can submit this so as a business user i'm just submitting a brand new uh application request or in this scenario for privacy team to understand what am i coming up with and how things would be and then i can also say that uh any happy to tell the additional info right i can post comments to the privacy team as well rightly here so what would happen is for for the privacy manager when i go to his login and start looking at aspects on the home page we get to see a brand new crossing activity kind of recorded right here as you can see here account payments is kind of right here and as a privacy manager i can review it looking into the details if you see we got the justification we know which business unit this is being referred to some of the details and also we are looking into information object related details so we can also as a privacy team we can also interact with the business users right from here saying i need to schedule a call and post the comments and these comments are pretty much only visible to uh privacy team and business users any privacy team conversations will be will be maintained private right so if i go to vals uh if i go to wild stream well can also get on you can get the comments that are being posted by the privacy team also an emails have been sent in paddling as well uh on these on these interactions right so that's how we can create and from here you can assign the processing activity or you can uh you can send a privacy impact assessment based on the process that you have defined to understand more details about this particular personality yeah and i think that interaction being able to just be able to interact is is so helpful because you get your questions answered right away and i think if people haven't figured it out already you know that employee center that that promote was showing you that i mean that is sort of your central control panel it's not just privacy there's you can enter risk events you can acknowledge policies i mean that you've got it you'll have legal all the different departments can be on this one portal um so this is becoming for a user you know for this is the this is the place to be a business user it's a place to be absolutely and that's exactly what i want to touch upon next seeing uh saying that this is the place where i can come and i can look at what are the privacy specific assessments that i need to take right and what kind of control attestation that has been given to me so it is that front and center for the business team to come and look for all the kind of tasks that has been uh assigned to them and that in any and any other request that they need to raise be it a privacy impact assessment for a new implementation or report an issue policy exception so this is the front-end center for the business team to start interacting with uh with the grc team and here not just from a grc point of your point of view even other solutions uh from servicenow kind of uh kind of uh coming here as a consultant yeah this this this is this is becoming it's not replacing the ticketing um portal for the itsm but for a business user you know this is becoming the place that we're pulling everything together consolidating your cost service now and so that's that is that's i think i think it's very helpful so moving on so we spoke about uh assessments and as well as the portal capabilities and from then on if we go further down let's look into the home page side of the site so once all of these details are filled and there are various processing activities that we have collected ultimately what we are trying what we are looking at here is the posture privacy posture from a risk aspect from the compliance aspect and that's exactly where the com um the compliance overview is there month on month showing you how the entire trend report would be with respect to the compliance posture and as well as the overall control status across various controls and how many are compliant and non-complied and the other new report that we have added is the most non-compliant control objectives now here the whole idea is to see things from a control or a control objective point of view and understand what is that one control objective which is kind of impacting 10 crossing activities which means these are the 10 processing activities where this particular control objective is kind of non-compliant right so now privacy team is looking into these aspects from a different perspective not from a processing activity point of view but from a control objective point of view to understand what is that what is the most troublesome or the non-compliant uh control objective that i need to work on to fix quickly around multiple processing activities right in a very similar fashion we have the entire authority documents and policies related status across various kind of controls that are applied right here and moving forward with respect to risk management aspects here we get to see the critical risks uh trusting activity criticality processing activities with her critical to score as high right those things kind of shows up here and again very similar to the control objectives the report that we have seen here the statements which are rated high right so this is that one statement which is kind of rated high across three processing activities which means now privacy team can start looking into this particular statement and try to help the processing activity owners to reduce the risk on this particular one i think it's it's the uh it's the being able to prior we're prioritizing for you the the risks that are the greatest impact to your business and i think that's that's where the value is is you're not having to analyze it yourself you know we are giving it to you absolutely absolutely that's the whole intent going forward on the processing activities we have various reports based on the data that we have so ultimately it is like how many data subjects are we dealing with and how it is like divided right data storage types and even data category wise uh how many general personal data we're processing special category data so ultimately getting into the processing activity specific reports and we spoke about regulatory changes right so this is where the regulatory change management integration is coming as part of this particular release right so here we get to see the regulatory changes that are specific to privacy authority documents as such so when we have the regulatory change and integration which is available as from irm pro onwards if there are specific regulatory tasks that are identified which are mapped to authority documents um which which are of type privacy then we get to see those related things right here and privacy team can concentrate on the filtered work rather than looking into the overall regulatory changes which might be quite huge in nature so that's on the regulatory change aspect now we spoke about privacy privacy team their reports their dashboards and all of that right but what if i am a compliance manager right so if i go to a compliance manager's workspace what i get to say is from overall compliance manager point of view i'm looking at various regulations at the same time i have a quick report right here talking about the overall privacy posture right which means as a corporate compliance person where i'm looking into overall compliance and their posture i get to see the entire privacy posture right from here and navigate to the dashboard and see if suspect this is another integration aspect saying that privacy is not seen from a cyber product but also has a visibility to the overall ir and suite of aspects this is not a siloed product it's part of an overall compliance and risk program absolutely and if i and if i log in as one of the risk manager right that's in this case i'm logging in as a risk manager even over here i get to see privacy specific posture right so let me go to the workspace this workspace right from here here and then that drop down menu that we just saw up there at the top is actually part of the new user interface that we have for several of our products of servicenow and several of our grc products absolutely so in this case a risk manager is the one who has access to some of these particular workspaces and they can always switch between the workspaces right so but in general they prime they primarily come to the this workspace and from here i can i can try to i can understand what is the privacy risk assessment posture right what are all the risks that have been assessed and how how the entire foster is right here saying which are on the high risks and the overdue tasks and the risk statements related ones and this course all of those things are visible to the enterprises manager right from here itself right so that's exactly where the power of shared libraries and the power of privacy team working in their space but at the same time at the same time enterprise test management team is also connected corporate compliance team is also connected and trying to look into privacy from an overall irm point of view is that coming together absolutely we have one question about um processing activities actually can you can you can can users document sub processor processing sub processors that support certain processing activities absolutely so privacy manager here once again go back to so every processing activity um every processing activity can be man can be kind of documented and it can be related right and that too related in the context of uh when we say subprocess in the context of information object sharing aspect right so when i go to hr onboarding we can say that these are all the personal data that is being processed and how this part personal data records are being shared from on upstream processing activity and the downstream processing activity point of view right how am i getting this data right so that's exactly where we have processing activities kind of connected from a hierarchical fashion to understand the data flow and this is where the sub processes in this case for this particular processing equity these are the sub processes and this processing activity is acting as a process for for another application right here right so that's how we can we can enter we can associate or kind of maintain the hierarchy to understand the overall data flow in the context of prosthetics perfect thank you excellent so with that have you looked at some of these reports risk overview and overall processing activity specific reports regulatory change management quite an important thing for us to understand because this is something that in the privacy world regulations are changing drastically so having such a report is going to help customers a lot and then information objects right information objects aspect where we are not just having information object which is associated with the processing activity but also it has its own context on what kind of citations or policies or statements governing this particular information object and also impacted processing activities that are coming not affecting all of that right so the those are some of the critical enhancements that we have released as part of san diego san diego version as such open for questions and yeah that's all from me i don't have any other questions on the list right now but everybody please we've got about six minutes left please put your last questions in here i'm going to skip over um and just share very um briefly our um there we go some of the places where you can find more information um hopefully you're seeing my screen that says connect with us you know please you know can find us on the servicenow product site on the on the community and i put in the chat the link to the ask the experts playlist on youtube i don't see any other questions in the list right now i want to thank everybody for joining us i really appreciate you taking the time and promote i i really appreciate you taking the time and walking us through the product so thank you very much also thank you thank you teresa and uh quite excited for you guys to try the product and let me know in case you need any help from my side wonderful all right we hope to see you in some of the the next and upcoming webinars that we've got and with that i will bid you um farewell and have a wonderful day your evening bye thank you bye uh um

View original source

https://www.youtube.com/watch?v=Ey78fXWpZTg