logo

NJP

What’s new in Policy and Compliance Management

Import · Apr 08, 2022 · video

welcome everybody thank you for joining us glad to have you all we're gonna wait a few minutes let everybody get into the room before we get started all right thank you everybody for joining us you know welcome good morning good afternoon or good evening depending upon where and when you're joining us or if you're joining us on demand um we're happy to have you um we're here to talk about policy and compliance management and i am very happy and excited to be joined by initiary initially would you like to introduce yourself thank you uh hi everyone uh i'm inishley and i'm part of the product management team here at servicenow i manage our policy compliance and audit applications and i'm very excited today uh because i'll be showing you some of the features that we release in our march store release in san diego or store release fantastic and i am the director of product marketing um for the risk products um so i um get to work with industry a lot which is wonderful we are actually on our fourth webinar in the series so we have had three other webinars which you can find on the ask the experts channel on youtube um today is policy and compliance and we really hope you mark your calendars for next week because we're going to be talking about business continuity management i think that's going to be really exciting really interesting but i know everybody right now is excited and interested to hear about some of the new things that we have in policy and compliance so without any further ado i am going to turn it over to anushri who is going to walk us through some of those features and he's just more importantly she's going to demo them for us all right thanks derisa to grab your screen um can you see my slide okay it looks fabulous awesome all right so as i mentioned before i will be showing you what's coming up what actually release in march store release and i'm super excited to uh demo those features today so uh these are uh some of the features that we released in this store release one of the feature that i'm really excited about is policy authoring integration with office 365 uh i will be able to demo you and to inflow on that then we also release first line experience uh through integration with employee center uh this was covered already by kash in another webinar so i'm not going to go with the details here in the demo then we also released some enhancements on the control where we are now supporting creation of multiple controls on a specific entity and a control objective there was a restriction in place and we are we are opening it up so you can create multiple granular controls on the same control objective and entity then we also release compliance data source registry this is uh an integration framework that we uh we have uh we are providing which will be which can be used by uh customers who want to integrate with our controlled objectives with uh any equivalent checks or policies from other servicenow products an example could be a change policy or uh there is a new introduction on new policy which is a codified policy uh that was released by our devops team so that's called pace policy you can indicate with other equivalent policies or checks uh on uh on other servicenow products and then um map or measure the compliance of your control objectives this also allows you to request exception on those uh equivalent policies or checks so this is a framework for integration framework that we release so i will quickly talk about that or show you that how that works based on the time that we have then we also did some enhancement on the ucf uh i have heard a lot of feedback on this but if you're using using ucf you would be uh currently the system has a limitation of only uh creating or importing the authority documents through the shared list if they were already downloaded in the platform you have to add those in the shared list before you download new uh authority document documents from ucf so we remove that restriction and this allows you to download more than 100 authority documents through multiple shared lists so this is an enhancement that we did on the ucf integration site and finally we did some enhancements on the security and access access site where we are providing a feature called as confidentiality which will allow you to mark different uh records is confidential and only the users who are uh assigned on those or or are on that record may be assigned to or any uh anyone in the watchlist or anyone in the assignment group would then have access to this confident uh this record you could add other users as well if you want uh who would need access to the confidential record so that's an enhancement that we did another enhancement that we did is user hierarchy so we enable this feature on a few of the records out of the box of course you can configure it for other records so if this allows you to provide access to someone higher up in your hierarchy uh let's say if you are an issue owner and uh you're assigned to an issue and your manager does not have direct access to the issue but they want a visibility into what they're uh what their reportees are working on so this allows you allows the manager to actually see or view those issues as well so this is some of the enhancement that we did i'm going to start off with the first one which is policy authoring integration with office 365. um with this feature we are providing an integration with office 365 onedrive or sharepoint and uh this would allow your policy owners uh different collaborators or contributors or subject matter expert reviewers to edit and redline the policy in a collaborative fashion using office 365 word document and one right this provides you in capability to either create a new document on onedrive or also connect to existing document if you have a policy document that is stored on one right you can connect to it using this feature you can also see different version history of the policy uh on the policy record so you will be able to see the previous version of the policy the previous word document that was published versus the new one so we are maintaining the history as well and finally you would be able to uh convert the word document or the policy text into pdf and attach it to the policy so it can be published as a kb article so i'm going to take you through the flow quickly so you will understand what are the different changes that we did here so as a policy owner i can draft a new policy or i can edit existing publish policy uh by sending it back to draft so that this is existing functionality but you can do that uh through this integration so the word document will be ready for your edit again when you send the policy back to draft we introduced a new role called contributor new persona called as contributor who could be a subject matter expert so if you're writing let's say a security policy and if you want to invite someone from the security team uh to help you edit or draft the policy you would be able to do that and this user would then get edit access to the word document on one right once the draft is ready then the policy owner can send this draft to reviewer and the reviewer then will be able to review the policy uh if there are multiple reviewers they can review it in a more collaborative way on onedrive and then provide their comments they perform their redlining on one drive but the same can be retrieved or synced back with the policy text on the policy record once the review is done and the policy is ready or to be sent for approval the policy owner goes through a publishing checklist we added the step in between so that uh the owner would then make the policy ready uh ready for approvers to come in and then approve it they will get a clean copy of the policy and then the same can be published automatically when the approvals are done so once the uh policy is ready uh with the pub and publishing checklist is completed the owner can then send it to approver and approvers then will approve and the policy will be auto published so this is the flow and you can see that we've added uh the indication of a 65 we have indicated it through this flow and you will be able to see the touch point and how so every person i will get edit access or view access to the policy when i get into the demo so with that i am actually going to switch to the demo and show you how all this works i have an example of policy here uh this is a blank policy there are two options that you see here this is a new tag called as policy text there are two options here you can either create a new document on onedrive and we are providing a for default folder location this is a property you can set uh you can you can provide of course your folder as well as the folder location where the policy should be stored and provide the name of the policy and that will create a blank document on one right or you can connect to existing document which which will ask you the folder location of this document and ask you to attach this document once you connect it that's actually going to go ahead and connect with the uh the file on one right so uh just for the demo purpose i have already set this up so this is my policy information security policy what i've done is i have enabled redlining already and i've connected with a policy which i had stored on one right under this folder so if i open this one word document here it is going to open the one one drive word document for me and if i go back here there is a document access tab that you can see here what i've done is i have added various users if i go back to the details tab here there are uh various user who interact with this policy recorder owner approver viewer contributor so all of them will get access to the document and here you can see when the policy is in draft state uh the contributor and the owner has edit taxes as in when policy moves to another state the access will change and i'll show that to you so uh let's say i have this policy which i've already drafted it is actually synced back here with the html text so this is where you can actually update your policy whenever you make any changes on the word document and the same will be populated here retaining the format of the document which you can see here so the same format the header everything is synced by and the policy shows up um as a as well formatted policy here so anyone comes whoever comes to this record will be able to see the latest version of the policy now uh once the policy is drafted i can now send it for review so i can send a message to the viewer we have a question here can you actually set up sequential approvals or reviews so currently it is not sequential uh currently uh the approvers um and reviewers are send the notification and all of them can reviewers all of them can come in and review the document and provide their comments but that's something we we might enhance in future to provide um like a sequential approval so if approver one approves the policy then it will go to another floor it is basically all the reviewers will get collaborative access to the word document and they can uh work on it but based on their comments whatever they provide the comments will be captured and it will show which approver or reviewer has commented on what part so that's captured and then we show that on the policy record as well but the approvers uh are sent uh the approval recalls are also sent to all the approvals but all of them need to approve the policy for it to get published so perfect so i'm going to go ahead and send it for review and once it is sent for review all the reviewers who are added under that reviewers field that i was showing will now get notified and any of the any one of them or all of them can come in and start reviewing the policy now if you see the document access has been changed so my contributor now has view only access but the reviewer has edit access along with the owner so any review comments anything added by the reviewer uh can be seen by the owner and even they they can work with the reviewer in a collaborative fashion so i'm going to log in here as a reviewer and as a reviewer i'm going to go ahead and open this word document once i do that i will uh have edit access to the document i'm going to go ahead and turn on my track changes it's already turned on i can either work off of the online document or i can go ahead and open this up in the desktop app if you're more comfortable with that so let's go ahead and start editing this policy add some comments here so are you able to is it does it support any of the any any word fonts all of the word fonts or is you know formatting an issue that displays it basically is word right i mean every every feature that's available to you in world is word is available here okay so do you just to clarify did you have to download this word document and then upload it again or are you still in the service now so i what i did is when i click on open inverted just opens the word document from onedrive uh for me and then this is the online version of word document which i can start editing right here or as i said you can open it in desktop app so you're not downloading the one right uh word document but you're actually uh opening it on the online version of what you so you really are able to stay within the platform and stay within the product we're not asking people to jump out of the product and jump back into the product again so this really is streamlining the whole process this is it's making it much simpler and easier for people to be able to to add these changes and to have these trains just tracked and then i'm assuming there's an activity log that goes along with this also okay that's absolutely so you will be able to see the activity log what's happening as well here and um like i said you open it up in word and it actually just opens another tab awesome all right so what i've done is yours i've added my review comments and then i'm gonna go ahead and i'm going to go ahead and submit my review and once i do that the owner will be notified that the review has been submitted and the comment will be visible in the activity log so the owner would know which reviewer has submitted and what they can go to the word document and see the changes as well the other thing that owner can do is uh they can again update this document and once they update the document you will be able to see that all the comments and the track changes are also synced back with the policy record here let me go ahead and try again all right you have to love the uh the internet working working from home is always uh challenging right when we have internet issues or slow internet yeah in my case yeah same here so yeah it takes you seconds and then what you see here is the the same the comments and the tag changes are reflected on the policy record here so whoever is coming to the policy report will be able to see the latest status of the document and we'll be able to see all the comments and the red line that was done on the document as well so now this is done and let's say all the reviewers have completed their review now the policy owner will get this button on top which is a new one which is complete publishing checklist once i click on that it is going to give me a checklist which is sort of a playbook that i have here which will take me step by step through the process and make sure that i formatted the policy well and it is ready for publishing so the first uh first uh the block that you see here talks about uh cleaning up the policy of analyzing the word document it asks me to accept or reject track changes remove open comments and clean up the document so i can open up the word document from here go to the word document and make sure i do that before i actually i'm sending out for review or approval sorry so i'm just going to go ahead and accept the track changes let's say i have resolved this comment i'm going to go ahead and delete this and once i do that again i will go ahead and update my text so that i will see that the text has been reflected and the clean formatting is shown here so i'm going to go ahead and refresh my page so this the checklist isn't it's not really for approvers or reviewers it's really the checklist for the policy owner right to be able to be sure that they're doing everything they need to do to make sure the policy is clean and and current and available and and all of that so it's really not specific for approvers or reviewers okay that's true so for the owner to make sure that they format it and the policy is clean before they send it out for approval final approval right we have a question here um do end users outside of the policy management team also see that the document edits in progress or are they only seeing a published version they will only see the published version who whoever only has access to this policy record like owners contributors reviewers approvals will see the document and will have the access to the document and any changes on them once the policy is published it will be published as a kb article and that kb article is the one which will be visible to the end users so that sounds reasonable okay so i see that the form uh policy has been reflected here the format close okay i'm going to mark this as complete and it will move on to the next step which will ask me to check or review the formatting again what it will do is it'll unlock that field for me and make it editable so if i want still want to make any changes i can actually do it here this shows you how the policy looks like when it is published and i can make any changes if i want to hear and edit the policy text but i'm good with the policy it looks good so i'm going to mark this as complete and then it will move on to the next step which will ask me to review any attachments if there are uh for on this record now if this is a policy which was republished i might have some attachment from the older version which uh might be outdated so i'm i want to remove them i might want to remove them so those attachment will show up here since there are no attachments i'm just going to mark this as complete and it will move on to the next step which will allow me to attach a policy text as pdf this is an optional step if you don't want to attach to that pdf you can skip it mark it as complete this also helps with the use case which which we have heard from customers where if there are longer lengthy policies uh customers would not uh that there were some requirements where customers were not looking to actually uh add the text on the kb article or the policy text field but they would like to add it as a policy attachment and they can just add some generic description a short description here on this text so this toggle that you see on the left hand side will allow you to do that so you if you switch it off this text will not be synced with the word document text anymore you can maintain your separate text text from the policy text and then you can attach the policy as a pdf version on the kb article so you're providing that option as well but uh for the demo purpose i'm just going to go ahead and say attach pdf and i would like the policy to be converted into the pdf now if you can see that pdf has been attached to the policy record if i open this open that up this is a pdf version of the document which then is attached to the policy record and once the policy is published uh the pdf will also be attached to the kbr now the final step i have here is checking my final set setting which is around the publishing setting i uh to making sure that the policy knowledge base is uh correct if i want to change it i can do that and the policy template that will be used for publish policy or a kb article so if this looks good i'm going to mark it as complete and once everything is done i went through all the steps to make sure i'm ready for this policy to be published once it's approved i can go ahead and then request approval so this is my final step where i request approval and if i want to add more approvals i can do that here i can send them a message so people really like the checklist is is the checklist configurable can you add additional steps to the checklist yeah it's a playbook component that is available on workspace if you want to configure it and add additional steps you can do that great yep so i am going ahead and requesting approval once i request approval you can see the document access would be changed and all the users now have only view access to the document because this is a final uh approval stage we don't want anyone making changes everything is already done and we are now sending it out for approval final approval so i'm going to log in as an approver here and approve this policy says approver i will go to my task inbox and i will see that there is one task pending for me which is policy approval i am going to request the policy approval i can view the text on the policy so i can go to go back to the policy and look at the policy text and that policy text will be available uh basically i can either go to the policy itself or i can go to the word document and view the policy so if the policy looks good i am going to go ahead and approve it i can add my comments as well if i if it doesn't look good you can reject it and add your comments and the policy will move back to draft and the owner will be notified as soon as i publish it a kb article is created and it will show up on the policy as well so the policy is now published and if i go under the policy history i can see that the policy has the kb article associated with it and it also has the attachment to the word document which was published it shows other details as well in the history like valid from valid to date when was it approved who are the approvers reviewers and contributors and this is my policy history tab that is maintained now what i'm gonna do is uh i will again log in as policy owner and i will just show you the uh again uh the step where the owner would be able to uh review the policy let's say there's an annual review cycle and send the policy back to draft so let me log in as policy owner again so quick question here how does oh a quick question how does the final final approver know exactly what has changed for them to approve can they go back to previous versions yeah so they can go back to previous version and then i'll show it show it to you in a bit but uh let's let's send it out for review and the policy will go back to the draft stage which is where they can again start drafting policy let me actually refresh this uh policy word document on the policy word document they do have a way for you for to check the version history so if you see here i have the version history here i can see what the changes were done uh let's see by who as well so it shows me the entire version history of different changes that were done on the policy and i would be able to check any changes that were done so approver will also get this view they can go ahead and view the different versions of the policy and the changes that were done so we can see the versions in the word documents yeah nothing really changes from the kb article standpoint though as far as versions right it's just it just shows it as kb article so if you go into the policy history tab so this is one way of reviewing on that document when the approver will come in they will be able to review what was changed and what were the different changes done on this document by owner and reviewer they can also go to the policy history and if they want to see a previous version of the policy they can see it from here so they'll be able to see let's say this was the now edited draft again uh the policy or reviewer if they want to see what was the older version of the policy they can see it here so they'll be able to see the older version of the kb article as well as the document the word document attachment and then they can compare that with the current word document as well and then out of curiosity if for some reason they've decided you know what we made some changes and that was a bad idea can can they make a previous version the current version again absolutely so the word document provides you that capability of restoring um of different versions so they can go back to the previous version and restore the version if they want to and then um one question here or comment is so once the policy is published all controls go back to the draft state okay okay um we've got a bunch of questions um let's see i'm not sure okay i'm not quite sure i understand this but are the older policy versions linked to other modules for example past audits we don't really create any links between the older kb articles and any sort of previous audits that were conducted correct no we don't do that today yeah yeah um okay then the next one here is how many levels for policy hierarchy can we establish will it also showcase policy level zero one two parent child policy relationship and also from kb article will policy levels be visible not from the kb articles but if you go to the policy uh itself you can create different uh child policies as well here if i create a new one let's say um we showed the history today on our overview page so let me go ahead and show that to you so while you're doing that i want to point out that industry is using our new next experience user interface so you all can see the drop down menu at the top that she's pulling down and you can see the jewel tone on the side a lot more streamlined when she goes to list views it's only showing her the list of activities that she cares about as a compliance manager and i don't know if you all notice we're not really going to show it this time udkar showed it when he was showing risk um but when she went over as a approver she showed very quickly the the new portal that we have the employee portal that you can use for your front line employees to be able to manage grc tasks by t-tasks legal service delivery tasks um basically it's the one-stop shop for all of your employees yeah absolutely all right sorry so this is where you see the hierarchy of the policy and you can create multiple hierarchies as well um it is only shown to the policy owners or policy who have access to the policy uh but the end users would only see the published kb article which is the latest published kb article so if the if you want to attach any uh additional documents or sub policies you would be able to do that through the process i showed you so if you want to attach any pdf of the child policies or any documents you you would be able to do that and then publish to the kb article awesome all right so that was my end-to-end policy authoring workflow uh feature and i'll be happy to take up any questions or connect separately if anyone wants to understand it in more details i'm going to move on to the next feature so that is control enhancements so as i mentioned we did some architectural changes and we allow now creation of multiple controls or sub controls on the same entity and the control objective i'm going to get into the system quickly and show that to you so right here actually are you getting back over next next time you show the employee portal let's pause for a second so people can actually see what it looks like you have to do it now but um next next time you go past it sure i can do that alright so what i have here is an uh control objective uh implement approve changes it is uh associated with the uh the change management policy and under this control objective i have about 79 79 controls now this is a control of which i'm going to take this example here so the control or the control objective is associated with the entity type under which there are various entities and because of this association we have all these controls created automatically from that entity type now for the all these controls that have you will notice there's a new field that was added inherit from control objective and by default when a new control is created automatically we mark that inherit from control objective field as true which means that we are automatically creating this control from the control objective the name of the control would be same as the control objective and that's an auto generated control that we have the feature that we have today now uh in if you saw in the old architecture once a control is created on an entity and a controller objective i won't be able to create another control for the same entity and a control object or combination but now with the new feature if i go ahead and create a new control here and let's say i do use the same entity go ahead and let me use something else maybe this entity is not active in this instance the sap financial accounting seems to be everybody's go to uh yeah i'm just gonna go ahead and go to entity yep this was inactive so things get changed all the time on that warranty all right so i'm gonna go ahead and do that again this time it should show me because i've activated it so once i do that uh you notice that i have implement approve changes control objective and the entity sap financial accounting i haven't checked inherit from control objective checkbox this time and what i am going to do is i'm going to uh write or probably name this particular controller differently so this is my more granular control which where i'm saying implement approve changes with back out plans right so i am going to go ahead and save it and once i save it and it's asking me to fill up the mandatory fields i'm going to go ahead and assign it out to an owner that's one of the things i like um about the system is that it doesn't let you it doesn't let you pass link to the next level without providing all the information it needs to be able to do what it needs to do later so in effect you're not providing an insufficient or in insufficient amount of information okay absolutely so if you notice here uh i have another control created for the same entity and the same control objective combination here the inherit from control objective uh field is marked as false and which means that you're manually creating it and uh you are not basically copying the same name as control objective you can create multiple controls as you want um on the same controls control objective and entity so that's the feature of the change we did on the control side uh if there any questions let me know there are yeah absolutely give me a so a couple questions so how do you prevent duplicate duplicate controls from being created accidentally yeah so we do check there's a unique constraint on the name so we do check if there's another duplicate control creator with the same name we don't allow that um so that that's how we handled it could could existing controls allow you to uncheck the inherent from control objective selection uh existing control if they're automatically created uh and that's where we mark it as in hedge from control objective is true uh if you want to uncheck that uh it you might be able to but if they are created on a control updated then we actually make it read only because that's basically done through automation which means that you've chosen that control to be created automatically using your item generation again you know trying to keep you from making mistakes that might have problems down the line so so you've got these two controls the question here is how can several controls contribute to a compliance score of one control objective so the compliance score logic doesn't change uh your controls are still considered when you're calculating the compliance score so any controls are associated with control objective the compliance or the average of all the compliance and non-compliance status of the control will be considered and rolled up at the control objective level and at the policy level and so on got it i think that are the questions right now awesome then i'm going to move on to the next feature which is security and access enhancement i think i know there were a few questions around it uh and i'm going to first of all show you how what we've done here so the first feature is providing a way to restrict access to a certain record by marking it as confidential and then the second is visibility into the records uh in the user hierarchy and then there was a question around can i mark all the records confidential by default uh you could do that we don't do that by default on the system but if you want you can probably choose an allow or add a business rule or a logic to actually market all of them is confidential uh the confidential if your market is confidential then becomes very restrictive so you have to be careful which records you want to mark as confidential and not but you would be able to do that if you want to let me go ahead and show you an example of you got ahead of me i was going to ask you that question you're just you're too good all right so okay lots of instances yeah see that's that's the downside of having multiple instances is figuring out which one has what in it okay i'm thinking so we have a lot of of other enhancements that that initially you know spoke to at the very beginning in her long list of enhancements that we're not going to actually showcase but if anyone had any questions about anything about what they saw earlier i'm sure she could touch on those for example the ucf enhancements that we've done neither hierarchy any of that would be a would be fair game and again i'm putting in the chat the link to the ask the experts channel and i will put a link to our bcm webinar next week we do have a question here um how can can we see how the policy looks as a knowledge article and what the ux is for people looking at policies so maybe you go back to that after you're after you're done with this yeah i have to see if i have an instance where it's configured on service portal but um yeah i can show that date so here is a here is an example of confidentiality feature where i have this particular issue and if i mark this as confidential what it does is it by default captures whoever the users are on this particular issue assigned to or assignment group or issue manager they these names get populated into the allowed user and value allow group by default and if you want to add more you can do that as well what it does is it's going to bypass the acl at the issue table level and allow only these users who are mentioned in this particular fields uh and give them access to the record so that's my confidentiality feature and the other feature that i spoke about was the user hierarchy so if i have let's say assigned to user here uh which is karen's zombo in this case if karen has in manager uh who actually does not have direct access to this issue right uh the manager of karen is not an issue manager or is not assigned to issue or it's not even let's say compliance manager or a compliance user but they will get access or visibility into the issue or or the record which karen is actually working on so that's the user hierarchy feature what we've done is we have enabled it for these tables so the confidentiality features are enabled by default on issue observation engagement audit task evidence request evidence request task and remediation tasks um but if you want you can configure these for other tables as well and by default these are the users and groups we populate in the confidential users and group fields so this is a list of all of them and these are two records that we have the user hierarchy enabled for out of the box issue and remediation task so issue manager issue owner um the manager of these users will get access to issue and the manager of sign two will get access to remediation tab so this is enabled by default but you can enable it for other tables as well awesome all right any other question on this not on this one no um once you get back to a uh an instance when people are interested in the unified view i don't know if you have at the top we have compliance workspace if you can click on that you have any other workspaces that are that are up there at all in this instance uh so sorry there we go okay so this this this allows you to move between workspaces very easily it consolidates everything in one place um and then yep and then um and then if you are a business user we have the employee center portal that allows those users to be able to do um acts like policy acknowledgements policy exceptions and not risk events you can also use it for it legal service delivery but that is the um the employee service portal or the employee center depending on who you're speaking to uh you can also you also have your policies there but we also have the the virtual chat bot is there in the bottom right hand corner so if you if you wanted to use our chat bot to be able to do something or look up a policy you can do that also so it is sort of the one stop shop for your business users and this is the employ center portal yeah so this is the employee center portal i know kash has gone over it but i'll quickly go over it as well so as an end user uh we've built this portal which is actually a common portal between different products so if you're using uh itsm and you have incidents uh problems they'll show up here as soon as the risk in compliance applications are installed you'll be able to see this menu on top risk and compliance and this will take you to the risking compliance page where you can report uh an issue you can request an exception or you can report a risk event quickly from here and going back to my home page again you will be able to now see the grc tasks that are listed here uh any grc assessments if i click on to it it'll show you list of control attestation let's take an example of let's say improve uh implement approve changes we've done some enhancement again on the attestation as well i think previously uh we've heard a lot of feedback from customers that we need more contextual information about the attestation so we are providing the description of the control the entity it is related to the control objective it is associated that information here so you can actually uh understand what this control appreciation is about which was not available in the service older service portal before so that's one thing and then once you go to grc tasks it actually takes you to the risk portal where you have see you can see as as a business or end user you have list of tasks that are assigned to you and you can go through all of them and perform them here so this is the same inbox out of you which are your compliance managers or your second line business users also get it so that is my uh grc task page and going back to employee center i see other things so if i want to request uh i have for example requested an exception or reported in the show they all will show under my request so i can quickly go to the issue that i've reported and see the details here uh who it is assigned to what is issue source what is the priority i can talk to the user who is triaging the issue or managing the issue and quickly take actions from here so this is my end user or employee view that i have here we do have one question i was hoping for some clarification um but the i'm not quite sure what you were showing at the time but the question is who should be listed as the issue manager so issue manager is uh usually someone with a compliance role either a compliance analyst or a compliance manager who is or on audit side that's an audit manager or an auditor who is responsible for reviewing the issue and making sure that the issue is resolved and doing the assigned two is a business user who the issue is assigned to so they are actually working on it but the manager is the reviewer or the accountable person who who oversees the issue and make sure that this result got it all right so that's the employee portal um there are other few uh the features one of them is compliance data source registry i'm going to quickly show you an example of what exactly we are doing here so this is my data source registry it is basically a way for providing a quick form which can be used by anyone to integrate with our control objective what i'm doing here is i am um integrating with the policy as a code engine the policy equivalent or codified policy that is uh that is a product or an application which is developed by a devops team what i'm doing here is i am writing or i'm actually selecting the application table i want to associate my control objectives with in this case it's a base policy and what this basically tells you a step-by-step process to identify which is the entity equivalent on this policy that you've connected with so that we could generate entities and controls automatically from our site so it just takes you step-by-step uh the it just takes you to through the process process to identify what is the equivalent entity in this case there are uh entities associated with which are identified as application service which are associated with this policy which uh they they call it as deployable which is nothing but like a test instance or a dev instance or a production instance and an application service associated with it so here what i've done is just configured everything uh here and once i do that this is how it's going to show up so if i go to a control objective i see this related list devops conflict policy and if i click on it it actually shows me a checks or a policy which is a pace policy which is equivalent of a policy that i can connect with my control objective now this is an example of devops config policies uh we you can connect with say configuration compliance checks if you have the config compliance product installed from security this allows you to associate this particular equivalent policy with control objective and then what we do on our side because you've configured uh your data source registry we uh we identify or we already know what are the equivalent entities and we generate the entities automatically as well as the control automatically so then now you can start uh monitoring these controls based on the connection between the base policy for example any other policy and the control objective so this is where we connect our control objective with any servicenow product which has an equivalent check or a policy and start monitoring the compliance against those policies so this is a quick integration framework that we are providing which can be used by uh first for these integrations again we're going to see more on this in an upcoming webinar yes absolutely and last thing is ucf enhancements i already went through it i'm not going to go through the details i'll probably pause here to see if there are any questions that i can take up in last five minutes no actually this has been wonderful i really appreciate all the interaction and the engagements we know we're we're going to be showing a couple more slides here so if you have questions still post those questions but nope there's nothing there right now okay there is oh this is a question is there a session for changes to the audit module we will be doing more sessions later on you know watch the ass watch the community channel to uh to see the new upcoming sessions i did post in chat there's an upcoming one next week for bcm so we will be having more sessions in the future let me go ahead and steal of customer show yeah no so i just want to do a highlight on that uh so what we did in this release in martial is the changes that we did on ordered was were more around uh related to security features uh we didn't add any new feature as such on the audit so if there was a question specifically for audit uh these are the enhancement that we did more around con enabling the confidential feature on engagement observation audit tasks evidence requests so this is enhancement that we did uh along with of course the the new user interface the polaris user interface that you see here is now enabled for uh the entire platform including audit modules so those are the only changes that we did in this mastery sport audit uh but any other questions uh i'm happy to take them up without it that's absolutely true where we'll be having another release in august so uh there'll be more more there and and a few things maybe even in may or i don't see any more questions um can i go ahead and steal the screen from you yep that's it all right i'm gonna grab the screen here and just very briefly if you guys can keep asking questions we still want to see your questions do you see my my screen industry what do you do yeah wonderful um just want to make sure that you can still connect with us we love talking to you we love sharing what we're doing with you um we're very passionate about it we hope that you guys are excited about it too um you can always visit us on the product page servicenow.com risk the ask the experts webinars are out there on the playlist on the chat you can learn more about policy compliance we have a page just dedicated to it and of course we're always posting things on the community we thank you very much for joining us we really appreciate you taking the time i don't see any more questions right now so i just want to thank everybody thank you initially thanks everyone all right have a wonderful afternoon evening and we look forward to seeing you again hopefully next week and in future ask the experts you

View original source

https://www.youtube.com/watch?v=Qv7cpTDFXJ4