What’s new in Operational Resilience Management
we're going to be joined today by osman and i am roslyn wardle and we're going to be talking about what's new in operational resilience management thank you so much for joining us and we'll just get started now uh it's top of the hour on the east coast and thank you so much for joining us today a couple of housekeeping things we're going to get out of order um you're on mute so if you could use the q a feature to ask any questions that would be great we'll get to as many questions as we can throughout the session and the session is going to be recorded and shared on the community forum afterwards after the session ended ends you may be prompted to fill out a short survey and this is just for our own feedback it's not going anywhere but we do appreciate your participation and feedback just to help us improving i wanted to go over a few of the other sessions that we've run already this month and another couple that are coming up so earlier this month we went through business continuity management and that was aswan and that was in a very engaging conversation we also had it and ops risk management policy and compliance and audit management just happened and now as you know we're talking about operational resilience we're going to be talking about vendor risk management later in the month and then coming up in september we will talk about some of the dev ops accelerator improvements and enhancements that we've brought if you have any questions or thoughts about those or would like to see other ideas again you can put ideas in the chat q a however you want to share with us and we'd be happy to try and get topics that are are of interest to you and keep addressing those throughout the year so without further ado i'll introduce you to osun aswan is our principal product manager and he's responsible for both our business continuity management and our ops res products and i am roswell marvel as i said and i'm a product marketing manager here at servicenow so the three operational resilience features we're going to highlight today are business services importance and impact tolerance analysis and scenario analysis and i'll just give you a quick overview of each of those and then i will pass it over to osman who will be able to demo each of these features for you so the first one is creating and maintaining business services customers who are already tracking business and technology and application services can now bring them into ops res and the reason to do this is to understand dependencies within context and we're providing for you a 360 degree tabular view across your suppliers facilities people and your technology pillars this enhances the understanding across each of these areas and provides business context for the service with your grc data from the cmdb and oswin will detail that shortly the second feature is the importance and tolerance assessment similar to recovery time objective in bcm you need to understand the impact and importance of all services and products to delineate the impact to your customers your organization and the market for any downtime associated with a product or service this feature is pre-configured to support many of the regulation requirements that are out there it assigns impact and tolerance and includes workflow to support the approval process and there's built-in scoring and calculations so this is the second feature that aspen will talk about and the third feature is a really exciting one that i think we'll spend a little bit of time on which is the scenario analysis for operational resilience while there's always the possibility for an unexpected event to occur planning for and testing multiple scenarios and having an understanding of their measured impact to business is critical for your operational resilience with scenario analysis um you can design and simulate events as well as record and report on the findings and it allows you to identify the different ways that critical businesses services could be interrupted and the point of which those disruptions might become a risk by conducting this analysis teams can plan ahead and they can bounce back more quickly from any disruption so i'm really excited to bring this to you today as well so oswen i don't know if you want to take over control and share your screen and provide a demo that would be fantastic sure just a second and again if anybody's got any questions throughout the demo please open the q a and we'd be happy to try and get to as many as possible all right i hope you guys can see my screen thank you so i've just uh searched for operational resilience right so this is the new release that we did in the 4th of august right earlier this month that's when the latest release for operational resilience happen so these are the capabilities that we have added in this particular release we will go over them if you have any questions please put it into the q a section we will discuss those questions and feedback whatever your comments are and then we can proceed to the next topics uh as we move on with the demo right so the first thing that we want to highlight is the uh business services view right so the business services view has been created for operational resilience managers right and operational resilience users the same can be also assigned to the service owners as well right so if you have already captured your business services as part of the cmdb that gets reused here you don't have to key that in again right so if you have captured the business services and the i.t dependencies as part of the cmdb that gets entirely reused in operational resilience solution so you can see this is a very similar view to the cmdb so all of this information is uh residing in the cmdb there's nothing new that i have created here rather what we have done is we have created a view of the same record which is specific to operational resilience managers so if i go into the different views that are available for this record there is a default view right there is an agent workspace view there's a compliance manager view and there are multiple options right similarly we have added one new view called operational resilience so if i go into the default view you will see the same fields here and this is where the business services uh have been captured in the cmdb when i say business services this is sitting in the table uh labeled as cmdb underscore ci underscore services and the type or the classification of the services business service in the same table you will also find technical services and application services right so these are more internal so for the purpose of operational resilience we are interested in the business services that are delivered here and customers so we have filtered out only that and we have showcased it as business services here right so this is the default view now if i switch to the operational resilience view you will see some changes in this related lists let's see what that is so if i go into the operational resilience view [Music] just give it a second let it load all right so these are the same fields that you see at the top and the related items and the dependency view that is there in the cmdp there's no changes to this right so the user would be able to view all the data that's already captured as part of the cmdb but in addition to this what the user would be able to view is this particular section where these related items are stored in the operational resilience management tables right so here you can see there is a hierarchy of the service itself so some of our customers call this as the top level service or they call it as a group service right so in this example i've taken payments as the group service and under payments there is something called retail payments right that is my service for which i am the owner i am looking at everything around that service now that's the idea that i want to get on the inside that i need to get from this view so the retail payments again is split or is divided into child services so this is like a hierarchy of business services that can be managed in the system so there's a top level item there is a mid-level item and there are child services as well right and it doesn't stop with three levels it can be n level of dependencies that are established so under retail there are sub classification of retail related services and then we have the processes that are related to my service or the child services so these are all the in internal processes or the activities that my team has to carry out in order to ensure the delivery of this particular service right in in case any of these activities are not completed on time chances are my service will not be delivered 100 as expected to the customers right so that's why we need to understand what are the internal activities that needs to be completed in order for my service to seamlessly get delivered that is the processes tab here and then we have again further dug deeper and we have pulled out the assets that support these processes or activities right when we say assets this can be of type facilities or equipments for example it could be one whole facility or it could be an equipment in the facility these are all dependencies of type facilities right similarly you can also see there can be certain functions or business units that the processes depend on without these functions or business units or key personnel the processes will not be completed because the processes would not be completed my service will have a downtime again it's the same point but then from a dependency perspective and how these are connected to my service same way you can see there are supplier related dependencies as well so these are some of the suppliers that are needed or their services are needed for the processes to be finished or completed in a successful manner the fourth pillar we are calling these the pillars that is the technology pillar these could be your applications and id infrastructure that your service is dependent on again the service is not directly linked to the underlying technology or supplier of people dependencies rather the service is linked to these are the activities or processes internally that needs to be carried out and the process processes in turn are related to these suppliers and technology uh as well as the people and facilities dependencies so that's how the dependencies are identified this in terms of regulatory requirements sim simply maps to the service dependency map right so you need to look at your service identify and list all your business services that's number one then identify what are the dependencies for your business service right so this is the first step where you'd be able to look at the entire dependency and it stops with this that is here if you are looking at it like a compliance exercise for your resilience regulations this should be good enough for us to say we have completed the dependency mapping but we did take it further into the next steps wherein we know there are a lot of grc data sitting in top of you know servicenow's platform right so there is an issue management system we look at some of the examples here and there are issues getting reported on every day right basis and they are classified as critical or not critical uh they have their own workflow somebody's working on it they are the owner for it they have a planned start date and end date uh that is the due date right so you you'll be able to see here all the open issues the current open issues right and which asset are they impacting because the issues are not getting reported at a service level the people who are working the front end are identifying and resolving issues at the asset level or probably at a department level similarly at a supplier right so it could be tagged to any of these underlying assets that are supporting your service so the idea here was to bubble up all of these issues that are overdue and are still open even beyond the planned end date so that the service owner gets a view of what are those red flags in other terms these are the red flags that i need to be uh looking at because of this issue not getting resolved some of these let's say for example one of the id infrastructure elements is going to experience a downtime because of which the outbound payment processes are not going to be completed and because this process is not going to be completed my service will experience a downtime right so the impact are is bubbled up the chain from the lowest level of dependency item to the process and from the process to the child services from the child services to the actual service that the service owner has to look at now the same view can also be you can look at it from the parent service or the group service as well just that this will include all the second level services and the related assets and issues so it's like a dependency chain we keep building and whichever level you want to log in and look at the underlying dependencies and the red flags you'll be able to dig deeper into that similar to issues we also pull in the information from the risk assessment capability this is basically based on the residual risk right so this is the residual risk score the common item that you see here across all these sources the residual risk has been identified as high so we just highlight those risks that have been identified for a particular asset or a department it could be a people related risk or it could be a cyber risk or it's a vendor related risk right so all of that is collected and we still use the same dependency mapping the the risks are identified at this asset level right and these assets somehow are supporting my my service because they are linked to the process and the process is rolling up to my service so that is the risks part of it and for this data to flow in we use the advanced risk assessment capability that's a risk management software application we just pull the information directly from there same thing from policy and compliance management um you'd be able to see these are the non-compliant controls or in other terms the failed controls right so these are the controls that we have and these have been tested recently and they have been marked as non-compliant right uh the reason these are getting highlighted in my dashboard is these controls are related to these assets and the controls can be of different types so we use this terminology called pillars and we classify them as whether they are technology related controls issues risks etc like the assets itself and so on same way there's facilities people and suppliers there are four pillars out of the box but these pillars can be configured for example some of our customers had this requirement of splitting the technology related items into two one is the technology item and the second one was data they wanted to maintain data as a separate pillar altogether and provide it its own attention right so we will be able to configure that we will look at the admin level configurations at the end but for now this is the construct right so this is a structure in which we are using the grc data and bubbling that up to the service owner same way some of the other things that we have included in this release are the change requests that are open currently there are certain changes that are being done in the system and getting tracked now and these are related to certain assets and these assets are rolling up to the process right and then they will roll up to the service same way these are the open tasks for example it could be an audit task right the audit task is still open nobody is completing the audits so we want to track those what are those items and you can always go ahead and filter it based on the priority let's say you don't want to look at all the open tasks or all types of tasks right you can filter it saying it should be a follow follow on task and it should be open and it should be of high priority right so those can be done pretty easily so you will get only the relevant items getting highlighted in your dashboard right so same way these are the open incidents the incidence comes from the incident management capability this is all of your id incidents right the open ones so you would be able to see the open priority one and as i said the state will be open or new uh those incidents get highlighted here same thing these are the current outages that are getting uh tracked right so these are the outages and degradations basically these are the items we flag as red flags for the service owner right we will go into the business continuity plans importance assessment and impact the scenario analysis next but i'll take the pause here let's look at if there are any questions this is the first view we created for the business service owner as well as the operational resilience manager and business users so aspen i don't know if you are accessing the q a or if you'd like me to uh read those two i i am uh looking at the liquidity right sorry i figured you would you're that good thank you yeah i'll go over the questions and we can take up the answers and then we can move on so the first question we have here is is the view available with a specific role through grc or irm so the role is operational resilience manager an operational resilience business user these are part of irm application these roles have been added already and you'd be able to access this view via that room the second question is what is the relationship of business services application and technology yes so the the relationship between business service versus application and technology service is many to many so one application service might be supporting multiple business services right similarly one business service might be dependent on multiple application services right so that is many to many that is default cmd the parent and child services relationships are maintained in the cmdb that will get pulled in automatically into the operational resilience module so there were some customers of ours who [Music] had this requirement where the cmdb was not measured yet right so they wanted to maintain the relationship within the uh operational resilience application right so as when as and when the cmdb matures they wanted to replicate the data there so what we have done is if you have the data in cmdb it gets pulled in here in this view right if you don't have it you can still go ahead and create those relationship within the operational resilience application which will not be written back into the cmdb it will be a local copy that is maintained in operational resilience whenever you think it is um mature enough and you want to maintain it as a single cmdb for all applications ids might on devops operational risk management audits all of them at that point in time you can very well move back into the cmdp that's how we have structured it now uh the next question is uh are the asset information can automatically link to relationship yeah so if you have this already in your cmdb be getting uh you know identified via the automated fashion or through a manual entry as long as it is in the cmdb we pull that into operational resilience you don't have to maintain that manually every time like i said this is a mixed set of use cases that we did get from the customer base some of them wanted to do it manually for example if it is not application right it is something like a people dependency there is no uh automation that is there or if it is a facility related dependency right so these data have to be keyed into at least one of the tables in servicenow as long as it's getting keyed in we'll be able to replicate that into operational resilience management the assets are the entities that's the next question yes that is correct uh behind the scene the data model is based on entities we create them as entities and then we maintain the relationship there that is what is the next question is uh so the service mapping whether the parent and child services adopting from the service mapping as long as it is getting added into the cmdb it will get pulled in uh based on and schedule job that runs right you can set it as uh let's say once in every four hours uh the operational resilience view has to be updated with the latest data in cmd or let's say one of every one of them right as long as it is there in the cmdb it gets pulled in that's how we are doing this and then we have one more last question uh in related lists the failed to control change request an incident um uh yeah so these are getting pulled in based on the assets right so all of these things that you saw this will be the same structure so basically this is the change request right and the change request is related to this particular asset this asset is related to the process and the process is related to this particular service that is how the change requests are identified same way you will see the tasks right the tasks are created and they are tagged to a particular asset and that asset is rolling up to some child service that is one of these four right retail uh child services and these child services are rolling up to my business service that's why these are getting attract here same thing with incidents you'll see the same structure here also there is one incident here and it is related to a particular asset and that asset is related to my service same thing with outages you will see that right uh issues also right these are the assets that are getting impacted because of this issue and they are rolling up to one of the processes and the process rolls up to my service same thing with high risks and controls as well so all of this is based on the relationship of my business service and what are all the different things it is dependent on and because this dependency is established whenever there is transactional data getting captured as part of grc practices all of that can be pulled in i can establish the relationship and the relevance between those grc data and flag out what are the high the hot spots right or the red flags that needs to be shown to the service owner or the operational resilience manager so these are the some of the ones we also have the vulnerability uh response management integration and hr cases etc coming up in the next releases so you will see those also come up here and in the current release this is based out of this user interface the immediate next release is in february when we will have the workspace ui for the same view and others that we will see as well right so there there's a very nice looking dashboard coming up to highlight all of this like you might have noticed there's a lot of data here right there's dependencies there's issues n number of rows of data because this is collecting information from across applications so there are some enhancements planned but for now if you are looking at implementing the application you can very well do that and start collection of the data we have multiple releases planned for this in the upcoming releases all right so this was the business service once we have the idea of the business service um the dependencies the next thing is you need to identify how critical is your business service i am the owner of only one business service in the system right let's say there are 2000 of those or 20 of those so i need to identify with what classification or criticality should i report this as right earlier till this point in time in the cmdb the user had to go in here and then simply select one of the values right so now what we have done is we wanted to bring in some method for calculating this right and this is called the importance assessment then some of our customers call it as critical business services cbs right critical business services so to understand out of which business these business services which ones are critical and which ones are less critical we added the survey-based capability where you would be able to take an assessment and based on the answers to the assessment the application will provide you a suggestion on what should be the criticality because we are comparing apple to apple right so all services are put through the same set of questions based on the answers for all the services we would say some of the services are critical some of them are not and some of them are medium critical let's say right so we will look at one of the example here this has a workflow as well we'll look at how the questionnaire is set up etc so this is the workflow um not a very complex workflow it starts with draft once the drafting is done and the person who is the assessor who needs to provide the answers to the questions would get it and this will be in pending response once they have provided all the answers it moves into response receipt once this is received if there is an approver which is optional right someone can review and approve your responses uh it will move on the uh from pending approval to approve and then you can close it right or at any point in time during this workflow if you think this is not relevant and this needs to be cancelled the user can simply say this is cancelled right till the point it is in approved status it is considered as a valid assessment and this will be picked up in your reports that's how the workflow is now let us look at the details of this assessment right you can provide a name for your assessment you can provide a description for the next person who is going to take the assessments let's say right there's an opera generated number that's a state which is actually the same values as here this is currently in approved state and you can say who's the owner and who's the assessor um the owner will be asked to select a particular questionnaire template we will look at what the template is right based on the template the user will get those many number of questions to be answered once you have selected the template you would be able to select these are the four services for which i want to do this assessment now right so there are four services that we have selected and this is the assessment itself so here if i answer this questionnaire once the answers hold good for all the services that i have selected here if i want um different answers for different services then i can create those many assessments as needed i will not be having all of these in the same assessment i have one for each of them right so we have provided that's flexibility as well so let me open up this assessment now just a second all right so this is the view for the end user who's providing the assessment right who's providing the answers so here broadly we have classified the questions into three categories right uh impact on customers impact on the firm and impact on the market so this is out of the box however you guys can go ahead and change it there's a graphical user interface for this you guys will be able to change whatever is the categories you can increase this to let's say seven or ten as well as under each category you can change the questions as well right so these are the questions so the user can provide for example this is a check box right multiple select so what are the kind of customers who use your service what is your customer base right what is the number of vulnerable customers who use your service so the user can provide these answers the same question is posted for every service owner they will provide the answer based on their service right so once these answers are provided we would be able to assign these answers with a numerical value behind the scene basically if i select 76 to 100 percentage for example right impact on market stability or let's say uh the financial impact is between these two values this is my answer right based on that uh behind the scene each answer has an score or a value assigned to it so we would be able to calculate the financial impact and say it has got a three point so i added 0 1 2 and 3 as possible scores for each of the questions at the end of day i have like 13 questions created and answered so based on the value that i have for each of this question i will get a total score and based on the total score i would be able to say which of these services or the service itself is important and what should be its impact tolerance so it's currently driven off of a single uh survey right so it calculates the importance right and it also calculates what should be the impact tolerance this is only an example i have taken this can be changed right so let me show you how this works behind the scene so if i go into the setting which is under the administrative capabilities if for my service after i provide all the answers it scores anywhere between let's say 0 and 25 let's say my score was 12 right so the application would go into this mapping table look for this and then see what is the importance uh you have scored 12 so it will classify my service as not critical and it will assign an impact tolerance of four days same way if i have a score of let's say 89 right so it will know this is the row that fits in right so it will classify my service as most critical service and the impact tolerance is one day right so this is the table behind the scene from where we calculate these importance and impact tolerance for every service but it doesn't stop here the user can however go ahead and override what the system has calculated that's what you're seeing here right that's an optional thing based on the answers provided by the user the system calculates these values right because this is already approved that's why you're not seeing this as editable but the user would be able to go and change whatever the system is suggesting in which case they are forced to input a rational for it so that it can be used in your reviews and approval okay so that is your importance um assessment and impact tolerance assessments so that is number one uh i'll stop here let's see if there's any questions on this and then we can go to the next topic i think there's three there are three questions okay i think the first question is from the previous view that we were looking at mapping off mapping of risk to failed controls okay we will definitely take that up um let me go over the operational resilience questions first right uh operations okay yeah that's a great question so operational resilience appears to be dependent on multiple sn modules right what is the foundational sm modules that are needed for operational resilience so uh the operational resilience application itself is a part of irm professional skew basically if you have irm professional you will already get entitled to operational restraints and if you see most of the capabilities that are there in the operational resilience revolves around irm so that is your risk management control test etc right the only additional capability that operational resilience currently interacts with and optional it is optional and pulls in data is from business continuity management so if you have business continuity management as well as irm professional you're covered so all of the capabilities that we are seeing will be part of uh your entitlement already so if you don't have the business continuity management operational resilience will still work it's just that the business continuity plans and exercise results will not flow back into operational resilience you would still be able to get all of your dependencies the impact tolerance scenario analysis the services view that we saw as well as the dependencies right so if i go back into that if you see the faster retail the example that we were looking at right you will still be able to see all of these tabs right all of the values getting pulled in as well only thing that you will not see is this particular tab here this will be heated that says business continuity plans same way in the dashboards there are multiple reports that gets pulled in based on the exercises in bcm we pull in the results the plans the areas which don't have a plan etc so those are the only areas that we will not be able to uh utilize without pcm other than that everything else will work because either they are already part of the platform for example change request tasks incidents and outpages they are already part of the platform failed controls high risks and issues are part of irm right and this is nothing but part of our cmdb which is part of the platform again so you'll be able to get all of them in fact an important assessment we just discussed which is part of operational resilience you will get entitled to that as well we are going to look at scenario analysis next all right so um is the assessment capability setup process the same as we have in irm that is correct um i will show you how the assessment capability we can set up what would be the limitations the next question is what would be the limitations if client wants to just go just with bcm and does not have irm pro if the customer has only bcm and does not have irm pro operational resilience management will not be available for them today so operational resilience management the prerequisite is irm professional or enterprise one of them vcm if they if they purchase only bcm or license only bcm they'll get only bcm application uh they are not going to get entitled to engage okay now if i go back to the assessments so this is assessment template it is the same concept like you do your risk assessment uh setup right so this is the template questionnaire template so the administrator can go in not all the users so you'll be able to see these are the categories right and under each category there can be multiple questions so i can have multiple questions under this let's just pick one of them right i can pick let's say customer base right just give it a second so you can for some reasons taking time just a minute guys okay there we go so you'd be able to see uh that this is uh of what type the question right and i can also say what are the possible options uh what would be the value in case user selects this as the answer this one and this one so the possible values are here and this is what we will be using for our uh calculation right so this is the same assessment engine which is part of the platform that fuels that assessment basically you'll be able to set up individual questions and the possible answers once you have the individual questions and answers then you can create categories and group them under categories once you have the categories you can combine all the categories and create one template itself right and that template is what you will select during an assessment which will be used for all your uh basically sending out the questionnaire survey to the people and getting their answers that is what this is um i'll we will take up the risk failed controls and risk mapping uh we'll just park that for now suraj um i will finish the operational resilience topics today right um if time permits we will definitely jump into the risk and control otherwise we will answer that over email for you guys okay so that is your second functionality that just got released that's the importance and impact tolerance right so once the importance and impact tolerance is done the next one is the scenario analysis uh before i get into the analysis itself let me show you some of the setup parts for that right there is and concept of event groups event groups are created for you to do reporting in the future basically you'd be able to create these as event groups uh as categories right so you can provide a name and then a label to be used in the system and this can be a hierarchical choice list basically you can have technology related events people related events itdr or infrastructure or control test failure events etc right so i just created some for example here once you have this event groups created the next thing is to go ahead and create the individual events itself right so the individual events can be something of this nature like some of the events that you foresee that can happen or it could be based on certain exercises that are done in pcm right so you would be able to uh use the same kind of uh you know taxonomy here and create these and once you have the events created you'll be able to tag it to the group uh the right group as well right so you'll be able to provide a name for the event a description you can say whether it is active or not in case you want to use this for references in the past and you don't want this to come up in the dashboard going further you can simply say this is not active anymore right so that means this will be in the system but it will not be available for selection any further the reason is if there is a reference to this particular event in some of the analysis that we did let's say in 2018 those data will still be preserved but it will not come up for analysis any further so that was that one this is the event group just a classification once you have the events created the next one is to create your scenarios scenarios are like a container of events right so i can have one scenario let's just take this as an example i can create a scenario i can provide it a description again here also i can make it active uh this is the id that's getting generated and i can classify the scenario into what are the different pillars that it's going to impact right so this again is used for reporting and classification uh you can add the different events that needs to be part of your scenario itself right so there's a facility outage then there's a power outage there is a commute that is getting taken out etc uh so you can add in number of scenarios i mean events from the existing event list basically right and once you have added it you can do is you can provide an order for this particular list of events so this is the same order in which it will be available for the operational resilience managers to analyze during your scenario analysis so but the user can also inject new events during the analysis that is injection of newer events during your analysis phase itself but this is the master list of events and scenarios so this is maintained by the administrator so there can be multiple scenarios and multiple events this is an end-to-end mapping right so there can be multiple events as part of a scenario as well as one event can be part of multiple scenarios as well right so that can be used uh once the scenarios and events are defined in the system the next one is for the user to go ahead and then [Music] create an analysis so let me see if i have some good data here okay again so for scenario analysis also there is an out of the box workflow so initially the operational resilience manager would be able to provide a name and a description for their scenario analysis uh there's an auto generated number you can call out who's the owner uh this person would receive any clarification or any question on this record right going forward let's say somebody is looking at it and then says i need to get some clarifications owner is the person who is responsible for maintaining all the relevant data and clarifications that's the purpose of this particular field there is a plan approver and the result we will look at what this is in a minute the user can say uh what is the actual start date when it should start the analysis should start right so once the user has filled this in um the operational resilience manager would be able to say these are the different services that we need to consider for our analysis basically right when you pull in the services based on the importance and impact tolerance assessment that we saw here right the latest one uh the application will pull in the relevant importance and impact tolerance as well this is the empty field i think we were doing some testing here that's why you're seeing this but otherwise ideally you should have all your data right each service can have a different impact tolerance for example the first one has an impact tolerance of one day and then 12 days and so on 4 hours 24 hours whatever that is based on your questionnaire that you provide answers to this would be calculated so that's your scope for your analysis right this is what we need to test then comes the participants you're going to say there are people from different uh facets of functions right or functions basically this user is to be participating in this analysis and they need to be representing the technology role now this role is not the same as the roles in the platform tables but this is just an indicator we will see what that is so oops sorry about that i should have clicked on a different link okay there you go so you can say which participant what is their role this is only an indicative list that i have added right you can manage your own uh set of rules that you want to use during your analysis right so i've said someone from hr someone from legal finance technology people data supplier and so on so you'd be able to add in the right set of rules add in the instruction for that user and you can like that build and list of all participants who need to be part of this analysis once you have identified which services to test who needs to be testing this together as a team the next thing is to say what are the scenarios to be considered if you remember we created some scenarios and parked it as a master list right so here the user can simply go in and say these are the scenarios we need to be conception so as soon as you pull in the scenario you will get the relevant events lined up in the same order that we mentioned during the uh the master list right so once you have the events uh the the scope the participants and what scenarios to be considered are finalized you can submit it for an approval that's when the plan approver will get it so this is before the analysis happens this user would be able to review okay these are the services the team is going to test this is the team who's going to take the time out for testing this these are the events they'll be considering once i know that i can approve it i can be a two and pro once approval is done uh on the day of the analysis people get an email they can participate in this so this is where the input goes in right so let me just open one of the events here so i'd be able to see this is the event this is the event group this is the description of it what is the scenario we are looking at now currently and what are the pillars it's impacting i can also see what are the who are the other participants if there are separate list of participants for only this event they'll get listed here what is the potential start date and potential end date time of this particular uh [Music] scenario event right and then once i am done with that i can go into the notes i can say these are my observations right these are my gaps and these are my recommendations for this particular event what are the vulnerabilities that we need to plug in what are the controls to be strengthened i can make all of those notes here in this release these are captured as an uh comment field or a rich text field right in the next release we will be actually integrating this with the observations capability and the gaps will become your issues and recommendations will become tasks in the servicenows platform so that's something that is coming up um but for now this is how your input is captured right you can add in all your commentary here but next release onwards that is in february 2023 onwards this will have its own workflow so you can have multiple number of observations and gaps and recommendations for the same event right once this is triggered you'll be able to say uh this particular event is done completed right so based on the input provided for every single event uh there's a duration for each one of this right based on all of this there's a summation and once all of these are aggregated together you simply compare it with the impact tolerance of every service and see if it has released that impact tolerance or not so this is your scenario analysis capability we have added in this release right now there was also one more request from some of our customers um instead of adding events and scenarios and checking all of this they had a simple use case of all i need to do is just pick up us pick up an asset and see if how many services will it impact if that asset goes down right you've not added it as a separate form together today uh but you'd be able to still pick up one of the assets from here let's say for example let me just see if there's any good example here there is an attachy just hold on please so if you pick up any of the assets from the list uh in the data model that we have created for this you would anyway see all those uh all those uh relevant um you know the upstream downstream entities and what are those um you know services and processes that you're going to take out in case your asset goes down in this case we are going to be impacting these many different business processes these are the upstream items right and these are your services that will be going down as well in case my server goes down so that can be achieved today that information is available but in the next release we will create something like a form where you would be able to just say these are the assets to be considered what are the services and processes that will get impacted but for this release what we have done is the scenario analysis is based on certain events and scenarios that can be created and maintained by the administrator that can be used by the uh operational resilience managers so this was the scenario analysis capability we look at if there are any questions uh okay so the question here is how is this scenario analysis different from plan and exercising management in bcm application so if you look at the scenario analysis part there is no plan involved in this right um there are no recovery tasks that are getting triggered basically you're just looking at what are the scenarios that can go wrong and saying what could be the impact in case that actually materializes right and you're just saying what would be the potential start and end date time or the duration that's all we are capturing here for the scenario analysis um the the exercises from bcm will become an input for this basically last time when you tested let's say one of the servers went down and it took us let's say 48 hours to bring that back up again so if it is the same scenario that you are testing now that would become your answer or the data substantiating your day saying whether it is 42 48 hours or 72 hours or 24 hours whatever that is for that kind of an event so the exercises will become an input here but this in itself is a different capability the exercises in bcm actually triggers the victory tasks somebody executes it actually brings up back again the let's say and server or one of the processes and then says this is the time taken for it right that is the difference um yeah so the next question is the observations will be the same as audit management yes so the observations will be the same as the audit management observations um we will be reusing that issues will be from issue management and observations uh not the observation the recommendations will become the tasks in the generic tasks in servicenow's platform so can the software find potential bottlenecks from input given into a scenario um so these are so that's what i was trying to explain so you can go look up for one particular asset and look at what are all the different processes and services that will go down and experience analytics right if you are looking for further information on this and if you have input let us know there and i'm glad to connect and see how we can add that into the software right we do have some uh additional capabilities coming up on this um but i'm not sure what you're looking for right uh the remediation tasks yes so this next question uh the uh the task that you are looking at what we will be doing is let me just show you probably the clans of this faster so when we are looking at the tasks related to a particular service for example these are all the tasks right this is my service and these are all my tasks now there's an additional capability here where i can simply click on new and start up a new task right so when i say new you'll see an interceptor page here what type of task would you like to create right you know there are a bunch of these things right so making it simple uh for all of you guys what we have done is we just exposed this one right this is called the interceptor you're seeing this button because i've logged in as admin otherwise this wouldn't be there if it's a business user you'd simply say i want to create a follow-up task or if you want to create a remediation task i think it should be somewhere over here right and so on so you would be able to filter this out based on what is your business requirement and only make that available for the end users so uh we've just opened it up right so these are all the different kinds of tasks that can be tracked so when i say the recommendations can be tracked in as tasks it will be the same experience basically you click on click on start new and you will end up on this one once you have chosen which one that you need to use probably you don't want to have all of these right all of them might not be relevant so you can just click on one of those and that should start working i hope that answers that question um all right so um yeah so today we were looking at only the operational related operational resilience related item the mapping of controls and risks is one of the open items i know kumar had suraj had one of those questions still open we will get that answered over email to you right or if needed we can we can set up a follow-up session with you to connect on that thank you so much with that said we are on top of the r and we have uh kind of looked at all the questions open uh so that's what we have for today it's demo thank you yeah thank you so much aswan um i'm just gonna move forward and uh conclude this out if there's additional things that you're interested in learning about we're uh connected on the community um obviously our website and you can always watch our live on service now on manned uh episodes thank you so much for your time today we sincerely appreciate it and we look forward to joining us again on another upcoming episode talk to you soon thanks a lot and have a great afternoon
https://www.youtube.com/watch?v=cZSTin-P4KE