logo

NJP

What’s new for Policy & Compliance Audit Management

Import · Sep 08, 2022 · video

all right all right thank you everyone um welcome if you're watching us on demand we're excited about that um we're here to talk about what's new in policy compliance and audit management we just had a store release earlier this month which was really exciting lots of great stuff there I'm very happy to be joined by anushri our product manager for policy compliance audit and she's also product manager for our continuous authorization and monitoring product uh so let's get into what we're going to talk about today a couple housekeeping first um it'll be automatically placed on mute we do want you to use the Q a feature we want this to be interactive um the session is going to be recorded you can catch it on demand or you can use our live on servicenow playlist and we'll have information in the chat on that um when the session ends you may be prompted to fill out a short survey so there's been a lot of stuff happening last week we hosted a what's new for business continuity management you can find that on demand now a couple days ago we had a jam-packed hour for I.T and operational risk management there was lots of exciting stuff there that that we showed and there's more coming in more releases obviously policy and compliance is today the devops integration we will not be talking about today or showing today we do have a webinar set just for that but initially we'll be going through the other new features and then operational resilience is next week so hopefully you found the registration page you have registered for all the webinars out if not please mark your calendar for the August 23rd webinar operational resilience is one of our main features in Tokyo that we'll be talking a lot about vendors management is awesome next week and then we round out our webinar series with the devops accelerator on September 13th this is an integration between devops config and policy and compliance management and in our irm applications so with that I'm going to turn it over to Industry who's going to talk a little bit about the features and actually going to show you them in action which is the really exciting stuff today I will be taking you through the it compliance workspace which is a new feature that we released in our store release the workspace provides the re-imagined user experience and the Persona based workspace for it compliance manager uh as part of the workspace the ID compliance manager uh has the dedicated home page where they can view the IIT compliance posture as well as perform various tasks assigned to them there's a unified task page where they will see they can see everything that is assigned to them assigned to their team and things that they need to watch there's also issues designing cage which provides the overview of all the it related issues that the IIT compliance manager need to follow upon or remediate each record has an overview page which provides the summary of that record the list menu provides the list of modules which shows the data which is relevant to the it compliance manager we have added a functional domain domain stagging functionality where ID compliance manager admins can actually tag various records as it compliance and risk and when they are tagged as it compliance and risk those records or those particular reports will be shown on the it compliance manager workspace with that let's get into the demo I have logged in as an IT compliance manager and this is my it compliance workspace when I come to the it compliance workspace I can see the overview section here at the top which provides me overview of all the different Authority documents which are nothing but regulation standards Frameworks which uh which I need to review and it provides an overview of the percentage compliance of the all the regulations over time the trend chart around of the regulation how they are trending uh on the compliance score over time you can also see specific high priority issues or high risk exceptions against these regulations or standards and the compliance score percentage calculated for them all the standards regulation that you see here are tagged as it compliance and risk so it only shows me the standards regulations that are relevant for me as an IT compliance manager the policy here again are tagged as it compliance and risk so I can only see the it compliance or IIT risk policies here and I can also see the compliance score trend of the policy uh over over a certain period lastly I see a number of entities that are tagged as it risking compliance as well these are mostly the cmdbcis or the entities related to cmbbcis which could be business application Business Services even vendor table can be tagged as it risk in compliance the percentage uh score here shows the percentage of compliance score over over a period of time so it's a trend chart here on the entities report here you can also see the high priority issue as well as risk rating if there is any associated with the entities the next section shows the control effectiveness of the uh of the it compli it compliance and risk controls the first reporters around their control testing so it shows all the open control tests if there are any overdue control tests they are shown here and you can also see failures in the last six months so this is a trend chart of the failures the second chart shows the indicators which is used for continuous monitoring of the controls there are 32 active indicators zero overdue indicator tasks but 32 of them are unassigned so I can quickly understand what I need to do as an ID compliance manager and go ahead and assign them out I can also see failures in the last six months so this is a trend chart of indicator failures of the last six months the last report is on the attestation so any open open applications that are in the system any any one of them which are overdue would show up here and again the trend chart of failures in the last six months we also see the summary of all the different issues that are related to it controls you can see there are 150 open issues three of them are overdue two of them are accepted issues uh three of them have policy exceptions or issue exceptions against them and three of the exceptions um that are created are also expired so I can quickly go to these issue and see what's going on I can also go to the issues overview page uh from here when I click on into it I'll get to it in a bit and the last section is our tracking section where you can track all the different audit engagements that are going on on different ID comply ID entities or uh ID controls there are three engagements here um and out of three engagement there are 23 ordered tasks which are overdue there are no overdue Milestones so we don't see anything here and the timeline chart here shows the upcoming audit engagements that I need to watch out for or I need to prepare for the timeline also shows the Milestone on top which which I need to track and there is an exceptions report which will show you policy exceptions uh against it policies or I.T controls and it also shows there are two high risk exceptions uh the strength chart shows the uh the exceptions which are requested versus approved and the ones that are extended so you can see how many are requested approved are extended lastly you I can see the acknowledgment campaigns which are uh the policy acknowledgment campaigns there's one policy acknowledgment campaign that's going on and there are 10 responses or 10 tasks that are signed out of which um some of them are accepted some of them have not been responded to yet and some of them are one of them is declined so this is my home page uh which provides me an overview of I.T compliance posture on the right hand side I can see a summary of all the different tasks uh that are pending or awaiting approval or something that is overdue I can click into it and go to the task page directly apart from the home page I do have the unified task landing page which will take me to all the tasks that are assigned to me anything that is assigned to my group uh and that and and the things are uh uh let's say in this case engagements or control tests that I have created or and I own on the pending task you can also see different filters here if anything is in overdue uh overdue state or in progress I would be able to quickly filter them out and see so as an I.T compliance manager I would be able to see all the different tasks in one single page this is the issues overview page where I can see all the different issues in the system I can at this point I can see everything which is non-it2 but I can filter down it uh down this to the ID risk in compliance when I do that it only shows me the issues that are associated to either ID control or IIT policy so here I see the issues break down by state by issue type um by issue rating or priority I can also see overdue issues uh aging chart By Priority by issue rating so I can see if there are any issues that are overdue I can see that there are 31 or there are issues that are overdue more than 30 days if there is an issue triaging going on in the system I would be able to see the issued features as well by state by issue type by priority and the issue triage aging by priority as well the tracking section will show me the remediation tasks associated with these ID issues any exceptions created on the issues any evidence request tasks associated with the issues and lastly the performance of the issues how many issues are open versus closed on the right hand side I would be able to see all the issues that I'm managing I'm reviewing assigned to me or uh or maybe the remediation cards are assigned to me anything that is overdue same for the issue triages and I can also see my group's issue so if I have any issues that are uh that are that don't do not have any owner or do not have any manager I can assign them out if anything is over to you I can quickly go ahead and assign them out and see if they are resolved same for the triages and lastly I can see the issue triages or mediation tasks that I'm watching I am on the watch list uh I can quickly come here and see it now lastly I see the list of different modules here um and in these modules I would be able to see a filter condition which shows me um the functional domain is it risk in compliance which means if I open one of the records here let's say let's open one of the policies here if I go to policy form I would be able to see that this policy is tagged as I T risk in compliance you can see that there's a new functional domain field added to all the records and you can choose the functional domain here whichever records are tagged as it risking compliance are the only ones which will start showing on all of these modules so any controls are attached as it risk in compliance any entities are attacked as it risk in compliance um the policy acknowledgments that are created on it policies or exceptions that are requested Almighty controls and policies audit engagements that are performed on it um ID related entities um and so on so I I can see everything which is filtered down to the data that I care about as an IIT compliance manager now how do you manage tagging of this data we are providing you mechanism to tag the data so if you go ahead and tag base table such as Authority documents policies entity Etc we're gonna trickle down that tag to its child tables so for example if I go to entity table and if I if one of my entity is tagged as it risk in compliance I am going to automatically tag all the controls issues issue triages observations Etc that are associated with The Entity so this will help you with the tagging of the records there is an initial one-time setup but at the end uh everything will be tagged automatically so this is uh all I have for this feature um so for the policy exception which is an existing feature we have done a bunch of enhancement this release uh we have provided an ability to extend the policy exception multiple times which wasn't possible before this is based on multiple customer requests we've got um we also are allowing an ability to edit the extension reason uh while taking an extension um or exception reason which is uh which was non-editable before so it's an optional field that the customer candidate if they want to change any reason for extension or otherwise also if they want to change a reason for uh for the exception the third feature that we've added is the detail risk assessment so ability to perform detailed risk assessment on an exception using our Advanced risk assessment uh feature so the user will be able to perform video risk assessment and populate the risk rating based on the assessment uh We've also done some other enhancements such as uh while requesting an exception from service portal or employee Center uh if you've set up a verification rule this was an applicable for the exceptions which were created from the hospital employees until it was only applicable for the exceptions which are created from Upstream applications like vulnerability response Incident Management before so we've opened it up so that if you have set up a verification Rule and if you request an exception from a service portal apply Central it would go through the verification approvals as well so that's the enhancement that we've done another um enhancement that we've done is we have we are marking the policy exceptions which are approved and expired as expired so previously we only had closed State we didn't have a expired substrate for the approvals which were actually expired so we've added that so it becomes easy for reporting and customers can identify which are the expired exception versus the ones that are just closed out and lastly we are also allowing a requester to withdraw or cancel the request when they requested exception even before it is approved so if they don't want it anymore they can go ahead and cancel cancel the request so that's the additional feature that we've added how does this feature work so this feature is enabled when you install GRC compliance management workspace when you install that it automatically installs the policy and compliance management plugin as well um and if you have the advanced desk assessment plugin installed then you can use the risk assessment feature that we have enabled so with that let's get into the live demo so I have a compliance workspace here I've logged in as the compliance manager I've already created a policy exception um as a requester so I'm going to go into list of my tasks and let's go to my group stuff and under policy exception I can see an exception for implementing change so this is an accession that was requested by able tutor let's look at the details here um which has the awaiting maintenance window as reason um and this field is editable you can edit and change it uh let me go ahead and assign myself as the approver and save it now while uh approving the exception you have different ways of approving this you can sell uh you can perform the risk assessment on uh exception and only then you can approve it so currently uh the previously we only had risk rating so you could choose only one of the risk rating from the drop down but now we are allowing uh you to select either a risk rating or you can select another meta method such as take risk assessment when I click on take risk assessment this risk creating field is now non-editable uh so let me go ahead and save it once I save it it is going to enable this accessories button on top so if I click on that it's going to uh create a risk assessment for me so I'm going to go ahead and click on accessories and I have myself as the risk assessor but I can choose anyone from the compliance team as well as from the risk team with the risk user or compliance user role as risk assessor you need to provide certain um risk assessment roles as well for anyone to take the assessment so that has to be done as part of the setup so let me go ahead and send the risk assessment risk assessment and risk assessment is created under this a particular related list let me go to the risk assessment and I'm going to start the assessment let me go ahead and save this and once I have it uh saved I see that that is creating is calculated as medium I'm going to go ahead review and submit so once it's reviewed and submitted under policy exception you can see that uh it's been assigned the risk rating of medium and if I go to my form I will also see that there will be a machine that is populated here oh let me go ahead and request approval and also submit it once it's approved it's going to now assign the risk grading to my uh policy exception right now I can see that the risk rating has been assigned to policy exception uh this is being copied from my risk assessment now this first case rating is uh mapped so the a the risk rating coming from the risk assessment is mapped with the drop down values of the risk rating here we have a mapping table with this race creating when populated in case uh the compliance manager needs to override this discrete they can always click on override and choose a different risk creating if they want to um if they don't want to they can just go over this risk creating and in this case I'm going to go ahead and keep this frustrating and once this risk rating is available I can see that I can approve this policy exception I can also request an additional approval if I want to or send it for a review but I'm going to go ahead and approve this policy exception for now all right let me go ahead and also associate impacted controls once it's done then I can approve the policy exception so the policy exception is now in approved state now let's look at the second uh enhancement that I've done on the multiple extensions so I'm going to go ahead and log in as um able tutor who's the requester of the policy exception and this is a employee portal that we are looking at let's go to my request and look at the approved policy session that we have here so this is a proof policy exception has all the details and it also has some actions here and you can see it has request extension UI action here once I click on it it's going to give me some information about the extension it is telling me that your wallet from valid two dates it is also telling me that I have remaining extension which is one the reason why it is showing me that we have a property which it can be um which you can set up to say how many extensions are possible uh if you have like five extension that are possible it's going to give me number four that there are four extensions or or one extension file extension that are remaining because I have not even asked for any um if there is only one extension which is uh possible uh it will show me that there's only one extension which is remaining in this case the property setup has one extension that's also that's why it is only showing me one but you can have multiple extensions um set up in the property I'm going to go ahead and um provide justification and in this case I can see that the extension reason is populated based on the previous extension region but I can go ahead and change it as well if I want to let's go ahead and change it and uh let me request the extension let me also change the extension date to a week and request it once it's requested then you can see that the substrate is under review I'm going to log in back as Carrie who's our approvert now under my task I can see that there is a policy exception which is awaiting my approval again so I can go into the details here um and see what is the extension date if I want to change that date for some reason I can do that here I can also see the extension reason which is different from the original reason if I want to change that I can do that as well so once that's uh all the information is available I have the rest creating from the previous one I can go ahead and approve the extension I can reject the extension I'm good with all the details here so I'm going to go ahead and approve the extension uh you will also notice that I have approved extension as zero year but the remaining extension is one once I approve the extension it's going to give me a approved extension as one so uh every time an extension is requested you will be able to see how many extensions are requested so as an approver I would have an information before I approve the next extension if I have too many extensions that are asked and approved I could ask questions to the requester on why so many extensions are needed and by the if they're already approved so I'm going to go ahead and approve this extension now once I approve the extension the the approved extension becomes one year one now and remaining extension is zero because I've set set up only one extension possible in the property and you can also notice that my extension date has been copying copied over to my valid to date and my extension reason is copied over to my reason so this is what happens when you uh when you approve the extension now uh this extension uh we've already looked at multiple extension and requesting or performing the retail risk assessment now the third uh enhancement that we did was uh changing the substrate to expired when it approves extension or exception actually expires so uh I could either wait for this date to appear and this particular policy exception would be automatically closed out or expired but since uh it's it's a weaker Tool uh away I can't show the automated approval exception closure so I'm going to go ahead and close this extension instead so when I close this extension since because it is approved it will be closed as expired so I'm going to go ahead and close this exception as the approver When I close the exception you can see now that the state is closed but the sub state is changed to expire so in this case um all uh anyone who comes and looks at the list of policy exception they would be able to report easily on the ones that have been expired all right so that's my third enhancement now we're looking into a couple more uh enhancements here so I'm going to log in back as uh as admin and I'm going to set up a verification rule foreign application here so let me go ahead and save this verification rule if I don't choose any source application which means this exception is not created from any Upstream application it can be created from service portal or employee Center uh let's shows one of their users here and submit it let me go ahead and now impersonate as evil tutor let's go to employee Center and requested policy exception foreign let's go ahead and submit it now when I submit from here let me go back to uh to invest in it as so when I submit the uh policy exception from from the employee Center and we've set up the verification rule we can see now if I log in as maxjerson um I can see that there should be an exception which is created and uh it it is uh it is a new state and not analyzed it which is ready for verification so let me go ahead and for yeah this is the one that we've created so I'm going to go ahead and open this and you can see that uh this particular policy exception is still in New State and there's a verification approval created for Mac uh so I can go ahead and approve it as soon as I approve it it will move to the analyze state so this is now enabled for any exceptions which are even created from Simply from service portal or employee Center I'm going to go ahead and approve this once I approve it this particular exception will move on to the new state let me also choose an approver here so as soon as we approve the verification approval the policy exception will move to the analyze state that is one more enhancement that we've done now let me show another enhancement that we've done let me impersonate as able tutor here and go to list of requests let's open up this policy exception now this policy exception is in analyze state it hasn't been approved yet so and if I look at the actions it gives me canceled request action which means I can cancel the policy exception request before it's approved in case I don't need it anymore if something changes I can go ahead and cancel the request so when I cancel the request the state of the request will be closed and the substrate will be canceled so I'm going to go ahead and cancel it this is one of the use case that uh we've heard from customers as well as uh the other other products from service now when we are doing some indication with let's say devops configuration there's a use case that developers want to cancel the or withdraw the policy session they were not able to do that before so we've done this enhancement and now you can cancel it out so let me go ahead and cancel it once I cancel it the state will be closed and the substrate is coming thank you so evidence requires as I mentioned as an existing feature which allows an audit manager a compliance manager to request an Evidence when they're performing uh let's say a before performing control testing in an audit or as a compliance manager you will be able to request an evidence for a given control for a given issue entities from your business user which is part of the who is part of the first line User Group now uh currently evidence request will allow you to request new evidence for a given control for a control test even if that evidence was already collected maybe in last quarter for the same control with this new uh enhancement that we are doing there are few improvements that we have done uh we are providing an ability to reuse already existing collected evidence that was closed so if you have collected an evidence for a given control in the last quarter during your audit engagement you would be able to reuse that evidence uh by adding it to the new engagement or entertainment that you are working on currently another nice thing that we've added is we provide a prompt user uh with the information on an existing evidence that might have already been collected for a given control for a given issue entity Etc so they can quickly go to it and can reuse it they can also uh request an evidence for any type of record we had some restrictions restriction around this based on the type of order you're performing if it is audit uh a team who is requesting an Evidence versus compliance team who's requesting an Evidence we had restricted the tables that you could request an evidence for but now we've opened it up so as an audit manager you'll be able to request an evidence for your controls control test your engagements and not only that but also for a policy Authority document citation Etc and same for the compliance managers so they would be able to request an Evidence on any of the policy compliance and audit tables uh we've done some minor enhancement we have we are copying the name of the evidence uh request task from the evidence collection uh evidence collection detail form previously it was copied over from the evidence request which is a parent table since evidence collection detail is a uh is is a table from where the evidence task is actually generated it makes sense to copy the name from there so if they made that small change we are copying the description of the evidence request task from the evidence request because that description field is on the evidence request with where the user would be providing some description of the evidence request so these are few of the things that we are doing and uh we're also allowing to copy evidence from the previous evidence request into the New Evidence request and things like that um how does this feature work uh once you install the compliance management workspace uh you would be able to request an Evidence on near the compliance and audit forms it installs the policy and compliance management plugin automatically but you need to install Advanced core application or Plugin for the evidence request feature to work so if you're using just the compliance management workspace or you need to install Advanced code and it will automatically install the compliance management workspace business or policy and compliance plugin um if you're using audit workspace and you want to request evidence as an audit manager you can install audit management workspace which will automatically install audit management plugin you need to install Advanced core application or Advanced audit application for the evidence request to work so this uh this will allow you to enable this feature so let's get into the live demo let's look at an engagement here I'm on the compliance workspace here logged in as an IT compliance manager I am performing the socks order 2022 and I have a list of entities that I have scoped in controls that are associated with The Entity and I have two evidence requests uh tasks that are closed out here and collected now let me go ahead and try to request an evidence for one of the control so I am trying to request an evidence for this control I'll select it and once I click on request evidence this is a pop-up which pop-up which already exists today but you can now see that there is a prompt or alert on top which says there is an existing evidence that may be relevant for your selection so I can click on view and it will open up the list of evidence that is associated with the selection I made so I can see that there is uh an an Evidence collected for this particular control if I want to reuse I can see the details here it was closed it was assigned to Able tutor the the due date was July 29th and uh and so on so if I want to get into more detail I can do that and I can go ahead and reuse this evidence if I want to now um how do I view the evidence so if I go under evidence related list uh previously I could just create new evidence requests but now I also see a new UI action which is ADD existing evidence so if I click on it it will give you give view or give me list of evidence that has been collected and closed out in the past so I can see there are there are different types of evidence collected for different controls here I can see the request reason why it was requested what was that you did what was the close date right when was it closed and uh what was the uh instruction what was the evidence requested for and who the requester was so once I have all these details I can decide whether I want to reuse this already collected evidence or I want to create a new one so if let's say I want to reuse this one here I'm just going to go ahead and add it once I added this evidence is now associated with my current engagement as well so if I go to the evidence you would be able to see that evidence for is for the new engagement as well but if I go into detail the evidence for originally was requested for the manage changes control right but now it is also associated with the engagement so you would be able to see that uh M2M relationship of the evidence with the engagement that is a new change that we did this is a new related list that we've added where you can see the associated multiple records for which shares basically this evidence now if I go back and if you want to remove this evidence from the engagement you could do that um I would try to remove two of the evidences here once I do that it will give me some messenger so it is telling me that uh confirm you want to remove these evidence like items and it says that the following um will be removed but not deleted from this engagement so it is just giving you instruction that this particular evidence will be removed it won't be deleted uh when you remove it and the second option or the second message says the following cannot be removed because they were created from this engagement uh the first one was the one that we just added from another engagement or another control that is the one since we added it can be removed from engagement but the other evidence request that I see on this engagement is Created from this engagement or requested from this engagement itself so I can't remove it if you want you can always go ahead and delete it as a requester or as an admin but this removal capability will be available for the ones that are just linked to this engagement and not really created from here now we'll be able to see the third use case which is ability to associate uh evidence from another request so if I go here uh let me actually go to a list of requests and let's see if I have I have one of the evidence requests here I will open it up and I can see that there is already an Evidence associated with it and um I also see a button on top so I can go ahead and add existing evidence from some other evidence request into this evidence request so I can go ahead and add it and once I do that it will be available for the user so you can reuse the evidence from some other evidence request as well we can also see a new evidence request let's go to list of engagements again so this is my evidence request if I'm creating a new evidence request here let's go ahead and create a new one when I'm creating a new request you can see the type field that you have here was locked down or read-only before so if I click on that it now shows me audit and compliance um type so you can always go ahead and choose any of them so this particular type is editable for me so these are all the enhancements that that we've done on evidence request awesome demos I hope you're as excited about it as I am I want you to connect with us please you know visit us on our servicenow.com Risk please join us on the community and again please watch us live on demand and you can use this QR code to get to the on-demand portion of the community thank you all for joining us thank you anushri for presenting I really appreciate it and please tune in next week for some more of our what's new webinars

View original source

https://www.youtube.com/watch?v=I1_j6zRgJ0w