logo

NJP

Control Attestations

Import · Jan 05, 2023 · video

[Music] welcome to the how to now series covering features and functionality within the integrated risk management product Suite in this video we will dive into the control attestation workflow from servicenow's policy and compliance application there are many control activities organizations can perform to help achieve their objectives by identifying and reviewing their critical controls one of these key components are control attestations so what are control attestations control attestations are surveys or assessments that gather evidence to demonstrate that a control is implemented correctly the survey results can be used to report on an organization's overall compliance posture let's look at how you set up a control attestation in service now the setup is completed by the compliance manager or compliance admin roles there are three key components of the setup first the question Bank this is a library of questions that can be used within the attestation assessment so you do not have to build each one from scratch next attestation types this allows you to use the questions from the question Bank to build different questionnaires out of the box a questionnaire called GRC attestation is provided finally the attestation designer is an intuitive interface that can be used to create and edit attestations let's see what this looks like in the system logged in is a compliance manager or admin you can search for attestation types once the attestation designer there are three key components the controls tab is used to create new questions and the response type can be selected here for example string which is a text field questions can be categorized and grouped together the questions tab can be used to add existing questions from the question Bank into attestations the category step can be used to add groups of questions additional settings can be configured on each question using the gear icon details such as the name whether the question is mandatory and help text can be amended the question can also be made conditional by creating dependencies with other question responses let's look at the out of the box questionnaire GRC attestation this has three questions is this control implemented comma explain and attach evidence Dot you can also preview what the questionnaire will look like for the respondent and make any updates as required let's take a look at the out of the box control life cycle as a default a control is created in draft state control owners are assigned to a test or self-assess that a control has been implemented after the attestation is completed the control automatically moves to review the review state allows for a final review before the control is then monitored going forwards monitor is the last active state of this life cycle a control can be retired if it is no longer applicable to the organization compliance managers or control owners can view a list of their own controls in the attestation section of the control the assigned attestation type and respondent can be viewed and updated when the control is in draft or monitor state attestation can be triggered on an individual control by clicking the attest button this triggers a notification to the respondent to complete the questionnaire attestations can also be assigned and triggered in bulk the controls that are require assessment should be selected by clicking the edit button the fields such as control attestation type and respondent can be updated in bulk attestations can be triggered in bulk by selecting the controls and clicking the attest button this will also send a notification to each respondent attestations can be scheduled at the entity level or control level and will automatically trigger based on the defined frequency at the entity level the attestation frequency can be set which will be applicable to all controls created from The Entity the attestation frequency can also be set at the control level using the frequency field this will override whatever is set at the entity level the respondent can access the attestation via link provided in the email notification received or via the attestation task and the compliance workspace once the assessment is opened the respondent can view the question set mandatory questions are shown by the Asterix the question is the control implemented drives the compliance rating for the control being assessed if the response is yes the control will be considered compliant if the answer is no the control will be considered non-compliant and if not applicable is selected the control will not be included in the compliance calculations once the questions are answered the attestation can be submitted for review using the submit button now that the attestation has been completed the control moves to the review state compliance managers can view the attestation assessments including each response when satisfied the control can be moved to the monitor stage attestations can be triggered from the monitor State either manually or automatically via the frequency compliance scoring is automatically completed by the system let's explore how this is calculated to calculate the compliance score using the control weight this property needs to be set to True average score of controls based on weighting can be calculated by dividing the total weight of compliant controls by the total weight of all controls this is the most commonly used method but can be set to false if weighting is not required controls in active states only are considered during the compliance score calculation in draft in retired States as well as controls that are not applicable are not included let's look at an example for using the control weighting control 1 and control 2 are compliant and have a total weight of 20. control 1 2 and 3 are active controls and therefore the total control weight is 40. the overall compliance percentage for the entity is 50 percent let's look at an example that doesn't use waiting Ctrl 1 and control 2 are compliant and so the total control number is 2. control 1 2 and 3 are all active controls and therefore the total control number is three the overall compliance percentage for the entity is 67 percent compliance scores rolled up through the compliance and entity hierarchies control objective compliance score is the average of any child control objective and control scores policy compliance score is the average of any child policy and control objective scores citation compliance scores the average of any child citation and control objective scores and at the highest level The Authority document is the average of the citation scores compliance scores also rolled up to the entity level taking the average of all control scores entity type compliance is calculated by the average of all entity compliance scores now we have covered the end-to-end attestation workflow the benefits of using this process include the reduction of manual tasks by automating the control attestation process from end to end including automated notifications drives accountability with trackable assessments attachments of control evidence can be stored in one place and accessed and reviewed when required based on the responses the compliance of controls is automatically calculated and rolled up through the entity in compliance framework structures the results can be used to report on organizations compliance posture thanks for watching for more information please visit now create

View original source

https://www.youtube.com/watch?v=Zqjm7bPBNRE