Do I need a mature CMDB to Implement a Risk Program?
all right all right good morning good afternoon and good evening everybody I appreciate you all taking the time out to join us um today we look forward to today's session I'm Anne-Marie Fernandez I'm a senior technical product marketing manager I'm based out of Danville California and I will be moderating today's session so this session is going to be the first of four sessions to talk about foundational type topics we've got um also a couple webinars we've got a ton of webinars but complementary to these foundational sessions we'll have quarterly we also have a monthly session from Florida Lee College in emea that's going to be talking some more of The Cutting Edge really cool stuff so look out for those um and Aisha will be sending out the link on how to register for them um so uh the first question the first thing that we're going to cover today is do I need a mature cmdb to implement irm on servicenow this is a kind of a common question we get from customers so we are going to try to answer this question for you today um and today I have Matt corwall who will be introducing himself yeah thanks Emery and uh good morning good afternoon and good evening to everybody joining from around the globe uh my name is Matt Orwell I'm a principal business process consultant as part of servicenows Professional Service organization uh that we refer to as expert Services uh I've been on the now plat or I'm sorry I'm based in Minneapolis Minnesota and I've been working on the uh now platform since the Kingston release and have been with servicenow uh for about two years really excited for today's topic awesome awesome all right so we've got a couple housekeeping things before we get started so we've saved uh time at the end for some q a but during the session feel free to ask questions along the way um be sure to use the Q a button versus the chat um just because then if we don't get to your question we can more rarely grab that um the questions and answer them so next week we'll be having a follow-up office hours and we can take those questions and answer them there um and also share them on the community so this presentation is being recorded and will be shared on the servicenow community and also after the event we will be sending out a survey we would appreciate your feedback so we can aim to get better every single time um and next is a little plug yeah thanks Emery uh so part of why I am so excited to be here today is that in addition to discussing with you all uh the Confluence of irm and the cmdb I also have the privilege of representing servicenows uh risk and resilience expert Services team and if you don't know who we are uh we're a group of Highly skilled Technical and business process experts that can help solve any and all implementation challenges that you might be considering uh we are uniquely positioned in that we have expertise across all of the servicenow uh irm domains uh meaning that while today we're going to be talking about a lot of the core functions of integrated risk management uh we also for example have key uh resource and experts in the Privacy ESG and business continuity domains and so my uh my call to action for all of you today is if you like what you hear and you want to learn more I'd encourage you to either are connect with me on LinkedIn or reach out to your local account team that is supporting you from servicenow perspective thanks so much Emory all right all right so before we get started just to get to know you all a little bit better we've got two polls to kick things off the first thing is to just best describe your cndb implementation level today sorry is it ad hoc meaning no governance or none at all and this is your cndb um not your irm the second question is going to be around irm so ad hoc developing um your cmdb has some governance around it it's used operationally maybe an incident problem or change or it's got a defined governance and configuration management process and you've got the services defined as well with some Auto data population and then sort of the highest level is you've got governance and strategy executed around your cmdb implementation and services defined and automated data is coming in and flowing in foreign so looks like we've got a lot of uh folks answering um I think that let's see if there's any more folks submitting can you see the results Matt no not yet oh you can see it okay good um all right good okay so it looks like we've kind of got like a little bell curve going with a lot of folks with a defined governance and configuration management process so that's awesome um let's go ahead and launch the next poll um this one is around your irm implementation oops sorry all right so um describe your irm implementation today or integrated risk management one are you thinking about purchasing servicenow integrated risk management are you licensed but undeployed and maybe there's just low usage uh or maybe you actually have it with several products but maybe it's just inconsistent deployment and then the last is license completely um completed your initial deployment with expected usage um all right so it looks like we've got a lot of folks that are in the licensed and deployment with a good amount of folks also in the first and two levels which is good this is the uh we were hoping that we would get a lot of folks in that area and we'll give a couple seconds uh to then go ahead and get started uh give I'm sorry give key people a couple minutes to finish the the pool all right awesome awesome okay good good thanks for answering those uh poll questions um so today's agenda we've got really simple agenda we're going to answer three questions one what does the same DB have to do with irm anyway um then our main topic for today is do I need a mature cdb to implement irm on servicenow and then we've got kind of a fun question at the end where we're going to put Matt on the spot and ask him if you were a director and just purchase servicenow where would you start and then Matt's going to do a quick demo um all right so uh here we go so uh the first question Matt so what does irm have to do with the scene DB anyway yeah so this is a common question uh or or inquiry that we get early on and conversations we're having with customers that are considering implementing servicenow irm and so the way that I like to think about this is that servicenow irm is unique in that we grew up as a product alongside the core strengths of the now platform meaning at the center of how we think about measure and assess risk and compliance in the Litany of things within irm's capabilities are that assets services and business-based risk and compliance is Central to our data model um and that's you know a good opportunity to introduce this idea of the servicenow common Services data model the csdm and we are going to talk a bit more about that later as was mentioned during the agenda but what this means in Practical terms uh if you're somebody who is new to servicenow or are considering servicenow is that our irm solution is designed to operate as part of your ecosystem of known data points within the servicenow environment and that more excitedly if you know what's most important to you and you know where your known data points are you're well on your way to better protecting that which is most important to you and your business by leveraging irm as a solution so that's where I like to that that's really where I like to think about this is cmdb is going to inform where your data what data you have irm is going to help to inform what you need to be protecting what you need to be measuring and what you need to be taking action on and those two things are designed to interact and and mesh really well together which I do believe we are rather uniquely positioned in the in the irm market to uh to help customers achieve that both in in Rapid value but also in a way that allows for scalability into the future foreign for the next question absolutely all right so um can we talk a little bit more about um why we're all here which is do I need a mature scene to be to implement service now well I kind of gave the answer there sorry uh no problem uh you know one of the big things that I say is you don't need a mature cmbb to implement servicenow irm what you do need to know is what data is being used to inform decision making and ensuring that that data is accurate and relevant so that isn't to say that everything needs to be included but those areas that you're going to be focusing on emphasizing on the areas that are driving key Either non-compliance key risk so so on and so forth you want to have good data that you're making decisions on um and as I think was pretty well represented during the poll question earlier many customers tend to sort of see themselves at differing levels of that Journey and so rather than trying to tell you sort of a one-size-fits-all approach to solving the challenges of your cmdb I like to think of this more so from the concept of starting with what's most important so as an example uh your critical business applications your critical Business Services or those things that are really um going to be most impacting as far as your ability to operate your business to interact with your customers so on and so forth and so from there I consider what your key business drivers are so first you're defining right what are my key business processes what are my key uh critical business applications now think about what driving what's driving those so do you operate in a heavily regulated industry um you know if for example Financial Services or other areas such as that med tech so forth consider beginning with a framework driven compliance program so look at you know nist uh cyber security framework uh the center for Internet Security uh we've got a number of different um regulatory driven Frameworks that you can start with um where you can then begin to marry those together um but let's take another example so are you the type of organization that's operating an environment where risk informed decision making is going to be key to sustaining and or growing your business right so thinking about the stock market you know maybe an easy way to think of this is you've got your your growth stocks and you got your your value stocks right so maybe you're the type of company that making informed risk decision making is going to be crucial to you out competing it's going to be crucial to you holding off competitors so on and so forth and if that's the case then you might consider going with more of like a programmatic risk identification and assessment process as a starting point however the good news is regardless of where you choose to start you can breathe easier knowing that servicenow underlying all of this is supported by robust workflow from an end-to-end perspective and the data model that's designed to grow with you and mature as you mature that way you're positioned uniquely to be in a position where you can start with what's important but so long as you continue to sort of work within the guide rails that we've helped to set up within the common Services data model you can also feel comfortable knowing that over time you're not going to run into upgradability challenges you're not going to outgrow Your solution as you continue to mature and really you're going to chart a path where your investment might be incremental but your maturity and your scalability is really going to start to look more you know logarithmic right it's gonna it's gonna accelerate that much more quickly yeah and there's kind of a new thing called csdm the common Services data model Matt do you think people get confused between csdm and cmdb and do you want to maybe flush it out a little bit for folks yeah so so I think of of csdm uh and I've got a I'm gonna have maybe use my analogy more than once here but um I like to think in an analogous terms so think of servicenow as a platform as your coloring book right uh in csdm they're gonna be the lines on the page so telling you where where to color with it cmdb and irm are really sort of the they're the colored pencils that are going to help you to to draw your Masterpiece out of this right so the idea and and I'll bring it back to the the uh depiction we have up on the screen here is cmdb is a process that drives you know accountable ownership and governance and and so on related to the management of your it assets your business services your business applications all of the different things that you're going to see in this lower sort of chunked out area csdm is saying we know that we know that cmdb is vitally important to the servicenow platform and here's how we can fit in with everything else that we offer as far as an integrated solution is concerned mm-hmm thanks Matt and and also to clarify a lot of folks think cmdb is that orange infrastructure data but CSM includes the foundational data as well right so everything in in the green so the key thing is for for risk which is the this a lot of colors on the top is really we take that data from the foundational csdm and then bring it into irm but what you're saying is bring it into bring in what matters most right and you've got the guard rails of csdm to make sure you don't get yourself in trouble yeah exactly I mean to grossly oversimplify irm uh if I may in effect what you have are information objects that you want to measure those could be office locations those could be data centers those could be people those could be processes those information objects are then measured against a set of criteria that criteria can be risk derived so what am I what are the things that that are drivers of my risk those can be compliance derived what are my internal policies or external regulations but at the end of the day really servicenow is built uh service on irm is built on this concept of basically templatizing everything that's required to get you to what do I want to measure and how do I want to measure it um and and csdm I think of is as as a process that's going to keep you on track and and you know we talk a lot in the servicenow world about you know out of the box versus configuration versus customization and that doesn't totally alleviate that conversation but what I can tell you is from an underlying data management and data quality consideration you're going to keep yourself very much on the straight and narrow and you're gonna you're gonna grow as the platform grows and I think you know the customers I see Mo being most successful in their use are the ones where when changes happen they're readily able to embrace those changes and kind of lean into the new functionality versus those customers who kind of see service now as you know it can do anything so build it as anything and now it's started to see more as like a threat of when new opportunities come in rather than an opportunity awesome yeah all right so in a way people like to think of it as maybe a platform on top of the platform would that be accurate yeah absolutely it's a that's a great way of thinking about it and it's a it's a platform on top of a platform that can talk to the other platforms too um and that's really where the you know that's where we get into the the so much value can be derived of identify the information that's most important to you one time and use it throughout your environment and irm is as a spoke from that but you know there's there's going to be that you're going to learn as you mature your processes other value plays that you can start to use that data to drive more accountability whether that's you know one of the good examples and I don't mean to get too tangential here but another area where we commonly see organizations mature from sort of where they're at to where they want to be is to stay well now that I kind of understand what's most important to me I'm measuring it and I'm working on it now how do I put a sustainable program in place to assist with that well I can tell you that from something like a APM application portfolio management there's a natural uh Synergy that can happen there where you know as your next thing now that I've I've measured and I have an understanding of that which is most important now I can start to look at what's also emerging and am I staying ahead of the trends or am I falling behind and do you know and how do I need to course correct so that we can continue to uh continue to optimize rather than sort of claim victory and then stagnate from there on out makes sense makes sense um okay so let's move on to the next slide uh one of the things that we also wanted to show you all is this is the new view of um operational the operational resilience dashboard um in Utah um is available and uh this is what it looks like so essentially think of operational resilience as more of a dashboard but there's a lot of architecture behind it too that we wanted to show you all today so again this is the new UI but um if you look at it uh in the the old UI or the UI 16 this is really just a service record called retail payments for example the record above this will look like a typical cdb record where you've got your dependencies the one thing that we wanted to show you here is for the service if you bring in your parent Services child services or your processes either in your either from doing a Bia or from your cmdb um what uh operational resilience will do is take this data based on your services and create the dependencies and put them into pillars so you'll see we've got facilities suppliers technology and then there's other pillars as well so it starts to classify these dependencies right so the services depends on um not just I.T but suppliers as well so all that all these dependencies get brought in from your services and Child Services and then once those all the assets every asset gets brought in then it relates all the operational data so like your incidents your change requests your issues any risks vulnerabilities all that kind of gets tied together and you can see it from the operational resilience workspace here so um this sort of red dotted line boxes out what we call um red flags um or think of it as indicators of instability so if there's a lot of incidents happening outages all that data sort of coalesces onto this workspace and we can start to see like something's going on with this service so this is a really powerful way how the scene DB really will support um your services structure and again the Bia is another good sort of quick uh quick and easy way to get started so if you know your critical services use the Bia and that will bring at least this data in to get started uh all right anything you want to add to that Matt uh nothing specifically around around features but I think you know just to sort of drive my point home previously about seeing seeing new releases as an opportunity rather than a threat uh what's going on with an OP with Ops res is is a really is a really interesting and unique opportunity to start to bring together the the various parts of servicenow irm right because there's a there's a risk component there's a policy and compliance component there's even a business continuity component um and being able to embrace those right through staying aligned with our data models staying aligned with uh intended functionality is going to put you as a customer in a place where you can take advantage of these quickly and effectively and so you know I would just sort of use this as to serve as a reminder of if you like what you see here and you think that this is cool more cool stuff is just going to continue to come out and the better position you are the easier it's going to be to continue to consume the new features on functionality that's coming out when we as we mature the product further awesome yes and use the coloring book right use csdm to guide you all right so so this is just a quick takeaway for folks matter did you want to yeah I just uh so so when I speak with customers one of the areas I like to to begin the conversation around is is just understanding you know what what drives your your your compliance your risk your your security organizations right and so if your focus is for example uh you know looking along the left-hand side here think about considering your scoping um of of what it is that you actually want to measure right so using the example of Sox compliance I know that this is a this is one that uh many of our spreadsheet uh spreadsheet based customers who are kind of struggling to get out of that that vicious cycle um like to look at that and just say you know if I could even just automate uh automate how I'm measuring the the parts of of socks that are really causing the most pain for my business owners and are causing the most pain for my assessors and so forth we'll just start by ring fencing those business applications that you know are are relevant to socks again you might not have all the data but your regulators and your external Auditors are certainly going to tell you whether or not an application needs to be compliant with socks so if you know it is ring fence it and start to put the right controls around it so that you can more effectively manage it and I would sort of apply that logic of of Define what's most important put a nice ring fence around it and then go measure and take action against it um and that's really you know this isn't meant to be overly exhaustive it's meant really just to say hey if if you're struggling to sort of understand you know what do I all have in play out here you could be forgiven because there are a lot of different things that are driving uh risk and compliance in this current environment that we're operating in but if you can even just figure out right what's your top ten heck what's your top three uh you've already got a great place to start from to then inform how you want to take next steps awesome awesome all right so this is just a guide uh for folks to get started um and one thing I just wanted to call out here was when you're looking at the the tables that you want to go up we see customers use for their respective um needs whether they're Financial or um needing to comply with PCI or socks a lot of these are not necessarily infrastructure type um um records that they'll associate to their control objectives right so a lot of it is service related ownership Related Group related so as long as your group data sort of that foundational data is good you should be able to get a very robust um irm program using servicenow right and I do think there's that's a great you keep me up so well Emory to to Really Right drive this point home of yes you know and I mentioned this earlier when we were talking about how irm sort of grew up alongside the cmdb we're also not unique in that respect within the suite of applications that servicenow provides right and and so as irm has matured along the eye the core sort of I.T Centric pieces as have many of our other areas right and that's where I I I I overwhelmingly and resoundingly agree with this sentiment of like it doesn't just have to be your I.T assets right this can be it can be anything by which your cat currently capturing today and where you have even a little bit of confidence in what in your data well that that's enough to get started right and if you take nothing away from this webinar but what I'm about to say take this away which is enough to get started can lead you on a very long fruitful path getting caught up in do I have everything am I collectively exhausted am I mutually exclusive am I this am I that am I that you will always find reasons to delay getting the value and so you know I really do just want to reiterate this whole idea of you know don't be afraid of an MVP don't be afraid of yeah starting with with a subset of your processes and then looking at how can I mature them from there how can I prioritize my backlog well you can't get to a prioritized backlog until you first and foremost have something that you can put a backlog against so get the value get to using the application and then figure out what's going to be most important next yeah and then so Matt a lot of times folks will have a parallel project going on at the same time to have their cmdb either um going back to baseline or getting more accurate or just getting more healthy how do you reconcile those two projects uh irm project and cmdb project going on at the same time at some point they're going to intersect right and so you're saying let's get started with the MVP but when we do have good data how do we then pull those together so without going into too much depth on uh software development practices of you know starting in your lowest environment and promoting up from there um I would say where you have those those perceived choke points of where there's other work streams that may impact your your your time to value I would say you know at risk of stating the obvious here be collaborative and be communicative um your your platform owners are you know first and foremost most company platform owners want more use on the platform so don't shy away from your core teams and and understanding how they can help you as part of what they're working on rather than how they might hold you up but the second part of that is you know also at risk of being obvious here don't let don't let Greg get in the way of good either if you know that if you know that your cmdb team is working on a six-month project to to clean things up then then chart your course so that you can you know perhaps use dummy data when you when you're developing and getting things ready and then when you know that that's going to go live just orchestrate your implementation and your go live so that you're achieving mutually beneficial outcomes because again you know the the the the really awesome benefit that you can achieve here too is if they were already doing the cmdb cleanup and now as an added thing they also are achieving positive outcomes in in the governance risk compliance irm space well you're you're just building more allies that are going to help get behind how you want to drive your program forward so to me not that that's not that's not a risk that's an opportunity right that's a chance for you to have a seat at the table that's a chance for you to be building relationships with your core team that's a chance for you to build your relationships with your data owners your data custodians and the people that frankly are going to have to keep this stuff up long after an implementer like myself is gone exactly and then I and then I was also saying that I mean that's a that's a really good point and then also once the the cdb or CIS the infrastructure CIS are populated whatever it is those are things that matter to you so those are things that you'll probably want to start bringing into your risk program right um and then there's also indicators right so let's not forget about indicators um and and that level of granularity might fit better right with the the sea ice so as the cmdb gets more populated with your networking things your servers and all that infrastructure stuff you may rather use indicators anyways than assign them to risks yeah and again though uh you know indicators for those who are uh unindoctrinated it's just a nice it's just a fancy way of describing continuous monitoring uh but you can't apply continuous monitoring to a process that you haven't first set up right and that's that's where I want to bring this back to by identifying what's most important by figuring out what either your external regulators or your internal management is prioritizing you've now got a program that you can apply continuous monitoring to that you can leverage indicators for that you can start to look at you know driving automated issue workflow so that when you do identify something it's getting to the accountable person as quickly as possible those are all pipe dreams until you first and foremost plan to stake in the ground and you say I need to manage and I need to measure that which is most important that's the place where you want to start from that's where you want to mature from and you may find that once you get there your priorities are going to change over time and what you thought was really important maybe won't be the case and the reason you thought that it was important was because you know until you started getting some of the insights you're seeing from this collection of it data of personnel data of office location data of external regulatory data you didn't really know what was actually uh what was actually throwing you off course anyway yep good good advice um all right so let's answer go to the next question Matt if you are a director and just purchase service now where would you start Road mapping um Road mapping wise or product wise yeah so um excuse me uh so first and foremost I would focus on outcomes right uh what do you want to protect how do you want to measure it and who do you want to inform about those outcomes um I think starting from this place of we we want to consume more licenses of irm probably not probably not going to lead to the best outcomes or you know we want to digitize something just to digitize something I I've seen customers fall into that that snake bit before and realistically it never leads to sustainable results if you design with outcomes in mind you're going to not just make yourself happier with how much better you're working but you're going to make your stakeholders and your management teams happier because they now have better information to then drive the next series of outcomes off of you start with compliance or risk or audit yeah yeah so so many times the answers to these questions are going to depend on what kind of organization you are uh I mentioned this earlier but I think it's it Bears lynching again um you know starting with risk that could be the right solution for you starting with compliance that could be the right issue if your audit Department's on fire maybe you just start performing audits uh in service now because it's just it's going to alleviate a tremendous amount of pain where to start is going to be a bit subjective and so I don't want to sort of take like a firm and fast point of view on that because often that answers rather nuanced but what I will say is I would start with the content that's already available on the servicenow store to identify the regulations which best suit my needs so as an example to that today we have content packs that align to sarbanes-oxley we have content packs that align to nist 853 we have content packs that align with uh the center for Internet Security benchmark and they're just available to go download right and so if I'm someone who's already sort of feeling a bit overwhelmed by the breadth and the scope of like how am I going to go about attacking improving this you know spreadsheet email smoke signal program that I'm having to operate or that I inherited just use the content that we've already that's already there uh tried and true vetted because what's that what that's going to give you is everything that's inclusive under that regulation and then it's going to let you look at okay so of that what's you know what what do I really care about right if I'm looking at nist and I'm in an industry where physical and environmental security is crucial to me well maybe maybe I maybe I narrow down my scope to focus on that right maybe right now you know I'm a I'm a company who's dealing with some customer trust because of you know my internet boundaries that I'm I'm defining for people to come in and use my applications and resources well if that's the case I'm probably going to start with the center for Internet Security and I'm going to focus on standing up a controls program that's going to help me defend the perimeter right and then in doing so I'm going to get ancillary benefits vis-a-vis increases in consumer trust um that can then go on to say all right well now that I'm actually you know I got controls I'm measuring them I know that I'm increasing my consumer trust uh and my my regulatory trust well how do I now think about scaling that right because whatever benefit I've gained is probably not where I'm trying to get to so then it then that's where the whole maturity mindset starts to come in oh sorry oh no I I was uh just gonna sort of close that thought by by mentioning right as well so I know I'm talking a lot about uh information objects talking a lot about what is happening in the external environment but another area where we we tend to see customers have pretty good information uh and and in my opinion only uh I think it tends to be because the lawyers have to look at them before they get published it's also policy information so I I generalize these Concepts into regulations or what external parties tell me I need to do policy is what management and the board tells me I need to do well if I know my external regulations are accurate and by the way I can get them for free on the content store and I know that I have good policy standard compliant that type of compliance data because Management's not going to accept that that that's out of date or inaccurate or or not aligned to you know the vision and the the goals of the company um well I can basically sort of marry those two together so that I have visibility into my internal priorities my external obligations and the things again overlying it with the the csdm idea is I also know what's most important in which I want to protect now I've got basically the the Run book for you know the early goings of standing up an irm program so if I were coming in and somebody told me hey this isn't working we need to have something that's that's going to be better I would start there you know the biggest thing I would I would sort of say not the biggest thing but with the idea in mind that this is also an approach that's going to take days and weeks to get to Value rather than months and years um and I do think it would be uh I'd be remiss if I didn't also acknowledge that part as you can you're gonna get to a production instance more quickly by leveraging that approach than you are by trying to you know document a Litany of use cases and then trying to figure out how you can backdoor that process to make it work in servicenow seeing customers do it yeah sometimes they're successful other times they're not but I one thing that is certain is those projects always take longer than when you than when you're coloring within the lines on the coloring book that's true so true awesome all right so you guys ready for a demo um Matt you ready for the demo now sure am wait just one moment here all right so today we're just gonna kind of spend a few minutes taking you through some of the concepts that we were talking about today start by by using those who are unacquainted to the servicenow App Store so you can go you can get to the App Store if you're in your development environment by just going in and uh looking for uh applications uh all available applications under systems and from there you'll see here I've already gone ahead and selected what I'm interested in so I went to the product family governance risk and compliance searched for Content pack and you'll see that we've got GRC starter pack we've got for where did it go already off my dog track uh so we can put in like uh CIS and I can see why is that not all right well let's see I'll just look for all of them but what I can see here is when I come in and look at so first of all you'll see you know number of different applications you don't have to you don't have to use everything all at once um however point being here so here's a cyber security controls accelerator this is another one that you can come out um you'll see I've already got it installed um but these are all just meant to get you started with Authority documentation citation um relationships and basically get you to get templates of all the potential controls that you're going to want to leverage into the future so for our uh for our demo today I'm gonna hop back over and again for those who uh haven't been into service now for a little while uh pleased to show you our workspace views um so what I've got pulled up here is uh our compliance workspace and then I've drilled down into the center for Internet Security controls version 7.1 um again this was I clicked download I came back a day later and I had all of this up for me um which is pretty cool uh but specifically what you can look at here is again for somebody who's not overly familiarized you can provide an overview description what am I looking at here what am I not being compliant with um you know how are things breaking down now this is a demo environment so they're not all cleaned up but what I did want to reference here is underneath this uh controls you've got individual I'm sorry underneath this uh Authority doc you've got individual citations so think of these as just The Logical deconstruction of how something is narratively written in a in a Authority document basically broken down to be written as though it were a control um and what's super interesting what's super neat here is with these 191 citations this also you can drive this so that you're also automatically creating control objectives um which is a nice piece of of automation that that can alleviate some some pain and time but I don't want to get into too much of the solution instead what I'd like to sort of show you is um how you can think about oh sorry my the little Zoom drop down thing is preventing me from seeing my screen that's not online there we go so what I'd rather show you though is is some of this idea of like how once you've put in this idea of the underlying csdm um Services critical business applications and so forth once you've identified and defined that once you've identified and defined what what you want to measure you've now got basically the ability to within servicenow irm either laterally or vertically Traverse each and every relevant area that you're going to want to drive insights from so again we're going to start from this idea we're going to start from the control objective today is this tends to be sort of the the linkage point between my internal policies my external regulations and then what I want to measure them against vis-a-vis you know data centers things like that and what you'll see is you know data recovery capabilities this is this is an important one right uh particularly in the context of remote work right I I I I go out to uh to an industry conference and I lose my laptop and on that laptop with stuff that I really couldn't afford to lose how am I going to recover that data well what's interesting is if we go down and we start to actually look at what is all associated with this record you can see well I know that all of my critical business applications need to have data recovery capabilities right I can't just have my customer facing apps totally totally um go unavailable um but what I can also look at from this view is that again it's going to look exactly like it looks up here but I'm also now able to tie back that not only is this a key thing from from my own internal point of view because these are affecting my critical business apps but this is actually also something that I have a regulatory obligation to abide to uh furthermore and and I'll dive into this from the from the critical business applications and this is where I get into this idea of you can actually Traverse around the the app so if I click in here I can see all right I've got 25 entities associated with this right think of entities as people places and things um that you want to to measure an outcome against so I can see for example I've got things like my payment applications I've got things like uh Inventory management so on and so forth but I can also see that as part of my critical business applications I've got content references meaning I need to abide by CIS I need to abide by the nist cyber security framework but I can also go in here and I can see that and so that's my external environment I can also see in my internal environment that I have an access standard that I need to abide by I've got a remote access standard that I need to abide by and then finally this this all sort of rolls up into this idea of for all of my critical applications what controls do I want to actually apply with them so for today's example we didn't do the full mapping because I didn't we didn't want to overwhelm you but in effect what workflow can help to drive and where you can really start to see a lot of the uh automation value that servicenow irm provides is where you can take these 11 control objectives and the 25 entities that are going to be the most important to your business and you now have a control hierarchy that you can begin to provide attestations to that you can begin to schedule routinized you know testing evidence collection so on and so forth and and this can be and there's a lot of flexibility here right you can do this as a straight permutation so take 25 times 11 and that's your control environment or you can actually get down into more detail and say of these 25 entities I know that say my payment applications need a different subset of controls than say my I don't know critical I.T Services applications right they serve different purposes they need different controls or you can take a look and say these are all critical therefore they all get the same control so that's going to be up to you and and your business and what what your priorities are but really the the thing I want to show here is you know I you once you've defined those elements that we were talking about earlier on in the webinar actually getting those into a usable state in service now it's marginal levels of effort uh this is not uh this is not a a Erp implementation we're talking about this is this is pretty quick to add the value and while it might not make everything perfect from the start it's gonna at least you know the areas that were your pain points and no longer are your pain points you're going to immediately notice those benefits and the things that were pain points and are still pain points you're probably going to feel them that much more and it's going to make a really compelling business case for why you want to continue to expand your use on the platform and in specific specifics irm um because really what I'm showing you here is is a very small portion of really where value can come from this product but it is a piece that to me I see as being very fundamental and once you get it right there's a lot of other things that subsequently you start to make more and more sense and you start to achieve that value in faster and faster fashion awesome um and there's a really uh there's a related question in the in the Q a met um which they're asking do you have an example of a company that has its whole seem to be linked to it org chart linked to its business process linked to business products linked to regulations that are both I.T um and business so I personally have not worked with a customer who has reached that level of maturity um I certainly think you know that is the idealized state right where you have everything sort of as an ecosystem you know you're updating once in the system and you're sort of using it any anywhere and everywhere you can think to to augment value um just the nature of servicenow as a product most of our customers wet their beaks either from an asset management an I.T service management or uh or cmdb perspective and so more often you know I.T risk I.T security and I.T compliance tends to be the leader business tends to be the lagger but that's also changing um and so I think companies are beginning to understand that you know it was the point that that necessitated automation most quickly um it was also you know the parts of organizations that we're we're subject to more you know Outsourcing activities subjected to you know more uh and this is just my opinion but uh more more of sort of like the knowledge drain which then sort of drove the knee to more systematically manage this and I think what you're starting to see is more and more businesses are also rationalizing the portfolio of how they want to work what applications they want to work in and what skill sets are required on the business side and so they're starting to now see that you know as we're making that change we have emerging risk we have new areas that we need to comply with um and that's where I tend to see again like companies start with I.T and then they understand that a lot of I.T problems are just business problems wrapped around an I.T problem and so they realize oh there's a lot that I can also do to to drive this more but to answer the specific question not yet but I think that there are I I certainly know of customers that are doing some really interesting Leading Edge type stuff um and so it's not for a lack of um it's not for a lack of like the software's ability to do it or a customer to achieve it but rather you know mo many of our very Leading Edge customers are looking both at breadth of what they're measuring but they're also looking at like next level Leading Edge um sort of thought leadership type activities and how servicenow can help them adopt that uh as well right right just because folks are trying to do more with less these days right so take advantage of the platform automation Ai and that sort of thing so um some of those are actually going to be featured by blurta in really short segments um monthly throughout the year so that's just something to know um and then the other question is would in your opinion servicenow irm be able to accommodate all those links from the cddb to business regulation foreign documents so we talk about all those linkages um right that big colorful picture does servicenow accommodate all that so the short answer is yes it accommodates it the longer answer is and I'll speak for my own experience um rather than than Towing too hard of a company line here but what I've experienced working with customers is while they can do that usually they don't want it to um just because the map the volume that it tends to create um so the focus tends to be less on can you ingest all of those I.T sources and then relate them back and it tends to be more which of those sources do I want to associate that so that I don't end up with you know tens of thousands of controls but rather you know hundreds of controls but those hundreds of controls are the things that are really the most important and the most impactful mm-hmm awesome yeah so back to the coloring book analogy all the linkages are there in guiding you to color it with your data your regulations your processes um and you can grow with with the platform that's right my daughter has a coloring book and I have a coloring book you can be either awesome all right so I think that's it uh just wanted to start to wrap things up with a couple key takeaways met yeah sir coming all up uh all right so so key takeaways uh I don't want to read off the page uh but I will sort of summarize by saying uh some of the key points that we've talked about throughout so don't let Greg get in the way of good your CMD your cmdb doesn't have to be perfect the most important thing is that the data that you care most about the information objects that you best want to protect that you can rely and trust that data yes I probably agree with that yeah from there focus on those things that are most critical to you if you're an organization that right now you know if if your big focus is Top Line growth try to stand up a compliance program or a risk program that supports Top Line growth if you're working for an organization and it's as much about just keeping the competitors at Bay consider taking an approach that's gonna that's gonna help you achieve that outcome right don't see this as a check the box activity don't see this as just another way to get out of spreadsheet see this as a way to sort of transform the way that you work and to really Drive accountability to the to the right parts of the organization and provide visibility into the key parts of the organization third uh use what's already available in service now um align what's already in service now to our csdm this is going to continue to help you that isn't to say Integrations are a boogeyman Integrations can also be a great way I know we didn't talk about it a lot here but that's another one that once you kind of get your program off the ground you can also start to look at you know where else do I want to be ingesting data and how where do I want to send it within service now um for anybody who's in a security organization out there there's there's certainly a tremendous amount of opportunity here as it relates to vulnerability results you know are you the type of person who's struggling to get through the mountains and mountains and mountains of high severity issues and even understand if they're real or not servicenow can help you with that you know you may not want to start with that as a use case just because again we're sort of of the premise of you know build it on a strong foundation and then scalability comes more naturally but point being here use what's already there but don't be afraid of what else is out there because servicenow is also built to take on that data and to do it in a way that's not going to incur you know tremendous amounts of tech debt and and hamstring you into the future ucsdm uh it's a fair this is a somewhat New Concept uh that servicenow has come out with or a solution that we've wrapped but this has really been at the center and the premise of our Organization for a very long time use the data model to populate the data as it's intended to be used um it can sometimes feel like we're all special snowflakes and in many respects we are all special snowflakes but we have designed this product with the idea in mind that we want to impact value to is is wide a breath of customers as possible we have not designed this to be a bespoke solution with a certain industry or a certain irm vertical in mind we have built this to to suit the needs of of a multitude of organizations so if you feel like csdm doesn't work for you I would encourage you to sort of challenge yourself challenge your management challenge your stakeholders and really ask yourself why your program is is in a place where where you are going to struggle to to take on whatever what are principally like good platform usage habits yep and then lastly use accelerators uh we have things out on the servicenow store um we have we have Partners out in the ecosystem that have some some very interesting uh opportunities that they can provide um but understand that servicenow already has data that's available to you you already have data that's available to You music to jumpstart your program um don't see it as a cheat code just see it as a necessity to keep up with the fast pace that your business is changing at um because frankly if you're gonna try to stand this all up with a blank spreadsheet where you start to key this stuff in it's going to be a tough go yeah so if there's information that you can leverage do it all right um couple questions um oh okay we got two questions in the chat how are Fields positioned in the UI is it top down then left to right or left to right then top down and that's my question yeah so so I'm gonna give you the most service now answer you've ever heard uh it can be either um our platform has a lot of flexibility um and UI is often one of the areas where when we talk about configuration versus customization we tend to try to keep folks into if you're gonna change the way that Fields look on on a farm do it in a way that's not going to impact your future um but out of the box as a standard they tend to read uh top to bottom left to right um but in essence right in reality what you have is on most servicenow forms you're going to have the key content to the form you're going to have any um any linkages out to other places and then you're going to have related lists and related lists are that's the secret sauce yeah you know that that's what enables you right so and that will read left to right um so think of it in that context I think of it more as just whomever you're working with to get your program going just keep in mind that you don't want to make any changes on the form that's going to impact you in the future yeah beyond that you've got a lot of flexibility awesome yes there is a lot of flexibility so there is another question which is what is what a bad jump start look like let's let's save that for office hours um or try to answer that offline because that's actually probably a really good question to start with um so just wanted to wrap things up um we're we do have office hours next Tuesday from 9 to 9 30 um just to follow up this session we can talk live it's not a recorded session so hope to see some of you guys there if you have any questions also Aisha has put in the chat all the links to how to register for our upcoming webinars um we've got some exciting stuff coming up and here are the uh the QR codes so that you guys can go ahead and get registered or take a look at our GRC YouTube playlist um to look at some of the functionality um so and just last words thank you all for joining us today and hope to see you soon in a future event thanks so much Anne Marie and thank you to everybody who uh made the time to come today your uh your time is truly appreciated thank you all and take care thank you
https://www.youtube.com/watch?v=AFzD_YprgeE