logo

NJP

How to: Get Started with Risk

Import · Jan 31, 2023 · video

hello ladies and gentlemen and Welcome to our risk management how to Workshop here on the now platform my name is Spencer Dixon and I will be your Solutions consultant for today going over our integrated risk management solution and more specifically our risk management application so getting started here let's go over a quick agenda for today's presentation now we're going to start with a brief overview of what risk management is next we're going to dive into its features and how risk management really works next we're going to jump into implementation and best practices for that implementation and after that follow up with a live demonstration and lastly go over some supplemental resources to get you guys on your feet and running with our risk management application so starting off here with a brief overview of risk management as a whole so within our now platform in our risk management solution we have a number of applications now today we're going to be focusing specifically on risk however within our solution we do include policy compliance audit vendor risk business continuity and privacy applications now while we are focusing specifically on risk these applications all act and talk to each other on this now platform and so some of the key aspects that we're going to be looking at here in terms of the platform are going to be diving into our dashboard reporting or checking out things like orchestration and automation via our workflows here on the platform moving forward here what exactly is a risk so a risk is going to be a vulnerability that can be exploited by a threat now some classic examples of risks are something like a global pandemic what would happen if a global pandemic hit our organization or things like a software attack or uh loss of availability anything like that those are all examples of classic risks that are threats to organizations now risk management essentially ensures that those risks that could potentially negatively impact your I.T or business services are identified and treated so some key rules that pertain to risk management are going to be our audit committees our I.T steering committees risk officers and pretty much all levels of management what's the risk management application work here on the now platform so we're going to begin by implementing your risk register and loading that into service now so you can do that by either manually creating your own risk register or loading in data that you've previously had through something like an XML file from there we can look at those specific risks and begin assessing them and so in these assessments we can automate them to essentially look at your inherent and residual risk scores and once we get those risk scores we can then use that information to determine how we want to respond to it so out of the box we have four classic risk responses those are going to be acceptance avoidance mitigation and transference of specific risks however we can Implement any sort of response that you may need moving up on the screen here to our mitigating controls so adding in mitigating controls let's say we've already implemented compliance we might have a number of different controls that we can add to help us mitigate particular risks so from there we can look at our control posture and of course monitor those assessments and residual risk scores moving down on the screen here it's important that we continuously monitor our risks and that's where our indicators come into play so our indicators work to actively monitor those specific risks so once they're realized let's say a risk actually comes to fruition we can go ahead and kick off an issue and respond to that as soon as possible via our active monitoring through our indicators lastly reports in dashboards give us the view and information into the entire analytics within our platform in terms of looking at our risk posture across our entire organization moving forward here I'd like to go over our quickly run through our risk architecture here in the governance risk and compliance application so of course looking down here at the bottom left here compliance and policy management are not going to be included in the risk management application however these three all do interact with each other and they interact with each other through these entity types right here so our entity types are going to be how we categorize our risk policies and controls across the now platform so we can connect our different entity types through things like our cmdb or configuration management database so in this way I can have specific risks tied to things like specific assets business applications Business Services Etc now let's say that I want to build my risk framework from scratch we can start out over here in within our risk framework and this framework is going to act as a sort of hierarchy for our specific risks starting with our overall framework we may want to have look at something like operational risks so underneath that I might want to look at particular risk statements right so for example risk of a pandemic what we what we realized uh what we talked about earlier so we can then tie that specific risk or risk statement to different entities so let's say that we're going to have risk statements for or excuse me we're going to have uh that risk of a pandemic that riskayment of a pandemic for each specific office location so our LA office our San Diego office etc etc we can tie those to those different entity types to then categorize those risk statements in this way we can create different risks moving down here with those specific risks I can continuously monitor that status and outcome that risk to see whether or not it has occurred through our indicators so these indicators are going to act as continuously monitoring devices to determine did that risk actually happen has it come to fruition yet and from there let's say that that risk of pandemic was realized it can go ahead and kick off an issue so a quick example of this let's say that you have a risk um that pertains to your website status so you can have an indicator that monitors your specific website status let's say that your website has been down for three hours that indicator can then realize that and fire off an issue and turn that risk from potential into actual create that risk form so you can go about mitigating that next moving down are our response tasks so like I mentioned earlier out of the box we have mitigation acceptance transference and avoidance and based off of whatever response you may choose you can kick off different workflows for example I can have different tasks assigned to different individuals to determine how I want to handle specific risks and that's kind of the framework of our risk management application here within our GRC or integration or irm application now let's go ahead and dive into some of the features within our risk management application so the first thing that we're going to take a look at here is our risk overview dashboard now similar to other dashboards on the now platform our risk overview dashboard is a highly Dynamic and this means that I'm able to kind of dive into any of these sort of analytics as I may choose which we're going to get on to in the demo later on so here I'm able to take a look at my full risk posture as an organization or see all the risks related to organizations and their score up at the top here so here we're also able to tie each of these risks to specific entities so I could see a specific report like this pertaining to a specific office location if I'd like to all I would have to do would be to select that entity and update accordingly moving down to the risk by category here this is going to give us an overview of not only our risks in the entire organizations but also broken down into different departments so I'm able to see our operational risks I.T related risks Legal Financial Etc giving you a lot of visibility into the risk posture of your organization as a whole now this is one of many reports to that come with servicenow and simply by turning on that risk management application plugin now this is going to be a list of those base reports that you get by simply switching on that risk management plug-in things to highlight here are again that risk by entity we have high inherent risk things like moderate residual risks risk heat Maps a lot of reports that you can get by simply turning on that plug-in moving on to our next feature and that's going to be diving into our risk library and register so this risk register is going to be a full list of all of your risks posed to your organization now having a register like this on one platform is great because as you go in and change any aspect of your risk it's going to dynamically update so you get real-time data not only in the list view but also in terms of the reports that we just saw once we go through and click on one of those risks we can manage the full life cycle of that specific risk and this is going to allow us to kick off a number of different workflows pertaining to this risk now what do I mean by that so this means that the life cycle of a risk on the now platform starts when we draft it out we can have specific risk identifications so we can give ability to people throughout the organization to say hey I think I have a new risk on a particular project and create and I risk identification record they can have someone within our own team prove that or you can draft out Risk by having someone in your team create a new risk on the platform and we'll run through that a little later today in our demonstration as we draft data risk we'll then have inherent risk assessments and this is where our workflows start to come into play so when it's time to assess a particular risk we'll automatically send out some sort of email or notification to that risk assessor letting them know hey it's time to fill out this risk assessment and that's kind of the power of the automation Behind These word flows once that risk assessment is complete we'll choose how to respond to it again we have those four classic responses in terms of acceptance mitigation uh transference and avoidance once we have responded the risk will be reviewed then we will be able to monitor it over time now in that monitor phase that's where those indicators are going to be extremely powerful because they're going to see things like when is my risk actually occurred and be able to notify and kick off those issues as needed we can also retire our risks and this is helpful in terms of moving into that audit stage and looking back on the risks that you may have closed previously now let's talk about assessing those risks so risk assessments are going to act to identify and analyze those threat and vulnerabilities that might affect your organization so out of the box our risks assessments are going to ask things like what's the probability of this risk occurring alongside what's the impact that this risk has to our organization now one frequently Asked question that I get a lot is how do I create my own questions to go into this risk assessment and that is where our risk assessment designer comes into play now our designer allows us to add or remove questions as we please and even change the scale of those questions so out of the box what you're seeing here is going to be a scale of one to five ranging from very low to very high however that scale can be changed as needed next moving on to our risk assessment process looking on the left here this is going to provide an optimal strategy when designing these specific risk assessments starting at the top here we're going to start with something holistic like our business service assessment moving down we're going to then identify its supporting IT services from there we're going to Branch down into what quantifies that specific service in terms of this example that's going to be our application and database from there we're going to break it down even further and in terms of application we're looking at things like our servers and data centers and in terms of the database we'll be looking at things like virtual servers physical servers and data centers now that's going to allow us to identify all the components that make up the specific service that you're creating this risk for and really allow for Meaningful risk statements and an optimized strategy to quantify that risk as a whole now risk scoring there's two ways to look at risk scoring here on the not platform and that is in terms of quantitative or qualitative scoring now quantitative scoring is going to be things like looking at your single lost expectancies or your annual rate of occurrence or even things like your inherent average loss expectancy while qualitative data is going to be looking at things on a scale of one to five so in terms of your inherent impact or inherent likelihood it's going to go ahead and take that and scale it from very low to very high again those skills can be modified as needed so providing you a lot of options in terms of creating these assessments now what we see a lot is assessments that use both qualitative and quantitative data that seems to be pretty popular when utilizing these risk assessment design features now when scoring data in a qualitative manner this is going to allow us to create risk criteria and this criteria is going to allow us to assign a some sort of numerical value behind those risk scores so let's say that something with a very low impact and a maximum value here is going to be equatable to around a million dollars or an extreme likelihood is relatable to about a hundred percent here you're able to characterize those scores and modify them to meet your needs in terms of those specific risk assessments now once we have the ability to assess our different risks we might want to create a risk hierarchy so this is where we can utilize our GRC workbench so here we're basically what we're doing is looking at a hierarchy of our different risks here we have our risk framework then we're going to have our particular risk statements and lastly followed by our specific risks down here so here we're also able to link with something like our cmdb so we can look at things like our relationships between our different applications and our Associated risks here we can see our risk management architecture that we addressed a little earlier just a little bit more visual representation so starting out here we have our overall risk framework then we have our risk statements so let's say that uh we're like taking a look at something like an operational risk and that operational risk statement May pertain to the risk of an earthquake so I might have different control objectives from compliance that tie into this particular risk statement maybe that means I want to have certain Disaster Recovery plans in place for my San Francisco office for example we may also want to have specific risk indicator templates that's tied to that specific risk statement as well also underneath this specific risk statement I have that risk so that would be the risk of an earthquake in our San Diego office LA office San Francisco for example uh et cetera Etc then I have those specific indicators looking out for that risk that occurred now let's say that we accept the risk of an earthquake hitting there's nothing we can really do to avoid it we have a risk response tasks and mitigation plans ready with specific controls in place to help remediate that risk as soon as possible so for example we accept the earthquake is going to happen we can at least be ready to clean it up after it occurs and that's where risk response tasks come into play now we can also tie to risk events and these risk events can be any kind of risk that isn't related to it up to you how you want to differentiate these risks and these risk events here on the now platform now when we're talking about those risk statements here's a typical example of something that we see quite frequently so out of the box we have three risk statements in this specific screenshot that's going to be loss of confidentiality down here but we also have loss of integrity and loss of availability now these risk statements can be extremely helpful in linking and automating the creation of risks by tying these specific risk statements to business applications so I can tie these statements to let's say every business application that I have to automatically build out my risk register now next here we're looking at the parts of a risk statement and what's on that form some common things like name framework issue group description however we also have things like different categories alongside inherent and residual sle's and arrows now underneath those risk risk statements lies are specific risks so here we can see a typical risk where we can monitor the entire life cycle of that risk alongside this we can see that we have a loss of confidentiality to risk tied to our specific entity type in this case that's going to be a piece of software here as well as a short description and here we have the different parts of a risk as well notice we also have those common things but some things I'd like to highlight are again that entity type that's going to prove to be pretty powerful in terms of categorizing your specific risks we also have things like our status of the risk that depends on the life cycle alongside our risk scoring now imagining that risk scoring here's what it looks like on a record format so we can see that our inherent score down here is going to be a 4 and that's going to go ahead and affect our calculated ales alongside taking into consideration that calculated score so talking about that qualitative data here and seeing it visually on this form now if I want to track all the details related to my risk status and journey I can do so in this activity Journal down here so this journal is going to allow us to show all the changes that happen on that risk so anything from work notes to version history Etc being pretty powerful in terms of having all of your notes in one central location now let's go ahead and start talking about how we're able to respond to our risks so again on that now platform a risk can be mitigated accepted avoided or transferred and then we can create different workflows based off of those responses so for example let's say a risk is accepted we may need to then create a plan have that plan be approved reviewed etc etc so here we can see exactly what that looks like and how these risks can be determined following a formal risk assessment this is how we're really going to look into that residual risk now in practice what we're going to do is have different actions based off the different risk responses that we choose so here we can see mitigate is going to pertain to deploying those mitigating controls accepting that risk is going to pertain to assigning a business owner and having them understand and sign off on that risk avoiding the risk is going to need the action of rejecting the risk and deploying measures to avoid it lastly transferring that risk is going to essentially transfer the risk to another party or entity so it can be dealt with there now we have a number of different workflows that are kicked off based off which response you choose so here we can see how the following acceptance avoidance mitigation and transfer go ahead and change the state have different approval processes and create different tasks now that we've talked about what a risk is those specific statements Frameworks and the architecture that it all lies upon let's talk about best practice in terms of implementation so we have a number of keys to deployment success first thing that we're going to do is determine our business case so we know what outcomes we're looking for so for example today's outcome could be having that risk register up and running so I can create new risks and risk statements so that I have a hierarchy of risks build built out and ready to go now defining success criteria as well so maybe we're able to assess all our different risks and have that register in place so planning for adoption is something we're going to take into consideration during this stage so before we are fully operational this could be things like changing our branding on your instance or aligning our strategy and culture now moving over on the slide here into the preparation phase this is where we have a lot of training and fundamentals courses already set up for you guys to take so I would highly recommend servicenow and GRC fundamentals training as this provides a pretty thorough understanding of the now platform as well as our GRC solution framework and essentially it provides information on how to successfully manage and deploy those services on customer instances alongside this we want to make sure that we're identifying a product owner to determine who we're giving the admin capability to in this preparation phase moving on to the planning phase here this is where we are going to determine a team that will own and maintain our GRC Solutions so in this particular phase this is where we're taking a look at stakeholders as well and defining a timeline and plan for testing and implementation moving forward into the collaboration phase this is going to be where we're making sure that all of our teams are on the same page so our compliance team our risk our policy management audit Etc these teams are all going to be talking to each other and getting on the same page in terms of our grc's solution lastly going over the Handover phase here this is where we're going to get up and running with that solution and application we're going to have process guides to make sure our users know how to use the GRC product successfully within that now platform now we have a number of different stages of maturity when it comes to implementation starting out in this manual phase our goal is to get people to basic and repeatable as soon as possible so this means that taking into consideration that one particular use case that causes the most headache I.E something like faulty Excel sheets again looking at that one use case implementing and then getting value quickly so then we can start expanding into adding policies to the servicenow adding in compliance requirements maybe we're taking a look at something like socks for example and as we keep building throughout our stages of maturity we're able to gain more functionality like audits becoming easier and realizing that hey I didn't need to email a million people to make sure that my risk assessments are completed this is where we move into that manage and optimize stages now the last thing that we're going to do here before jumping into our lab demonstration is taking a look at our specific risk roles so starting off we have those three categories at the top here our risk admin risk user and risk manager so our admin is going to be able to perform everything that a GRC admin or regular admin would do however strictly scope to this GRC application so here they're able to delete risk Frameworks statements specific risks modify admin properties and modify risk criteria now a risk user is going to be able to perform everything that a typical user can however again just scope to this GRC platform and they will be assigned to specific risks now Risk Managers are going to be able to again perform everything that a manager would do however just scoped to this GRC application here they're able to create risk Frameworks risk statements and create specific risks now here moving forward our risk reader is going to have read at only access to the risk application and modules pertaining to that specific application and they can also be assigned specific risks here now again looking into our risk user this is going to contain the reader and user roles in addition to all the inherent permissions the risk user can view entity types entities risks and Remediation tasks and the risk users can be assigned risks that have read-only access to the policy and compliance management applications as well now our assessment creators are going to be able to do just that they're going to be able to create assessments create updates to those assessments and publish risk assessments they're also going to contain that reader and user role next our risk manager is going to be able to again create risk Frameworks statements and specific risks alongside having those reader user and manager roles scoped in that GRC application lastly diving a little bit deeper into our admin again highlighting the fact that they are able to have the permissions pertaining to deleting risk Frameworks risk statements and risks and be able to modify those admin properties and criterias now with that being said let's go ahead and jump into a lab demonstration where I can show you what we just talked about already now that we've talked about what a risk is statements framework architecture Etc alongside implementation and specific roles pertaining to that risk application let's go ahead and jump into a live demonstration where I can go ahead and show you some of the features that we talked about earlier in the presentation so jumping right on in here first thing I want to show you is how to activate that risk application or risk management plug-in here on the now platform so I just went ahead and logged in as myself and given myself that GRC admin capabilities and what I'm going to do here is filter through up at the top go to the all section simply type in plugins system definition plugins and that's going to take me to this space right here from here I'm going to go ahead and type in GRC risk management and you can see that I already have this plugin installed but this is going to be the application that we've been highlighting today and simply come to this portal install this give your system a little bit of time to get that up and running and then we will be able to jump into our application features from here now that we have the features updated and on our now platform we can filter back to this all section and simply type in Risk and this is going to allow us to see everything pertaining to that specific risk management application so as you notice on the left here everything is alphabetized so if we want to check out something like our risk register we're going to have to scroll all the way down to the bottom so as we can see here these are all of our application features we can see the risk register here our risk assessments grouped assessments alongside some things that we talked about like our risk Library our GRC workbench again all in within the now platform here already taken that information into account seeing all the features that we have here let's go ahead and dive into our risk register and see how we can either import a new risk register or create risks here on the now platform so underneath this risk register category we're going to go ahead and jump into all risks and this is going to take us to again that risk register and the advanced view of all of our risks here on the now platform now if we want to create a new risk we can simply come over to this new button over here click it and just like that we will have our new risk form here up and running some things to highlight again simple stuff like the name description uh alongside something like our category and the entity type over here that we will jump into a little bit later in our demonstration we can also see that the timeline up here highlights all of the different phases so right now it's in the draft phase however if we go ahead and kick it off submit it it's going to go into the assessed phase so on and so forth now what if I want to submit a risk register that I currently already have on something like an Excel file to import a file like that all we have to do is simply come up to this top bin right here right click and right away we're greeted with our import selection here we can either insert new data or update new data it's going to ask if we have if we want to create an Excel template to enter this data and we can also utilize templates that we have already chosen from here we can go ahead and choose our specific file and upload it it is as simple as that already once we get all those risks updated into our register and imported we can go ahead and actually filter through the information that's on this risk register so let's say we want to change what we're able to see here we can simply come to this settings Cog over here in the right top corner and from here we're able to select things that we want to see and maybe take away some of the things we don't so let's say that we want to see the risks that are active or the risks that are or the specific risk class something of that nature let's say we want to put the active status next to our owning group from there we can go ahead and filter those selections and right away we're able to see all the risks that are active here next to that owning group alongside the class that they are in it's pretty simple to filter through the data and see what you want to see when you want to see it so now alongside being able to filter the data that we see on this page we're also able to filter through our risks as well so the bottom here you can see that I have around 12 000 risks it's going to be a little bit tedious scrolling through to try to find something so in order to filter through I can come up here to the filter icon and let's say that today I want to filter by state so I'm going to go ahead and select that state is and I want to check out the ones that are actually in the monitor phase from there I can run this filter and just like that I'm able to filter down to 400 or so out of that 12 000 that again are in that monitor state so pretty simple to filter through all of your risks within your risk register again you are able to see whatever you want to see when you want to see it again it's pretty simple to be able to filter out and see what you want to see in an easy manner now that we have gone through importing our data into our risk register alongside filtering and navigating through this register let's go ahead and check out our risk Frameworks so to do so go back to this all section and we're going to go ahead and type in Risk framework right away it populates underneath our risk Library and from here we're able to see all the Frameworks that are on our current platform so we have everything from corporate risks to departmental again Business Service third party alongside a lot of these specific ones like nist or anything like that so this is going to be where you're able to see the ones that are already on the system alongside the ones that you may populate yourself as well to create a new risk framework all we got to do is come over here to this new tab similar to those risks and let's say that I want to create a risk framework relating to Public Health so let's call this public health risks I'm going to go ahead and save now I do recommend it saving instead of submitting submitting is going to take you back to that risk framework while saving is going to keep you on the page and just like that we are able to see uh what pops up here so we're able to check out our entity types as well as risk statements that we can link this to so in terms of entity types we can create new ones or we can edit pre-existing ones if we go ahead and click edit here it's going to give us a list of those entity types that we already have within that now platform so these are all coming from the cmdb and these are going to populate when you do link that cmdb so let's say that I want to link my public health risks framework to something like our data centers or our company or business applications we can go ahead and filter that over and tie in that entity type to again then categorize our risk framework alongside adding those entity types more importantly we are able to add our risk statements so similarly we're able to create new ones or add pre-existing ones that we may have for the sake of today's demo purpose let's go ahead and create a new risk statement and again this is pertaining to that health risk that we have our overarching health risk so let's call this one risk of a pandemic from here I can also check out and create parent or child risks give it a description categorize it give it an issue group these are going to be our out of the box categories uh in terms of this specific risk we're going to go ahead and say that this is operational and again we're going to save this as opposed to submitting it so we can stay on this form now after saving this we're able to see what populates underneath and that's going to be pertaining to adding different entity types in this section we can even add our different risks here so link the different risks that we may have to this specific statement check out our indicator templates as well as if we want to link this to anything in particular like a website or a specific data center we can do so in these information objects and this is going to tie in directly with our cmdb to help relate certain aspects and applications to the specific risk statement now that we have our specific risk statement in place let's go ahead and add a risk to this risk statement so we can navigate down to this risk category down here filter in select the new Tab and that's going to bring up our risk form here so we can input basic stuff like our name and description and then again more complicated stuff like tying in that entity type or giving it an owning group so for the sake of this demo let's go ahead and name this risk pandemic and tie it to our information technology our it sectors so we want to be able to monitor our information technology in the unlikely event of a pandemic here we're going to tie it to that it group you can also assign owning groups or owners and these owning groups are going to be created by that GRC admin as well so doing so giving it what it needs I will go ahead save it now after saving This Record we are able to move it into the assess phase and in doing so we're able to select an assessor in this case we'll select some random like Andrew Taylor he's on the risk board alongside the amount of days that it has to be done until it's overdue from here we can submit it and just like that our assessment is sent out to the person that needs to assess it alongside giving them the specific timeline in this case it was five days for them to complete that specific assessment now that we went ahead and sent that risk assessment out to who we needed to go to let's go ahead and check out what this risk assessment looks like within the now platform so in order to do so we can go back to this all category and type in assessment types and underneath risk here you can see that I have it favorited by simply selecting the start icon after navigating to this assessment types page we're going to be greeted by a table with all of our risk assessments that we have on the now platform so in this specific instance I have a lot of Assessments that are already loaded in here however this is going to show you the list of all of your assessments that you have currently within your organization now let's say that I wanted to create a new assessment I'm going to go ahead and create one from this new button or we can jump into the assessment designer to take a look under the hood of how we can edit or create new assessments now jumping into this risk assessment designer here is where we can add new questions categories or controls in a drag and drop format so let's say let's go ahead and name our new assessment we'll go ahead and call it pandemic risk assessment and let's say we want to have a question relating to a numerical scale we can go ahead and drag and drop from our controls template over here right into that new category and we can go ahead and name this something like likelihood or something like that from there we can go ahead and add it in add a new numerical scale anything like that so our risk assessment designer is going to be a great template for you to not only edit and configure old or pre-existing risk assessments but alongside create new ones in an easy manner now that we've checked out our risk assessment designer let's go ahead and jump into one of these risk assessments that's out of the box or pre-configured on the platform so we scroll down to our simple risk assessment down here and jump into this record we're able to see name assessment duration the table that it's pertaining to alongside our scale factor and all the details pertaining to the specific risk assessment down here within our related links we're able to see our specific metric categories so in this particular instance it's going to be inherent in residual risk and if we open up one of these risks we're able to see all the questions that are with that are tied to this specific metric now some of these questions are going to be related to things like health and safety financials uh reputation the specific impact the employer and one thing I want to highlight over here is our weights so let's say that we are more focused on the financial impact of our specific inherent risk we can go ahead and weight this specific question higher and that's going to affect our overall risk score for our inherent risk differently so again we're able to assign different weights to kind of categorize and prioritize which questions and which specific areas that we are most interested in when assessing our risks now that I was able to show you a couple of features here on the now platform relating to our risk register and jumping into specific Frameworks diving a little bit deeper into risk statements and specific risks and tying all three of those together and lastly diving through our risk assessment designer and checking out our out-of-the-box risk assessments let's go ahead and jump back into those slides so I can hopefully provide you guys with a little bit more supplemental materials to get you guys up and running now jumping into some of these supplemental resources I went ahead and laid out some resources in regards to gaining process insights differences in terminology understanding post go live support efforts alongside configuration insights now Within These specific categories I would highly recommend that you guys navigate down to these specific links as this is going to be links to supporting documentation and materials on our now docs site so this is going to be a great resource for answering any sort of questions you guys may have post presentation alongside jumping into our community forums those are going to be a great way to answer questions as well and on top of those resources if you guys do have any specific questions that you can't answer via this presentation or the documents provided do not hesitate to reach out to your account teams they're going to be great in being able to answer any sort of questions or provide any sort of material that you guys may need with that being said I want to thank you guys for tuning in to today's presentation and on going over our GRC risk management implementation and solution hopefully you guys are going to able to gain a little bit of insight into the implementation and some of the features within our risk management application with that being said Thank you guys once again and have a great rest of your day

View original source

https://www.youtube.com/watch?v=msGPPE0aUg0