logo

NJP

What’s new in Operational Resilience Management

Import · Feb 10, 2023 · video

fantastic so um welcome everybody um we are going to start in just a minute we're going to be doing a live on servicenow our community webinar on what's new in operational resilience management um and I am going to start out by redoing some slides and giving you an overview um a few housekeeping issues up front and I'll introduce you to aswin shortly so just as a formality we do have the Safe Harbor notice if there's any forward-looking statements in this presentation I don't think there are because what we're talking about today is being released in the store but if there are any um we can't guarantee any achievement of those plans and you can read this for legal legalese as as you need to but as for housekeeping um you're going to automatically be placed on mute and we ask that you use the Q a feature to ask questions throughout the session if you need to chat with us we're happy to use the chat feature as well but all questions if you could put them in the Q a that would be great our session is going to be recorded and we'll share it in the community right after uh this has ended and after the session ends you will be directly prompted to a short survey if you don't mind uh just filling that out just take a couple minutes we really use that feedback to improve our presentations to you and provide you on topics that are of Interest so thank you very much um as I said here on a live on service now um we have a lot of future webinars and meetups and upgrade conversations um across all of our product line at servicenow specifically today we're going to be talking about risk but if you're interested in our other sessions that we have there's a chat that link that just got dropped in so please feel free to sign up for any other events moving forward and as I said we're talking about the new IRL applications and updates that are now in the servicenow store we're going to be talking specifically about operational resilience but we do have two upcoming risk webinars that we wanted you to be aware of the first is about risk management on February 9th and that's going to be talking about some of the AI assisted risk management enhancements that are enabling common controls inherents and issues tagged to multiple sources of failure so that's a really interesting one for anyone who's interested in Risk Management proper and then policy and compliance management we're also working on on enhancements there and we're going to go over those and show you what's available in this release in the store that's available now so again common control testing results can be related to inherent controls as can issues so definitely check that out if that's something that's of interest to you so as I said I was going to introduce Osman and I will also introduce myself so Aspen is a principal product manager here at servicenow for both the BCM and the operation resilience products he is the owner of those products so any enhancements features it's his team that brings those forward to you so you have him to thank for all the things we're going to be going over today and definitely ask any questions that you meet because he's a wealth of knowledge and I think you'll get some really good insights if you ask questions here I am the product marketing manager and I also cover BCM and operational resilience as long as our vendor risk management soon to be tprm product and as I said what we're talking about today is operational resilience first I'll go over the first major feature enhancement which is around our operational resilience workspace and what we're bringing to you in this version of the product we're bringing a new modern UI we're bringing the next experience as we call it at servicenow there's a lot of configurability uh Persona based workspaces we're bringing forward the managing Business Services the impact and in sorry the importance and impact tolerance assessments there's scenario analysis and self-assessment tailored for all these will be shown in the workspace the and with the next experience we always also bring you the 360 degree view so the main thing we're focusing on with this workspace is improving visibility driving efficiency and simplifying the navigation for you so this is what the workspace is going to look like but Austin will show you in more detail when we get into the demo again visually visualizing 360 degree relationships between your dependencies applying context to your data and looking at an opera organizational wide view of your operational resilience program we believe this leads to again increased productivity and the simplified navigation will help you move throughout the product more swiftly the minor features that I did mention were all the things that are we would call them minor but I would say that all of these are key contributors to the workspace that we're going to show you the 360 degree view super enhancement it shows you a really great visual for understanding your in interdependencies manage Business Services was a huge uplift for us for allowing you to Define service dependencies and collect some of those resilience metrics we enable you to have a holistic view of operational resilience whether you're looking at things that are coming over from the cmdb um from up from your business continuity your bias your business impact analysis or if you're using information from our GRC applications or whatever it workflows you want to incorporate into this operation it's a huge huge product we call it minor but I don't think the team would would tell you that it was minor because it's really going to bring you some impact speaking of impact we also are doing survey-based assessments for these business services we have uh got this scenario analysis which allows you to simulate events in your operational residence program the Southwest a test station enhancement is allowing you to print or develop PDF reports of your resilience reporting and it facilitates the ability to meet regulatory or audit requirements and finally my tasks is an area a dashboard for tracking and actioning all of your operational resilience tasks whether they're individual tasks or team tasks and again this plot provides some great visibility into things that you might need to do an action in the product so enough for me I will pass this over to us one who's gonna go and demo and detail all these features for you um again put questions in the Q a and we will start to uh answer those as they come in so thank you very much Aspen please take it away sure thank you thanks everyone for joining today's session uh like Ross was mentioning earlier uh we are going to look at operational resilience demo today right I'm not going to use any PowerPoint we will look at the application and if you have any questions please feel free to type them in the Q a and we can take them up and move ahead right let me share my screen uh I already see there is a question from shut up we will take that up uh as and when we proceed with the devotional please have a patience of one or two minutes we will get there and with that I am going to share my screen let me know if you guys can see my screen and uh if I'm audible if it's okay that's great we got it all right um so the very first thing earlier uh the operational resilience version of the product was released in our uh previous uh user experience this release we are releasing it as an uib workspace that is the user interface Builder workspace this is the next experience like Ross was mentioning so as soon as you log into the system based on the user's role uh we have introduced three roles by default but you guys can configure additional ones as well right by default there is an operational resilience user there is an operational resilience manager and then an operational resilience administrator so these are the three rules that the product ships with when you turn it on on day one these are the three rules that will be available you can assign it to different people based on the roles that are assigned to them they will be able to perform certain tasks in the application we will go over what that is and I'll also when we are looking at this UI and different functionality we will explain what these different roles can perform and what they cannot right so it becomes clear for you so as soon as you log in you will be able to go to this particular workspaces here and you would be able to see there's a new workspace that's got released that's called operational resilience workspace so you click on that this is the home page that loads you'd be able to see what are the services that you and your team are delivering today these are the business services which is in an active State that's how we have filtered this if you have this data already in your cmdb it just gets pulled in right if you do not have it for example that was the question that we were trying to address on the chat right shut up was asking what maturity level should the cmdb be in in order for you to start implementing operational rescience you could have a very matured cmdb or it could be the first application that you are implementing in servicenows platform right either of this case two extremes you will still be able to implement this I'll explain you how that can be done as soon when we start looking at how the data getting captured right so if this uh if this data is already available then that gets pulled in here similarly apart from the services what we also do is identify the dependencies basically these are all your different pillars uh this would be your technology dependency facilities people data suppliers right by default this is what the product ships with but you would be able to add more categories to this right you can add additional pillars or categories that needs to be tracked we will see where that gets added as well once we have the dependencies identified the application puts in information from different other sources of information so what I mean by that is these are the Red Flags around your services right the red flags are further broken down into issues that are getting tracked as Priority One issues in the issue management system there are certain controls that have been tested recently and then the result has come out as failure right so either they have not been designed correctly or they are not operating correctly so this comes from policy and compliance application the risk assessments that have resulted in a high residual risk right from our Advanced risk assessment this gets pulled in these are the outages that are getting tracked for one or multiple technology items or a facility for that matter same way there are some major incidents that are open now some change requests vulnerabilities that are getting identified for your critical applications are ID infrastructure right so this comes from a vulnerability response management system so these are all the different uh red flags that we are calling it as these are nothing but the hot spots the areas where there could be an issue that can you know disrupt the delivery of your business services so these are the Red Flags so there is uh data visualizations here where we uh you know categorize the services based on the number of red flags that are impacting them so anywhere between 0 and 10 and then 1 to 30 and then 30 to 60 risks issues control failures all of this put together so there are certain Services under that category as well there are two of them to be exact you can click on any of this piece of the pie and then you can look at what those services are at any point in time right so there are drill down reports as well same way the services are also classified by the importance of the service so this is in line with the importance assessment that needs to be done you first document all the business services in the system and then you can using a survey methodology that's a predefined template that the product ships with but you can tweak the questions as well once you have tweaked the questions you can send it to the service owners based on their answers the services are classified as whether they are critical less critical and so on so you can also come up with your own tiering like tier one service tr2 service tier 3 service Etc so this is only an indication on how you can classify the services in the system same way there's also a survey based questionnaire that can be sent out in order to identify the impact tolerance of the service right so this is the impact tolerance that you need to identify which will be used in your scenario analysis as well right so this is different from business impact analysis in the vcm application that is primarily done on business processes right the business processes support your business services here this is a separate questionnaire we will look at that functionality as well uh so these are the pillars that I was explaining you earlier so technology related dependencies supplier related dependencies facilities people data and so on right so um there are certain risks and issues that are identified that are impacting technology dependencies or the assets similarly there are some that are identified that are impacting suppliers of the vendors same way facilities and so on so this is a classification of the red flags or the hot spots that are identified from various different applications that are directly or indirectly impacting one or multiple of your business services and the delivery of that Services that's what this dashboard shows this is for the service owner or the business owner you'll be able to see these also you would be able to see what are the different activities that are getting carried out in the system today so these are the importance and impact assessments this is kind of providing you a program overview if you were to run operational resilience as a program there are assessments being carried out by different people from different functions uh you'd be able to get a sense of how many of them are in progress how many of them are completed uh you'd be able to see how many scenario analysis is underway how many of them have got completed again you can at any point in time click on the full list to get the entire list view of all of this put together same way there are self attestations also which can be used for downloading and PDF report for Audits and reference purposes we look at the details of all of these forms and the last part of the dashboard that is the suggestions section right so if you see here uh these are the controls that are failing or not performing 100 which the system says it's a good point to start off with by fixing them or strengthening them right in this case for example there is a policy document that is not updated so because this policy document is not getting updated it is linked to let's say two facilities right people are not able to get back to those two facilities for carrying out their tasks let's say and then that in turn is impacting five business services so the controls that are failing are listed down by the number of services that they are impacting directly or indirectly they are tagged to that service so this provides an idea of which are the controls that you might want to start looking at same way these are the risks the high residual risk areas it could be from a facility related risk it could be from data related risk it could be from an infrastructure related risk as well so this combines and the information from these different um functions or teams and then it just relates it to the business services that they are directly impacting and this provides you an idea of these are the risks that you might want to probably start fixing right this is an overall uh overview home page for all business services put together all the operational residence metrics so if you think about these things these are all different metrics being collected by different team members and different programs that are running on servicenows platform it could also be coming from external or Legacy systems where we can pull the information in and it can be used in the same dashboard as well so this is the overall home page let me see if there are any questions and then we can move into the uh the next section of the demo there are a couple of questions that came over in chat as well as the Q a okay uh let me see if I can get the I can do that if you'd like uh yeah no problem for us I can I can do that no no yes so the first question is from Mike he's asking are these pillars configured uh yeah these are um configurable pillars in the system I'll show you how that is done right just a second I don't know so this is an administrative task where the user or the administrator can go in and configure these pillars like I said the product when you install and turn it on it already ships with some of these predefined uh configurations but you can go ahead and then change it as well so let me just go into this form and you should be able to see operational resilience as a menu and under that menu you would be able to see these are all of your pillars and entity types so this is where the guis graphical user interface for the users to go ahead and change this for example I've created in my instance Services processes suppliers technology facilities and people so you for example can go ahead and add one more let's say that is called data and point it to a particular table that will start working as soon as you do that right and then that will start coming up in your dashboard here as one mode bar so that level of configuration has been taken care uh let me see if there's other questions so um the the servicenote product today so this is a question from Paul do we predict the service prioritization or important business services uh or that needs to be entered manually currently uh the importance of the business services is identified by a survey that goes out and it has to be entered manually but if you want this to be automated right based on number of customers number of other data metrics around the service we can look at doing that but currently it is a survey driven identification of the importance and impact orders both those values we will look at that in detail uh so the next question is in reference to issues are there are these tied with SN uh to technology major incidents yeah so these are two different metrics right so uh what you're seeing here is coming from GRC issues right so this one is from the GRC issues this is from the incidence this is from outages right so this is an example of metrics that can be collected from across the servicenows platform and different applications this can be enhanced as well you can add more metrics to this as from when you start implementing those products and then that data starts getting collected right we can pull that in as well I'll show you how this is getting uh pulled in let's look at that in a minute let me see if there are other questions anytime number is shown in the graph or report is applicable yes uh that is what I was trying to tell you guys so at any point in time you can click on any of this so either the piece of that pie chart or you can go into these numbers so that will take you to the next level of detailing and you would be able to drill deeper from there right uh I think [Music] okay I think those are the questions on the chat uh there are some on the Q a uh yeah so there is an overlap with BCM I'll explain how that works together Mike that was one of the questions on the chat uh so uh the risks the next question is from uh Dimitri so it is on are the risks and controls uh they are linked with entity of Business Service class or business process or down Downstream to the underlying business service we will answer both these questions let me quickly move into a service view where I would be able to answer both of those questions here yeah so what you're looking at is the business services what we have done here is essentially we have created a view for operational resilience so this is nothing but the services record in the cmdb if you already have it this will get populated this list that you just saw uh otherwise we will be able to create it from here as well so you click on new that will start a new record you can start creating by uh by keying in the information about your business service as well so this view is configured for the operational resilience user right so if I go into the services here I'm sorry let me see if I can so these are the services right uh So based on the concept of views that can be created for the records so what we have done is we have created one View for the service here so if you can see here there's a view that is specifically created for operational resilience users that is what you're seeing when you're looking at the latest interface this is the next experience right so as soon as I log in and then choose my business service I would be able to see what is the latest importance assessment what was the output of that what is the impact tolerance assessment that was done as well and when was it updated right it got approved reviewed approved and published that's why this is getting added here at any point in time I can go to the assessment that led to this output as well from here right in this dashboard and for my service called faster retail payments uh these are the Red Flags basically these are the metrics that are getting collected from across different applications and different functions this is the same thing that we saw for all services put together that was the home page or the dashboard this is for one particular service right I am the owner for this service let's say I'm responsible for the delivery of the service I log in I will be able to see these are the hot spots or these are the areas that you need to be aware of and these issues and controls are not directly linked to the service itself but then to the underlying dependencies let's look at what that is so you would be able to see the dependencies and the hierarchy of the service as well as the red flags in a visualization called the 360 degree visualization this is something new that we have released now in this release let me quickly launch that we will look at that and then look at the underlying data as well that fuels this visualization right so what I have done here is I've picked up one service that is the middle of this right so that is the primary item I want to focus on and I'm trying to get a sense of everything that is impacting the service as well as the context in which the business services in my organization right so if I look at this one the top level is the service hierarchy right so what I'm doing here is I clicked on the parent so I'll be able to see that my service faster retail payments rolls up to a group service or a level one service called payments there's payments under payments there is faster retail payments I am responsible for this service here same way I can also look at if there are sub Services Under this one right so there's a three level hierarchy I have picked up for this example you don't have to stop with three levels it can be n but for this example here and this demo I've picked up a three level hierarchy right so under faster retail payments there is retail adding points retail client lookup and so and so forth so these are the sub services that are rolling up to this one and this rolls up to payments as one of the services so that data is available in one visualization that is this section of the 360 degree view right the rest of the dependencies so for example it could be processes that you're dependent on faster retail payments needs or is dependent on these different activities and processes right these are nothing but the business processes you'd be able to see what those business processes are that are dependent that you are dependent on similarly you can also see it doesn't stop with the processes it goes One More Level deeper this could be your uh you know these are the different assets for example there is a facility uh in San Francisco there is a facility in India that you're dependent on there could be companies or vendors there could be business units uh and then there could be applications these are the critical software applications or Enterprise applications these are nothing but the the assets that are getting classified based on the pillars that you created earlier right we saw that earlier where the admin can create these pillars so these are facility related dependencies supplier related dependencies people technology and so on based on the classification or the categories that you want to create as pillars the dependencies are categorized as the one of them and then that will be called out in this as dependencies now the failed controls or high risks are actually related to these dependencies and processes these essentially don't have to be directly linked to the service they are around these dependencies and processes and they are rolling up or they are supporting your business service that's how this data model is done so you would be able to see here for example these are all the failed controls right so these are the controls these are the control objectives and you'll be able to see this is non-compliant it is impacting A supplier called IBM hypothetically here this is the supplier that it is impacting and the reason that this control is getting flagged on my dashboard is this particular control is non-compliant related to a supplier and that supplier is supporting a process called outbound payment validation and that process rolls up to my service so this is two or three levels of um the dependency that we have pulled in together we will see what these are in detail right uh these are the different metrics or red flags that we have defined by default you can very well change this name to something else if you are looking at UK regulation typically this is called the vulnerabilities right but because we have service now and vulnerabilities has a specific meaning in service now we are not using that terminology here but it is configurable you guys will be able to change that pretty easily so this pulls in information from ongoing change requests failed controls high risks incidents outages uh issues right all of these different various parameters these are the open audit tasks someone is not completing for example so you'll be able to see all of these you will also be able to see the assessments done on this particular Business Service these are the importance assessments and these are the scenario analysis which we will be looking into in detail next so this is a 360 degree view of a particular business service if I were to lay down in a very flat structure all of this data right what you're seeing here is a new visualization component we released but the data that fuels this is nothing but here right so if you see here this is the parent service that is the payments part that we saw earlier these are the child services this is the next level of dependency and then the next level is the processes that come together to support my service business Service delivery and the processes are again supported by various different elements here so if you see here these are all the facilities suppliers people uh all of these technology elements all of these coming together that can support the particular Business Service as and when we pull this in we also look at the RTO assessments or RPO assessments done on these ones from the business impact analysis in BCM also if they have been put through an itdr exercise right what was the last event date what was the status and what was the actual time taken to recover them so these are all contextual information we'll be pulling in for all the dependencies that you are needing for your business service from BCM application as well as if you see the issues here uh this is one of the metrics right so if you see here uh currently we are pulling in only the open issues and the ones that are gone beyond the due date right so this is a technology related issue that is uh tagged to one particular uh it infrastructure right and it is rolling up to one process and that process is rolling up to my business service that's why this issue is getting highlighted here these are the GRC issues right uh same way there could be a risk assessment team this could be the operational risk assessment team who's doing your risk assessments so we just pull in that information from the risk assessments here so you don't have to go and do the risk assessments again right so this just pulls in the information so it could be also split within the operational risk team as uh you know our I.T risk assessment or process related risk assessment or facility related risk assessment or site risk assessment right so all of this are getting pulled in and we will map it to the asset that is getting impacted because of the risk and the pillar that the asset belongs to as well as how this rolls up into the service so this is your process if there was a child service in between in this link it will identify that also and then it will give you the entire link from how this risk is related to your business service right so we build the entire tree hierarchy we're using this data data model that pulls in all of this information automatically for you you don't have to add it manually here so um it's the same way if you see here there's no manual addition of risks or controls right as and when these are getting done in those particular functions automatically the data gets pulled in here uh one more thing before we move out of here there was a question on uh the maturity of the cmdb again right so in the cmdb if you don't have this data and the data is not mapped using service mapping or the cmdb relationships or if you have done bias uh in business continuity management the dependencies will get pulled in from there in either of these three sources automatically it will get pulled in and the related metrics will get start getting collected for those assets that are here right that's how this data is getting pulled in now if you don't have a good cmdb data what you will essentially start doing is you will start mapping these dependencies manually with an operational resilience so I'll create much service let's say this is going to be zero right I'll go here I'll just simply click on ADD I can filter through based on whether it is a supplier or technology or facility right I'll identify the item that I want to tag as a dependent dependency I can select that and I can select add so that will add the dependency here it will not just stop there it will also start pulling in the relevant metric for the facility for example that I just added right so this is how you would be able to build this data within operational resilience management application if you don't have a good cmdb source or make sure cmdb right so this will be available here and this also has all those visualizations that we already had in the cmdb also so this is one of them the infrastructure relationship and then you can also see the uh the node map right so that is nothing but your dependency view this is something in addition to that dependency view that we have created for this release um this was the services part uh let me go into the importance assessment and before that if there are any questions we can take a look at that just give me a second um so I think we answered the risk and controls and how they are tagged to the entities uh so Paul has and comment on the either impact tolerances has been agreed in UK as severe but possible scenarios uh impact tolerance to BCM Dr rtos I will show you that Paul we are going to look at that now in detail yeah and uh there is one at the end if it performs separate assessments okay so there is one question there on uh there that is also on the impact tolerance and importance assessment let me walk you by what we have released and how it can be configured for additional use cases right that should probably give you the answers there uh just a second um so let me start off a new importance and impact tolerance assessment right so as soon as the user logs in we can see there is an hand holding for the user provided help texting each in every step during this assessment or scenario analysis in any of those things for that matter we will see that um I'll just provided a name and I can add a description to that assessment I can also pick up a template right so basically it looks like someone was testing this instance sorry about that but then you would be able to create and park these questionnaires or templates as an administrator and the business users would be able to pick up those templates that are relevant and they would be able to start filling it up right so I can provide an owner who needs to complete this assessment uh I mean an assessor and then an approver also right so this is optional so I can ask that user to approve this once the assessment is completed I can also provide an assessment due date by when the assessment has to be completed right once this is done the user simply saves this details that you have created and then the next step is to select the services that you want to assess so you can uh the way that we have built it now is we have made sure that the assessment that you are doing can apply to one service at a time or multiple it's purely upon your business requirement so you can choose either one or multiple services at the same time at one go right if you select multiple business services at one go what it would really mean is the same answers will apply for let's say the two services that you're selecting it'll apply for both in this case I am selecting one and let's say assess so this would create the assessment that needs to be completed by the assessor so that would be embedded within here so the user doesn't have to move into multiple places to get access to this right give it a second looks like it's taking time uh more than okay it will loaded uh all right so what we have done by default is shown and um example right when you turn on the application you will get this loaded predefined questionnaire but you can go ahead and change this right so there are three categories of questions that you will start seeing uh very much in line with the UK regulatory document right impact on the customers what is the impact on the firm what is impact on the market like I said this have to be these have to be answered manually today so you would be able to provide answers to these questions and then there can be weird uh rational for the answer right so for every question that you create in the template there will be an option for you to mention what kind of answers what are the options for the end user as well as the comments will get captured automatically right so you would be able to create your own questions that is there's no capsize on the categories and under each category you can have multiple questions right you can say whether it's a drop down a radio button or yes or no question all of these things right so this is pretty much configurable when it comes to that that so here there is a low medium high and so on so what is happening behind the scene is each answer that is being provided by the user here actually gets mapped to a score so that is where uh the mapping table is we will see that in a minute so once I have provided all the answers the user can submit this answers uh and then it loads in a read-only view once it is submitted there's no going back that is one of the checks that we have added in this release we'll be able to open it up in case that needs to be edited maybe in the future right um and then you would be able to see the importance and impact tolerance being calculated for your service based on the answers that you provided so it is driven by one single assessment today but we can split it into two as well I'll show you how that can be done um this is the system calculated value right but the user can choose to override the system calculated value in which case the user is asked to provide an rational for why they are choosing to override the system calculated value so the user can click on that and the user would be able to see the system calculated value here in case I want to change this I can go ahead and change it and then there is a command field that pops up as a mandatory feature or a field that the user has to provide same way here also so let's say I want to reduce it to four hours right so the user is asked to put this in this is going to come in handy when you're trying to send this assessment for uh review and approval right so in the initial stage we said there is an optional approval that is uh in place right so if you see here in case you want to send it through an approver this person would get that they'd be able to see what is the system suggested value what is the user changed into they can look at the the reason for that and then they can say approved so this person once they are done with all of this uh override and providing the answers you can simply say a request for approval this will actually Kickstart our workflow uh this would have gone to the next person in line right so that is how the importance assessment is done uh just a second let me also show you the uh one second so what we have done today is these are the assessment templates you can create your own assessment templates here right there's a graphical user interface for that you would be able to go ahead and do a mapping for your impact tolerance right so while you're mentioning whether it is CBR or possible scenarios right so basically you'd be able to get that done and then you can say what is the importance so in this case I have chosen a fourth scale one two three four right and and then most critical all the way to not critical so you can change this part and you can call it tr1 tier two or CBR whatever that is right you can come up with your own terminology as well as the impact tolerance I've chosen it as one day two day three day four day so keeping it very simple right so you can choose it to 15 minutes to four hours to eight hours 12 hours whatever that is um similarly in the reports and um in the uh in the visualizations right so there is an icon that will be used if it falls under this one what will be the color that needs to be used for that and this is the score basically So based on the survey that you take uh there's a score that is calculated and based on where that score is these two will be populated as by default or a system calculator value which the user can override so that's what happened here right so the overrated importance or impact tolerance can be done by the user but these two will be calculated based on the answers provided for all these questions that we just saw earlier and the same thing is used in this particular view this is where you will see that the icon and then the color for certain things are picked up from all of that is configurable as well we have made it pretty easy for you to go ahead and change that according to the classifications you need and make sense for you guys um that was importance and impact tolerance assessment we are doing it today only based on date time right so the import the impact tolerance is based on number of days and hours and time uh but we can expand it to other parameters in case you want to track impact tolerance in terms of uh the percentage of transactions getting completed uh number of customers getting served or it could be data right uh compromise and things like that so that can be added as well what I showed you was the placeholder for the date time how it is done today you would be able to add additional parameters to that as well so that brings us to scenario analysis in scenario analysis let me start an analysis new now there are a bunch of features that we have added here also so I'll just take the same example uh uh as a name so I can provide a description a goal for the next participants who are going to be tagged in this analysis part I can provide when the analysis should start for the Simplicity I'm selecting the same day as the start date and you can also say who's the owner right so we can pick up one of the owners here uh and plan approver is the person who will be approving the analysis before uh the participants are notified right so that can be one level of check and then once the analysis is complete the results can be reviewed and approved by the same person or a different person so this is another level of approval that can be uh optional uh purely optional that you can select based on your business requirements again right once I have done that I can save this and that's when the user would be taken to the screen where you can select the scenarios that you want to consider so there is a central library of scenarios that is created and maintained the business users would be able to go into this analysis form when you're doing the scoping for the analysis you can go ahead and select in this case I'm going to pick up some infrastructure related outages right so let's say facility out page and power outage so these are two things they are related to a flooding situation into some of our critical facilities so this is what we want to assess today right once I have added the scenarios to be considered the next one is who are the different people from different functions that I want to invite for this analysis right so I'll be able to select those users from let's say HR technology Etc so you can pick up those users these are the participants so the participants that load here for selection are the operational resilience users right the people who are creating and maintaining the scenario analysis or completing the impact tolerance or the operational resilience managers so these people can be from different functions for example HR or from technology or Finance Etc you can provide an instruction for that person when they receive an email for nominating getting nominated for participating in this particular analysis they will be getting this instruction sent to them as well right uh um I'm just creating this now right I can add any attachment that needs to be sent to this person as well so I'll be able to add multiple different participants from different teams who will be part of this particular analysis here so they will get notified when the start date actually arrives right so that's what you're seeing here as and help text here you'll be able to add multiple participants and then we can say what are the dependencies that we want to consider for our assessment so let's say we are looking at a particular building let's say the Texas one right so this is the facility that we want to consider so once you have identified that what is the asset that you want to put through or you want to consider for the analysis the next one is the services the system automatically tells you what are the services that will uh you know experience a downtime because this facility is going to be hit right so I can go to the services here I can click on ADD dependent services uh I will see that these are the four or five services in this case four four services that is going to have an impact because the facility in Texas is going to be flooded now this relationship comes from the same data that you guys were seeing earlier so the service has been mapped to a particular business process and the business process was tagged to this particular facility so when you're doing a scenario analysis the same data is referenced and the system suggests this is the scenario that you want to consider right there was a facility outside scenario uh and that's the flooding situation right and you're saying that this is going to happen in this particular facility the system automatically tells you these are the services that will be impacted because of the downtime of that particular facility so you can choose all of them or one of them based on who's doing the analysis and what you're responsible for you'll be able to add all of these here and then you can send it for a plan approval once approved the individual participants will get a task assigned to them they will be able to provide their uh you know analysis here and finally the uh the operational resilience manager would be able to collect all of those analysis and see which services are going to be breaching the import impact tolerance basically eight hours is what we created recently right uh if there are multiple scenarios that come together and it is going to be having an impact of let's say 12 hours that means the impact tolerance of this particular service will be breached uh this will turn into a breach status and by what percentage it got preached that is how the analysis will be completed you can track all your action items and findings as issues so you'll be able to send that to uh the issue management system this is the GRC issues you'll be able to track all the action plans uh everything as issues here uh so let me try to quickly log in or log out and then get this approved uh just give me a second so we can complete this analysis piece right now but while that happens if there's any other questions we can pick that up yeah one of the questions came in again it's um when does customization of templates field structure become a problem for future servicenow releases uh customization so if you are looking at adding or changing the layouts of the UI adding new Fields Etc all it is not a customization it is an um it is a configuration basically you can just add the new fields and that would be that would be treated as a configuration so your future upgrades of service now doesn't have any issue right it will be seamless so that is how we treat that but if you have any specific questions on that I'm happy to take that up uh you know after this this meeting uh I can explain you how that works uh the implementation at service now how it will impact your instance and future upgrades um uh really it is like uh if you look at the forms the workspaces um all of these are pretty much configurable so for example this home page you'll be able to drag drop you will be able to create new charts uh any of that stuff right that's all configuration it's not going to you know impact your future upgrades same way in the forms that you look at uh any of this form right if you want to add a new section add a new field add some validation make something mandatory all of those are configurations as well so there are certain things that fall under customization category I can explain that to you probably you know after this we might not have time for going over everything there okay I did the approval let me see if uh I can go back to the user that we started with uh we can look at how that comes up and how we can start that stuff so this is the scenario analysis piece [Music] okay this is the this is under the analyze state right that means it's moved under the analysis State the individual users would have gotten their request for response so when it moves into an analyzed State that's when you start seeing this responses tab so the individual users that we tagged as participants currently in this version of the release they will be able to provide their input but then we have locked it down that is John Doe in this case will not be able to see let's say ashwin's responses right and Ashwin will not be able to see John's responses but then the manager who is connecting this entire exercise would have access to everybody's responses individually and they can go ahead and they can complete this as well so let me look at the scenarios that we have let me pick up one of them to quickly show you how this can impact the output right uh let us say just to get some data going I selected some 21 days all right uh so once that dependency or that particular data entries being made for every single dependency every single events by the participants and by the user who is providing that details here where we have to tag that particular service to the event and and the dependency as well just a second let me see if I can tag that from here quickly uh this is the one right so what we have done here is we have created it like a slush bucket basically uh you can tag an event to a service or a service to an event similarly the um the assets also right so it's a end-to-end mapping you can pick up an event from here or you can pick up a scenario for service from here same way the dependencies and participants also you can add it at any point in time and this is a combination of the event uh impacting a particular dependency which is in turn having an impact on the business service so this is how it will start looking up so this impact tolerance comes from your assessment that we did earlier using a survey and this is coming up from the impact impacted asset right we are saying it will be down for 21 days for this example so it just does a comparison and then says what is the deviation what is the percentage breached whether it is breached or not the impact impact tolerance right so this is the analysis piece once this is done you will be able to go ahead and add an existing issue or identify an existing issue or you can go ahead and then report a new one all together so this will be tagged with this particular scenario analysis and the name and date so you can have a backtracking at any point in time you can go into the issue management system and then see what is the status of this if you are looking at it from this also you will get a recent state of that issue and who's working on it what is the uh you know progress made on that from within here uh this is the scenario analysis piece where you would be able to tag it to a scenario from a central library then the dependencies and then the services and also how you can track your issues and findings um and then we also introduced what we are calling as the my tasks this is one of the newer features as well uh instead of going into multiple different areas to accessing your tasks right all of these items that are assigned to a particular user have logged in as one of the users here everything that is assigned to this particular user will be parked under my tasks everything that the person has to complete will be under my pending tasks if there's something that the person has to review and approve they will be under uh my items and if I have created something in the past right I started an issue or I reported an incident or I have created a business service I updated an assessment all of those things that I've worked in the past will be in under the watch list so everything that the user needs access to can be provided from here the user just has to log in and then go to the tasks they will be able to get access to everything that they're supposed to work on and complete uh this is also something new that we released there is also one more dashboard uh I thought I'll catch up on it at the end if we have time looks like we can go over this so this particular dashboard called pillars right so there's a filter at the top it can be filtered based on facilities people processes technology Etc right so I can go with technology for now uh let's say if this is someone who's logging in from the technology team or the IT team they'll be able to see there are 33 critical applications me and my team are supporting today by making sure these services are up and running we are supporting six different business services so what we have tried here is to provide a business context through the different pillar owners right currently they don't know what is the business service we are depending we are supporting uh if my critical application for example goes down what are the services that may see an impact right so we have tried to bridge that view as well so if you think about it's the same data model right the service is dependent to Services dependent on processes processes depending on let's say technology assets so we just draw back and then pull that information in same way uh the I.T risk assessments can be seen here these are all the Cyber risk assessments done in the risk application these are all the it controls right how many of them are compliant how many of them are non-compliant some of them are not even be tested these are all the issues related to it uh major incidents and then this comes from continuity plans business continuity plans right this information gets pulled in from there the latest Dr exercise so the Dr exercise and business continuity planning that happens at an process or an underlying dependency level we pull that in and then we roll it up to the service that's how these two are overlapping and if you had seen in the dependencies there was also RTO RPO and the latest exercise result right so that will be pulled in as well so these are the suggestions for the IIT person who's looking at the technology dashboard so you will be able to see it related controls that are failing and impacting multiple Services i t related risk that is classified as high residual risk uh impacting multiple Services as well so same thing uh you can flip it to facilities so this would be the facility manager they would be able to see how many facilities are they managing and their context on how they are supporting the business what is the resilience posture when it comes to facility assets uh if someone from the procurement team logs in they'll be able to log into the suppliers filter they'll be able to flip it to that and then they'll be able to see how many suppliers are we dealing with today how are we supporting the business and what are the resilience postures and different metrics around suppliers today so these are the different metrics dashboards visualizations and the forms that we have released for operational resilience what we didn't discuss in detail is the self attestation piece this is also a survey driven attestation you'd be able to select the different Services you'd be able to select the different importance assessments and the scenario analysis and say for let's say year 2023 we are done and you can add an electronic signature and complete it and then once this is done there's a PDF file that will get generated along with the person who's signing this off right so where you would be able to see this attestation is for these four services and these are the assessments uh so this also comes with then default document template that you guys can configure so this was the overview of operational resilience guys if you guys have any questions or if you have any further queries um please feel free to reach out to us and then we can take them out yes last one that went long um but there are a couple questions I don't know if you've answered all of them uh if you want to just take a quick peek um but thank you so much I mean that was that's why I said in the beginning that uh Major versus minor uh enhancements there was a lot that went into this release so thank you and your team um do you want to just take a quick look at the Q a and see if there's anything that you want to address otherwise we can follow up with anyone we need to after yeah there are like three or four questions we can quickly go over that so there was one question where uh whether it is the best to do the best way to do is using different templates for assessments yes you can create multiple templates we can Target it for a specific set of output right that can be done and or if you want to start using it as it is in the product today and then as and when the program matures if you want to move into multiple assessment templates you can do that also right so uh you can start doing the crawl walk run kind of an approach uh the next question is issues added from the scenario analysis do they pop up in the business services page yes so whatever you add in the scenario analysis as issues they do come up in your business services page everything that is related to the service or the underlying dependencies that will get pulled in might not be immediately there is an scheduled job that runs and populates those dashboards so once that runs it will come up there uh what is the action that a user needs to take in the scenario analysis the action that we are tracking in the um scenario analysis is tracked via our issue management where you have an action plan and issue tracking system shut up that's where we want uh we have planned the findings and issues and actions to be tracked uh what happens if the business service hierarchy changes over the years so that's the last question uh typically the the updated data model will start pulling in the information and it will start dissecting it based on the scheduled job that runs it runs typically once in a day you can also manually trigger that right so that option is there but once that job runs it will start the reporting in the new hierarchy fashion so it all will get aligned to the newer data model and that is how it is we have taken care of that great thank you so much for all that you've shared today um and there's a lot of different ways to connect with us after this if you do have specific questions for us we'd be happy to answer them um Osman always makes himself available um to the detrimental probably his his personal time but he is amazingly um uh willing to answer questions so thank you for asking all that you did today um if you want to connect with us in other ways there is always um our community and uh as I said before this additional uh live on servicenow webinars that you can participate in so these is if you want to use the um the link was shared in the chat uh there is a QR code but that concludes our session for today thank you Osman for giving us so much time so much detail um really appreciate it it's a great presentation thank you yeah all right bye have a good day guys

View original source

https://www.youtube.com/watch?v=Ef_z0MoTuAM