What’s new in Policy & Compliance Management and Audit Management
all right we're gonna get started thank you all for joining us I'm very excited to be here to talk about what's new in policy and compliance on the new store release and I'm also very excited to be joined by derov Anna Nursery our two product managers so welcome I wanna go uh got a couple of things for housekeeping here before we really leap into this um you will be automatically placed on mute you are but please use the Q a we want to make this interactive if you want so you guys to ask questions you want to make sure you get your questions answered so use the Q a path the Q a drop down for that um that way if we don't get to your questions for some reason we'll actually be able to get to you because we'll be able to keep track of them um the session will be recorded and I will put in the chat a link to our YouTube channel our YouTube playlist um and then window session engine might be getting a survey if you do have time if you could take that that'd be awesome um we do appreciate the feedback uh so with that very excited we have released new enhancements on the servicenow store for policy and compliance very excited about that um we've got a series of webinars that we're talking about these enhancements the first one was back on February 7th so if you haven't seen that you can still Catch It On Demand on the playlist it's a brand new user interface um very exciting the next one we had was on the ninth and that's around nervous management application you don't want to miss finding out about risk appetite that is um super super exciting and cool um things that you don't want to you don't want to not know about in addition to our AI that we're using to categorize risk and then we also was part of the risk management application we use a couple of our common core things like issue data modeling and common controls we didn't talk about those in the risk management application um demo because we saved them for now so today as part of Carlson compliance we're going to go through common control inheritance we're going to go through the issue management inherence enhancements that's also applicable to risk management so know this not just policy compliance with that I'm going to turn it over to derov to uh to walk us through some of these very cool enhancements thanks for joining hey thank you darsa thanks for inviting to this call super excited thanks everyone for joining from around the world I see we have good participation today and I'm gonna walk you through our common controls feature as well as the other feature which is issues so it's a power pack session we just have one hour so I'm gonna squeeze right into n let's get started with the common controls so uh I hope you see the standard control screen right uh it's a blank screen right now yeah silver so before getting into common controls let's talk about what and why why do we need common controls or what exactly is common controls all about so for that I have uh standard controls which I'm going to Showcase so the controls that we have today is what we call it as standard controls the way they are today um we have control objective you go ahead and Link a entity type to it in general where there are a couple of entities that you have linked to it and it goes and it generates controls I'm sure every one of us on this call are familiar with this system of control which is there as of today so that's how we have it today now there have been cases where there is the control which is the same control which has been repeated multiple times just because of the nature of the control so for example single sign-on as one control right uh it is being used by multiple applications but then in the system with servicenow you have to create multiple controls for each entity which is each application that would be using the control that way there are many such examples where you might end up with a lot and lot of controls now the control has a life cycle which is end to end which is tedious to manage if you have to do it repetitive time this attestation of the controls that we need to do there's also the entire cycle of maintaining monitoring testing it the issues generated out of it all of them becomes too repetitive in certain case when the control is common in nature and that's how common controls came into picture so in common controls what we are saying is you have a common control which is just a regular control you tag it as common we'll see in demo how we tag it and you mark it as common which converts the control as common and you have the entity which is actually implementing it so I have let's take an example of facilities Department you have a facility department and you you have a common control which is access control so the swipe card access is being managed by Access Control by the facilities but all the Departments residing in there all of them comply to this so instead of duplicating the control for each of them what we are saying is we introducing a concept of Reliant entities Reliant entities meaning all these departments which are in that facility will rely on my common control in this case the excess control which we have so we link it directly to Common control now that's a chain that's something new that we introduced in this release not just that you may not want to go and add Reliant entities one by one and keep going with that so we also have Reliant NTD types where you link the entire entity type to the common control and all the entities which are in this case entity one two four will also Auto populate in your Reliant entities so they are relying on it and they are taking the advantage of being tested once applied to many of them kind of inheritance that we have let's go ahead and look at one of the examples so what we're saying here is you have an entity which manages your common control and that's your main entity we could call it primary entity conceptually but that's the one which is implementing it that's the one which is testing it and that's where all the fun happens all the other entities are just Reliant and relying and consuming that so you test once even your control testing your indicators attestation everything has to be just once on my common control notice that there is also scoring so once the common control is compliant obviously I want to leverage that compliance score so I go ahead and update my each individual entities which are relying on it the score gets updated based on the status of my common control so in this case all the Reliant entities are getting updated because this is compliant again yes the individual entities can have their standard controls too but on top of it it can have the common control actually saves a lot of time oh yeah because you're you're only testing you're testing that it's a true test once you know and related with many um yes so let's just take a quick uh second example before jumping on this uh actual demo so we have our sprinkler system where we are seeing all of these are my Reliant departments they are relying on these but this is being managed by my entity which is facilities so that's going to manage it and that's gonna test it we'll also see that this common control will can also be linked to multiple wrist because if I have all this as Reliant entities they might also have individual risk because today we don't have common risk it's just individual risk that you have as is but you can Leverage The Power of linking those individual risk to my common control so all of these risks are also mitigated by one single control rather than having an individual control for them um again that's part of the common control package that we have will quickly understand on how the scoring Works uh just once more slide before jumping into the demo I know you guys are excited about so here what we are saying is I have one Reliant entity which has five or just an entity not a reliant let's say it's entity which has five different controls out of the five controls the control two and control 3 are tagged as common so irrespective of standard or common control our scoring continues to work the way it used to work so how scoring works is if my control is active meaning if it is not retired or if the status is not not applicable then it is considered for scoring so in this case only the first three will be considered for scoring and two out of three so I have total three active controls of which the first and second is compliant so the score works as two by three which is 67 percent and percentage and hence my Reliant entity score becomes 67. this is in case of non-weighted ones you can also activate the weighing of scores and we also have that in the next slide so if it's weighted average score that we have it still works the same formula it's kind of a similar formula where not applicable is not considered or retired is not considered but only the active ones get considered however in this case instead of the direct average we take the weights so the weight of compliance is summed together which is 10 plus 10 and divided by the weight of everything which is the total as 40. so 20 by 40 which turns out to be 50 percent and that adds up as a 50 percent Reliant entity score at high level for whatever uh common controls is all about we'll jump right into the demo look so I've got a couple questions now the two of the questions so I want to make sure that you you cover these in your demo because I know you will but they want to so they want to know how they can turn the Sea of controls they currently have into Reliant controls so if you can make sure you show that and I know you're going to um and the same question for um entities versus Reliant entity types so make sure when you're doing your demo I know you're going to do that make sure you show that and then the third question is even if we consider control I think it's back to your example control 3 as a key control the compliant level will be higher in the calculation so maybe if you can go back a slide I think the question was sure uh was it for the weighted one even if we consider control three as a key control the compliant level will still be higher in the calculation uh so the compliance score irrespective of it being key control or not it depends on weighted in this example I'm taking the weight of the controller now the weight can be defined by the user by default it's the V10 but in this case we have changed it to weight 20 just to showcase the power of it and this is the same that works for regular controls or common controls the only enhancement that is is the way the regular control scoring Works com common control is added as one of the factors into it with the same scoring base so irrespective of it being a key control in weighted controls it depends on the actual weight of it which will be used in the calculation so what so what is the key control I think people are having a little trouble with what the key control is yes so key control is you have a flag on the control to mark it as key control which is used for reporting purpose and differently but it would not impact your scoring so it's just a flag used for reporting refers to report certain controls has key controls got it um so so when you go through the demo I think I think people really want to try to understand this whole common control entity and you know how to make sure you change it from a a regular control to a common control and yeah so again I know you're going to show that but make sure that you slow down when you're going through that you're probably going to get a lot of questions there okay yep yep we can do that sure so let me jump to the demo right away that's a great keep the questions coming lots of great questions we really love this making it Interactive yeah so once I log into my compliance workspace again um just to highlight the comment controls and the issue feature both of them are exclusively available in the new UI so it's available in workspace if you are still on the classic UI we are doing all the Investments to the new UI the workspace so we recommend users to use workspace for this so getting it started what we have is in this I can go ahead and go to my regular control so I just have my list saved here um if someone is not aware about the workspace you could go into the list View and from list view you could see all the lists that you have available on the instance it's still loading up it will refresh in a minute and once it loads up you get a library of this sequence so I have added my list which is easy handy way of favorites and what I've done is I can see all my active controls over here so in this list of control you would see now we have a new column called function the function is where we will identify is it a standard control or is it a common control so this is the new column that we've added uh in this let me go ahead and open one of the regular control that we have so this is my standard control that I have let me just go to a different one which is in draft status so moving a control from a standard to a common control or tagging a common control to a standard can happen when you are in specific States so right now what we are looking at is you need to be in a state which is draft so I'm opening up control which is in draft State and on the ellipses that I have on the right here is where I would see convert to Common so if you see this is my regular related list which are there the moment I go ahead and convert it to Common okay in this case there was no objective let me add one so this works for all your existing controls as well where you could just go ahead and save this where you could just go ahead and you will now see the new Option of converting your control into a common controller so I would go ahead and it will confirm do you really want to convert it to Common it will allow you to add Reliant entities I say OK and my page will refresh now you can see there are two new related lists that I could see one as Reliant entities and the other one is entity types so when I say a common control with its entity it's still the same entity which was applying in this case it was Acme and I just see this too as Reliant list let's start with the Reliant entities first so I'll also take a better example of a real life scenario so that's how you convert into common I have certain controls which are already converted to Common so I'm saying I have a control which is Monitor employee internet usage now that's across my organization across different location I don't want them to go to storage websites so they could upload some confidential details things like that so I'm monitoring my employee internet usage now when Reliant entities what I could go ahead and do is in this case it's for E Acme inclusive I also have one more which is for EU VPN so when I say it's for EU BP and it's for the entire Europe region and what I have done is I've added all my VPN for all the countries over there as Reliant entities so France Switzerland Germany Netherlands all these are added as Reliant entities how do we add that you just go to add button and you can say hey even the entity which I'm listing over here let's say in this case I'm saying accounts account application just an example I want to add it it's just as simple as that it will give you a confirmation it's added and you can see it's now relied instead of adding them manually we talked about adding them all together which is via ntg types so in entity types I may go and say that hey I have a list of departments I just want to go ahead and add all of them as well so it will automatically update my Reliant entities accordingly so if you see my Reliant entities are now 12 because it added a bunch of them from Department as the entity type you can also see if this was added from entity type which entity type so it helps you manage your Reliant entities effectively and we can also see the compliance code for all of them so that's the basic of converting something into from a standard control to a uh to the common control so here if you see I can again go ahead and convert this to standard as well so there are only two states where we support conversion the first state is draft and the second state is a test only in this two states would you be able to do it because the further States like review monitor these are the ones where it's actually live so we don't want you to convert it if you have to convert you move it to one of these states and then you convert it and then you can go along with it so I remember there was a question uh yeah to answer the question so right entity is basically an entity that is capable of taking a common control do you understand that right uh of taking a common control or rather any entity which says I'm consuming from the common control I can become a reliant entity okay so if I associate myself to a common control as consuming the common control I am the Reliant entity but I'm still my entity on my own as well so for example let me just go and show this and I can still have standard controls associated with that yes right exactly I can be a reliant entity and I can inherit the control testing and other results from a common control but I can also have standard controls associated with that that is correct so in this case if you saw if we see the monitor employee internet I do have Reliant entities as friends but when I go to France I still can go ahead and have my own controls which are standard controls and not the common one so in this case I still see that there is a standard control already in place and I may still go ahead and add standard controls as well but I also am Reliant to something else now how do you differ between them because that's a really good question how do I differentiate if I'm Reliant to something versus I'm directly implementing it so we had the downstream controls which was a really related tab existing on an entity which continues to show everything that you are implementing but if you are just reliant on something you would see it under Downstream inherited control so in this case this is a new tab that we've developed in the current release and in this tab is where we see monitor employee usage because it is being implemented by The Entity EU VPN but I myself France VPN as entity I'm reliant on it so I see myself as a reliant here so that's again a new tab that we have added over here I also recalled Teresa you uh you had one more question from the common control that hey I have a bunch of controls how do I turn them directly to Reliant so if you already have a bunch of controls which are their existing control under Reliant entities we this is the path for you know going ahead and migrating because once you take it new you could have so many repetitive controls you want to make it Reliant so we just go ahead and select add from existing control now what would happen is any controls that are part of the same control objective would be listed here so I see monitor employee usage S2 with two different entities so I may go ahead and choose them all or I may choose just one of them and I may say that I want to add it it will validate once and it will confirm that yes the selected entity can be added and then I say continue to add which will automatically add it so if you have let's say 30 40 controls or C of controls which are already there repetitive you just come to add from existing control and you take it all from there select all and move it here so that's one way to do it I I think we're hitting a lot of the questions we have out here um just to kind of reiterate I can have an entity it can be associated with two common controls right that rely on it they can have two common controls and additional standard controls and then I can use my control I can map you can I can map common controls associated with a control objective also I can get all my controls added also yeah yes yes under the control objective also you could have your controls added that would when you go ahead and link your control objective and entity type or entities that will create a standard control always so via automation it's always creating a standard but you can convert the standard to a common and in common you can also have Reliant entities as you mentioned so what if I have a reliant entity of a control and I also have have to implement remaining actions related to that standard control so you have a reliant entity on a common control okay but this is a control but maybe it's a common role but I also want to implement remaining actions related to that standard control so I guess maybe it's a standard control so basically if I have a reliant entity of a control so I have a common control but I also have a standard control I can Implement remaining actions related to that standard control also so really what we're saying is you can mix and match everything you used to do before everything you see before only you can now do it whether it's a common control or standard control it will always be a standard control you can continue to be reliant on something you can still have your uh other standard controls as well and do the regular uh regular tasks and activities that you have on it it will continue to go with it that is correct so I'll also showcase the 360 view I think I also see that as well I think people are still a little bit confused about the common control so if you're still confused about common controls please you know put a question there um sure and there's much more to cover as well so in the meantime we can keep going and I'll see if I can read some of these things out and put them together to ask so in 360 view what we've done is on the control if I'm already on the control all I could see is I can see what all are my Reliant entities on the common control so that's again a new dab in my 360 view for those of our customers who've not used the workspace 360 view gives you a list of everything together it's a single pane uh view where you could go and scroll on from different things so in this case my control is Monitor employee usage and I have Reliant entities on it which are 13 so I could still see them I also have Reliant entity types so from here again if I go ahead and go to my other entity which is France VPN I would see that hey it has a standard control which is one and it also has one inherited control where I am resigned to so I have two different controls where one is my standard control for output device and second is my inherited control of the monitor employee internet usage so I can still do both of these things over here as well coming back to my compliance workspace where I am on right now what we also have is you can also link your risk to the same control which is a common control so now if I go ahead and again go back to my entity where I let's say I have four risks so let me go to one of them I would say data access for example which is a risk on my entity I may say that hey this risk is being mitigated by my control which is a common control so I may come to controls and it gives me an option of inheriting my common controls so because my entity France VPN already has a common control link to it I would see this button over here when I go ahead and select it it would allow me to select my control which is a common control so that common controls the single common control is mitigating my risk this data access similarly if I have any other risk on some other um examples or entities I may also go ahead from that risk View and I may say hey I'm inheriting it from the common control and this is the common control that is mitigating my risk which is there one more thing to look at is when we are on the entity view so in this entity view where you are we've added one more table so you had uh you had a chart which was controls which shows you about active and non-compliant similarly for inherited controls also it will show you how many inherited controls you have and what is the compliance status of it so that's a new widget that we've added we've added the new Downstream inherited controls as a related list to understand this list better we will also be looking at another entity because that is Acme where I would go to so let me jump over to another entity which is in the meantime if there are any questions uh Teresa feel free to let me know so I am on Acme as one of my entity and I see hey there are a bunch of hierarchy of it and I have so many Downstream entities and again they may have so many inherited controls so over here what I'm saying is I have 23 Downstream inherited controls now these are not just my control which means it's not just inherited by me but also by the children of Acme so if you look at the right all of these are children and then they also further have grandchildren and so on so we have it at different levels at any of these level if I'm inheriting something from a common control it would come up in my Downstream inherited list so if I want to go ahead and see it in a better way what I would do is I'll say show directly related inherited control which means it will only show you the controls which are inherited directly by Acme so in this case I can see fire detection is being inherited by Acme as a common control but this control is being actually implemented by my entity which is at my America so that's the major difference the entity on common control is the one which is the primary entity how we call it as or the one which is implementing it the one which will be testing it but Acme inclusive is the Reliant on it so I see it in this fashion similarly if I go ahead and go back to show call what it would show is it will show all my children entity so eubp and if you see here ubpn is one of my child of Acme on my right and hence I see that EU VPN is also inheriting a control and that is uh by Reliant entity as sales so sales is also one of my child so these are all my children entities along with the common control and its actual implementer so you have Downstream inherited controls and you continue to get your Downstream controls which are directly implemented by you again in Downstream controls you may have something which is common so you may go ahead and filter out so if you see for Acme I have so many of them which are common controls now this are not just implemented by me but also by my children so if I want to see that hey in Acme what all is directly implemented by me I may say show directly related when I do that it shows me all my controls which I am implementing directly it's a mix of standard and common control but this is a existing feature I'm sure many of the users are already known to this but I just wanted to iterate because it becomes easy to bifurcate between common controls and standard controls once you have it because this will be used for reporting by many organizations so that's much of it for uh the common controls that we had I I'll pause again for questions we do have lots of questions that's exciting it's actually really good um so I'm gonna read it off to you here what if I am what if I am a reliant entity of a common control and I have a responsibility to implement the remaining requirement of the same common control oh now that becomes a shared control or much of a hybrid control is what we call it that's a different concept altogether we are working on that in future enhancement that is not something that is implemented today so be taking it step by step we only had standard controls till today what we've done is common controls right now and the next step that we are looking forward for in future would be the hybrid control where it is shared among the responsibility of implementing is shared among multiple entities and everyone would contribute to it so we call it as hybrid control and that is something that's a feature which will be coming in next future releases is there a way to denote the requirements for an entity to be a reliant entity of a control uh so we can I mean uh it's all depending from business to business organization to organization be not limiting anything uh over here but the compliance manager who's managing the control can go ahead and take their call on which entities to be added we do have certain system restrictions in place uh so for example when users would try to add a reliant entity it would only go ahead and allow you to add entities first of all which has to be active uh again those entities which are already a standard uh entity with the same name under the same objective we don't allow that to be added because then it will be duplicate I cannot be the entity relying on a common Control Plus also having the standard control with the same name exactly the same name because if I'm saying that hey for the fire sprinkler system I'm relying on control on entity a and then on the other hand I'm saying that hey I'm also implementing it myself that cannot be true practically so we avoiding such Mistakes by system so system will stop you and give you error message in such scenario also if you are already relying on something else as a control a you cannot rely on control B if the names are similar just for the same reason I can be part of one of them I cannot be part of both otherwise my score will be overlapped and duplicated so we avoiding that such kind of things from system itself and system will prompt you in such cases yes good saving us plenty of ourselves um so by default controls are still standard right you have to make them you have to make them um compliant and then um yeah I'm not really good thinking at the same time um then the next question here the exempt column here what what is this what does this apply to oh so this exempt column has been since before for the control if you want to exempt the control from certain things uh scoring and things like that but that exempt column has nothing to do with the common control feature that we have today it's it's just with the general controls feature which was existingly there okay so here's here's another one that's a little bit I want to read I'm going to try to read it makes sense um so if we so if we would like to see the compliance posture in relation to a date of retention for the company would that allow one parent for General data retention and one specific to gdpr could you have this too and could we under these have child controls based on different evidence as an example a Unix team would not be able to provide the same evidence as a Windows or window team uh so I'll split the question into two parts Part which you had was can I have two different controls with same name but both of them can be common yes that is a possibility so you have two different controls with exactly the same name so one is for socks requirement second is for gdpr for example and they are under the same objective the only thing is the implementing entity which is the entity which we see so let me go back to my common control screen so if I come here the entity over here which is there that has to be different it you can have two common controls under the same objective with same name but the entity which you have has to be different because it's being implemented twice by two different entities so that's the first part of the question and the second part was could we under these have child controls so control hierarchy was already in place so in common controls we are not touching that piece at all so they can have evidence and the evidence can be collected based upon those different child controls for the different teams maybe they are meaning the Reliant entities and they collected for each of these entities because we are already at a control level and at that level you have different entities but uh yes you can take evidence from these entities if they wanna if the user wants to just reiterate that question uh better for the second part it would be helpful so I know because we got to get on the issues but I have a couple more questions um one hopefully we can answer quickly um this this is a new user to servicenow is there a way to show the the um CIS the configuration items that the control is reliant on we can we can literally this is the power of the platform we can literally go from the service to the process to the asset level so the answer is yes um I don't know if you want to show that or if we just this is another webinar that we can do yes you absolutely can do that right just a high level answer to that is for each entity you map it to your CI which is already there so if I open the EU VPN and the DN if I go to details for the CI what I would do is I'll say it refers to existing record and then I'll look it up over here and Link it to it once you have the CI because in GRC world everything everything works on entity so even the CIS become entity actually had it been a CI it would have been 90d with the tagging and then and yes you could not walk to the CI and pull up the report so you get the list of all these Ci's correct um we've got a question about risk is there a roll up on common controls to see all risks or entities mapped under that rolling it up to a control objective citation Authority document so uh the control roll up still continue not the risk score but the control compliance rule up right that still continues to work the same so if you had a control level control objective level the roll up still continues to work the same the only consideration is the common controls related to The Entity will also add as a factor to it like what we saw with weighted and without weighted it will add as a factor to it but it will continue to work the way it is and then as far as advanced risk assessments it really doesn't impact Advanced risk assessments does it uh that is correct the only thing is you can have mitigating for the risk you can have a mitigating control to it which will help you but an advanced risk assessment you still continue to do the assessments which will give you your inherent and residual score and things like that so that continues to work the way it is and then we have a follow-up to the question previously about the um evidence collection um controls today can be sent to many but only were the evidence requirements are the same she would like to be able to aggregate up based on the control objective but where different teams provide different evidence files meeting the objective and if this is something you guys want to talk about later to kind of dive into a little bit more to get more details on it I'm sure that we can do that yes we take it offline but just at a high level also what I would like to inform is for the same control you can still have it attested and the attestation process still works the same so I may go ahead and see a CRC attestation I may go ahead and give a test and attestation respondents over here for the control even for the common control I mean to say and once it is attested it goes on further for the compliance status yes no but for the evidence requirements yes we could take it offline and we could discuss more yeah I think that I think that would be a great enhancement um I'll let you switch over to the issue stuff but while you're doing that I'm going to ask you a question um so on the store if someone actually wants to be able to start using these things it's not the policy they don't they don't import policy and compliance are they updating is it common core plug-in what is what's the what's the plugin they have to make sure they update yes so they will have the two plugins the one is the policy and compliance and the profiles plug in both of them is because issues code is lying in the profiles plugin whereas uh the policy income planes has the common controls thing so they will have to install both of them yes also all the details of how to do it step by step is already out on our website for documentation so yeah they can also find support docs we will also be sharing a KB article so if you have more questions in regards to how do you go ahead and do the weighted score because weighted score by default is not enabled you need to go to a property and you need to go ahead and enable it for common controls so that is where property under policy and compliance where you have Administration you would see it there let me quickly show that as well before we jump into the uh issues thing so if if you feel that hey weighted score works good for me what you would do is you would just go to properties in this case I've already activated under policy and compliance you have the properties excuse me and under the properties is where you could go ahead and Define that do you want to go ahead and second this one now I'll just have to refresh my instance once but uh basically in the properties is where you would have it I will also bring the I mean I'll also share a KB article at the end along with this we would post it which talks to you walks you through the entire process you could also select the states specifically where you want the score to be considered so only if active then they are considered so what are active you could again go ahead and Define it there as well so all of that is configurable for scoring as well and fantastic if I put the um in the chat I put the list the the URL to the registration page to register for more of these webinars um also the the playlist so you can watch other ones on demand but here we are with our issues sure so the issue is also we were getting that hey we have issues explosion there's so many issues we have to manually manage because one issue can only be linked to either one control or either one risk and even in that case because issue is common across risk and risk and the control that you have because both are mitigating each other then that issue should be allowed to be linked to each other similarly issue cannot be linked to multiple other objects if it's the same issue if I want to link it to three four controls or five or different risks or mix of risk and controls or risk events so that was all not available that's where the architecture changes is what we've done entirely from the technical model now what we are seeing in here is we are revamping we've revamped the issues already where now everything that you had previously as a reference field which was single select is now converted into a multi-select wire related list so in issues all the objects that you are able to you are able to relate as a reference field earlier which was only one now you could do multiple so the key feature basically is you can relate the issues to multiple risks control events any transaction records entities it may be orders evidences so you could go ahead and Link it to multiple objects this will significantly reduce the number of issues just because it was one-on-one you had so many of the issues and again managing the issue entirely from its life cycle again this is available to all our customers and for this you need to install the GRC profiles again this is only only available in the workspace experience so if you have the new UI experience that's where you would see the multiple linking if you're still using the old one you continue to use as is but you won't get the features of linking it to multiple accounts so just one thing you're not so I'm just having a before and after slide so in before you had individual issue per object in this way issue one two three and after you could say hey the single issue relates to all these things that I have in my GRC system let's look at a quick example I'm saying that there's a risk of unauthorized success and there's a control for excess control mechanism already in place if while testing the control the test field and that led to a tissue now I can link it to my entity my control as well as risk earlier I would have created two or more issues in this case but now it works only with one similarly a very common example in case of patching of systems if I've missed a patch it would lead to so many multiple risks which are there due to the single patch and now instead of having six different issues I can have one single issue managing by relating it to all six of them so that's that's majorly the change that we've done uh I'll jump in directly to the demo for this as well so I can go again back to my compliance workspace as an example in this case foreign I think it was the impersonation that we end it and I'll do it again I think the the big the big driver for this particular release really was simplifying a lot of the manual or repetitive um actions that people had to do the ability to inherit the testing from the controls the ability to relate issues to multiple um elements is is it really simplifies and and also it actually provides from an issue standpoint a holistic view of of you know where the problem is you know what it relates to it's kind of like a 360 degree view where you can actually see that this one issue released to all these different things which really it makes it makes it the ability to visualize where the issues are where the problems are what you need to work on first prioritize I think is huge um would it create duplicate issues between the two generated automatically let's see would it create duplicate issues between the ones generated automatically automatically wants a control indicator or fails okay so it would generate duplicate issues if a control fails an indicator fails multiple things fail would you get multiple issues that's the answer is no but maybe you can show how that works yes yes yes so one thing that we've done is exactly how you are explaining it that now you could have a 360 view of the same guitar issue so I have this financial accounting has a control test failure which was my application so I may link it to already a single control over here which is which it's already linked to or I may say that hey you know what this also applies to a set of entities uh this is just my demo data it's not relatable but I just want to show the power of what we've done so once I go ahead and say hey it applies to all three they also have their individual entities it also automatically updates the related entities for it so if you see earlier delivered two entities and addition of three more we can also see those three entities automatically linked similarly now for the same issue you may also go to risk and let's say it was due to a vulnerability and the batch fix was an example you may say that loss of availability is for all of these entities and earlier you had to had individual issues for each of them as well so now you can actually go and relate to them not just for this you can even have engagements you can even link it to multiple risk statements so risk statements again is the other thing which gets Auto populated if you have it different in this case it was loss of availability for all my invest so it's still one but had I gone and let me try to add another risk so it also updates the relevant risk statements for me so if I say loss of confidentiality for example um it would update my restatement also to reflect the same similarly when I add controls so I see now it's two risk statements that I see lots of availability and confidentiality similarly for controls when I go ahead and add certain things my control objectives also gets updated had it been part of different control objectives that I had we can also go ahead and Link it to multiple policies or risk events or processing activity processing activity just for those who don't know we also have a new app for privacy and that's where it comes from so you could also link it to those processing activities and the issue is linked to all of them going to the three what about what about citations yes yes we'll come to that as well okay so coming coming to the 360 view is where you could see that okay now my issue is related to all these multiple objects I can deep dive into one of them I can also see it by different ways and graphical I can further go down to that entity and I can see what other issues if there are any which are there and with the integration of common controls we can even see the standard and inherited controls such as a refresher for it so coming back to my um issue which I had I recall one thing which uh someone had asked was about you have indicators which are in place would they continue to create individual issues uh that is a yes for now so meaning if you had three different indicators on three different controls and they were failing it will continue to go ahead and create three different issues but you can go ahead and manually update it now because we don't know which indicator is because indicator is a manual set of automated indicators or manual it's all done by company to company based on their requirements so we don't know when you want to go ahead and mix it but yes that's again one of the things that you would have to take care of uh one more thing that we've done with the issues is for administrators uh this is so in GRC Administration we have added issue relationship configuration now what this does is as you saw that whenever I'm adding a risk the risk statement gets Auto populated similarly whenever I add a risk The Entity gets Auto populated that is driven by entries in this configuration so in here I go ahead and configure it that what is my relationship between issue to item item in this case is my risk or control and what should it update so I'm saying it should update my entity that's one entry my second entry talks about content which is again about my risk statement on entity or the control objective and my third entry is about processing activity so from privacy if I have a processing activity it will also update my relevant entity all these three configurations are also shipped out of the box so customers have it ready to use they are free to go ahead and add more relationships here and again there's a detailed documentation about how do you use this and how your admins can leverage it so if you want to go ahead and merge certain things or add uh when certain things are added you may as well go ahead and Link this too so um I will jump back for a minute and try to go back to properties I saw that I was logged in as a user rather than admin and hence it wasn't showing me the right things so if I come back to properties under my policy and compliance that's where we were talking about the scoring and here are all of these states which are considered for scoring so these are different active States if I remove something from here let's say if I only keep monitor so only monitor controls will be used for scoring or not I also have a property here which says use weighted average control so if I make it yes it will take the weighted average score or else it will continue to take the regular Squad so I just wanted to show it before we jump on to other that's majorly it for how we have it issues uh if someone hasn't seen I also want to take this chance to showcase the issue overview page because with the issues we also had issue overview page already existing but when you link the issue to multiple things you also see this dashboard now which will show you issue by State issue type rating you can go ahead and change it so it's a visualization you can track your tasks and exceptions for over here um and that's how this is already out of box you can filter it by entity and you can see certain things for that so even after the issue architecture changes this issue landing page continues to work the way it was supposed to work and even this is widely used for issues so we've got a couple questions in the last five minutes or so um this is really to be able to take um other elements and related to an issue you can't really map multiple issues together um together if you already have let's say 10 different issues which are already there now you cannot combine them or merge them into one as of today but that is something we could look at in future but today what we're saying is you remove all the other ones you keep one issue and Link it to all the 10 different objects from where it were created but if you had a bunch of interest if you related them to an object it would relate all those issues to that one object then awesome correct correct correct and so that's that's not the question so the other question then is um in the issue we saw the 360 degree view we saw risks we saw controls if we added another control and related it to that issue and clearly there was an issue so the controls that are related to that issue right now are non-compliant if we related another control to that issue would it automatically Mark that control is non-compliant uh no so it works the other way around whenever the control is non-compliant it creates an issue now if you link the same issue and go ahead and tag it to another control you are saying that because this issue is open on that control it should Mark it as compliant so the control status basically works on based on the attestation that has been done and the review of that control so linking it is just a alternative or an option to go ahead and work with the issue to have it linked to multiple objects um the the automation of it that still works the way it was working so does not change over there perfect we don't have any more questions in the queue right now but if you do have one please feel free to to ask it uh we we still have a free minutes so if we want to see I will also showcase as to have the controls let me take one common control we spoke about monitoring EU VPN as an example sorry this one let me take the other one so I just want to showcase that here if you see all my Reliant entities are there which are added by different ways I can also go ahead and remove my Reliant entity type which will only remove the Reliant entities from this so in case let's say a department moved away from a particular location or to a different location you may go ahead and remove that entity type and it would go ahead and update your Reliant entities and automatically remove that so it works both way for adding and removing as well what I wanted to talk about is if you see the compliance score over here it's also by default zero in this case it's zero because there are no other controls on this and the current control is non-compliant if I go ahead and make this control as compliant it will also affect my compliance score over here so all I have to do is go to Able tutor because that's the one who's been given the attestation and take the attestation and Mark it as compliant so even that works and that's already taken care about so the scoring gets calculated accordingly so we we have we got a couple questions we're going to follow up with those questions later on I want to have to I'm going to report we're going to have to stop um stop the recording and and move on but I wanted to thank you so very much for everything um let me just actually if you want to go ahead and and go to the next slide um there we go there's a way for you to connect with us we really appreciate your time draw you know Rob thank you so very much for your demo skills everyone was raving about them on chat um check out our website you know connect with us on the community you can use these um QR codes to be able to get the playlist it's also in the chat along with the registration for the webinars and again thank you very very much for your time and we look forward to seeing you in our next webinar thank you thanks everyone for joining bye
https://www.youtube.com/watch?v=6x6D1mEpCzI