logo

NJP

ServiceNow Emergency Management Webinar Series: Decision Support Workflows

Import · May 16, 2023 · video

appreciate everyone joining uh Maylene is going to continue to let folks in and put them on mute uh this uh webinar is being recorded so we'll uh you have a a record of this at the end if you do have questions uh if we can put them in the chat and uh Todd and I will be glad to take a shot at answering them at the end and with that we'll get started uh my name is Brian Myers I am a risk solution executive for servicenow I operate across the federal civilian space I've been doing this for about three years uh we brought Todd Huber out of the government and had him join us about two years ago Todd thank you Brian good afternoon Todd Huber here I am a solution consultant with servicenow in the integrated risk management practice working alongside Brian Myers and I have been with the company about two and a half years now I think and prior to this I worked for the federal government as both a contractor and Agave doing cyber risk management diet cap way back in the day and then RMF when we transitioned over so I in 2016 I look forward to the uh conversation and the time together this afternoon back to you Brian thanks Doug and uh before I got to service now I uh started out in the Coast Guard I actually did uh law enforcement for the Coast Guard uh then uh flew helicopters uh and uh had enough fun so I got into Telecom uh and ended up running uh the some DHS programs uh around their Network for uh um about uh 15 or 20 years uh got my masters in cyber policy and management and certainly uh wanted to uh continue into a a topic uh risk is where I ended up here in servicenow and it servicenow is a a great company so uh servicenow being a great company uh you know we've we've been growing since I've got here when I started we had about 10 000 less employees so about three years ten thousand employees we're seeing uh growth rates uh in the 25 plus range uh even through the pandemic uh we're looking at uh about 7 700 customers uh worldwide um and you know we do our work uh because we optimize we connect we create but we add back to the business we drive a lot of innovation and strategy back into the business so we can continue to uh get better do things better for our customers for our customers and we do that uh we we've been noticed as a great place to work um but it's less about our people and it's more about your people it's the uh you know 40 498 000 and people are part of the community have signed up for our community so they can share information amongst themselves we offer free courses we've got over we're we're shooting for between 2023 and 24 another million people being trained uh inside of service now uh through us and our partner and that's our rise up uh community so certainly uh want to make sure that if we have Partners on board uh this call we uh we definitely want to work with Partners work with agencies uh but uh really we're about the platform so our platform is based basically on on that single and reusable data model where a fedramp high uh solution uh SAS where uh we've been uh in used across fedramp about 150 times and what we do is we use that uh all of those capabilities in the purple though that all of those interactive pieces those silos inside of your organization and try to connect those using that single data model and then add AI add orchestration give you the capability to do low code uh across that give you a full analytics capability and again give you the security that your data is your data it's going to stay your data even if it's in our cloud that means absolutely nothing if you can't engage your customers so uh you know that's the engagement area there um whether it's through email or SMS or group meetings or chat or virtual chat we don't care how you're connecting with your customers we want to give you the capability to support all of those different uh instances across your organization and that gives us the ability to kind of uh offer the uh different um different dashboarding different dashboard capabilities so that you can see that data about your organization in real time whether you're in customer service you're in it or the back office or today we're going to spend a lot of time talking about being in governance So today we're going to spend time in governance and I apologize that you know the people uh signing in are still throwing me a little bit but what makes our platform different is that consistency and scalability that single data model with the ability to scale inside of that data Lake the ability to engage with your customers and with your partners and and make sure that you're talking in the same language uh so we offer that productivity through that Automation and being able to drive that Automation in uh into the uh into your workflows and then add in Ai and ml where we can so for the governance portion we'll really focus on risk management but risk we really don't talk about without starting with where you're with the important pieces and that's really policy and compliance so if you are a government agency if you're a corporation somebody is telling you these are the rules you have to follow and then you're setting up policy so that you can tell the people inside of your organization these are the rules we have to follow so that's policy and compliance we connect to uh our the external data sources uh bringing in the regulatory change management to ensure that you're you're following the correct regulations and so that gets you to a place where you can be compliant today we're going to spend a lot of time on risk management so you know the ability to measure and manage the risk across an organization whether that's starting in a project building into a portfolio at the Enterprise level or somewhere in between top down bottom up it doesn't matter qualitative quantitative again doesn't matter that's going to be the focus of our our discussion today especially as we're talking about those those mission-based decisions that that we've gotten to to make across organizations the third line of defense in governance risk and compliance is audit so audit management being able to understand who's auditing you why they're auditing you when those audits are due and then tracking all of these the the different parts of that audit from uh the beginning from that that letter that that shows up from oig or OMB or GAO and then flows down into uh the the your response and tracks issues out following that response Todd Huber is going to show you uh what we call our 360 view so the ability to see uh not just what uh the the system you're looking at currently but but also uh upstream and downstream from that uh uh and and what controls are in place and what risks might be uh affecting that device or or entity and then finally is privacy management but again today we're going to focus on risk management risk management is a is a crucial part of running any business how do you under how do you make decisions how do you understand how your spending and ensure that you're spending to mitigate the right risks not just the risks that are most prevalent and how do you then offer uh two-year leadership to to uh the the folks paying your bills um the fact that you're making the right decisions as necessary so risk management really follows a simple workflow and that's one of the reasons it fits really well with servicenow is because workflows are what we do and you know what we're going to try to do is is show the automation of what we can do as we move from a risk identification to setting a risk appetite for an organization for a portfolio for a project then measuring the inherent risk what risk is there altogether What treatments can you make what mitigations can be put in place then that should leave us the residual risk and then risk reporting one of the key factors because we are sitting on this data Lake and if we can look at Key risk indicators key control indicators key compliance indicators if we can see those in a digital fashion then we can measure these in real time we can measure those key indicators in real time so that you can see when a deviation occurs and you can take immediate action as necessary so that's going to be really critical as we're moving uh more and more into different areas of what uh these missions and and missions are going to be as varied as you know I've got to bring a team into an area what what risks do I face how do I mitigate those risks I'm doing a mountain rescue because you know what I'm I'm part of the Department of the interior and I've got uh um uh places I've got to get people out of uh crisis management building industry water rescue forest fire each one of these has a different risk set of risks and a different set of risk responses that can mitigate those risks we're never going to mitigate all of the risks but controlling those risks as much as possible is really the job of leadership as we're moving forward the way we measure risk is through an assessment so it Todd's going to walk you through a risk assessment and you know what we we talk about that risk identification we found a risk what asset or or uh group of assets is going to be uh um affected what probability is there what level of impact do we have mitigation plans and we can start sir we can certainly look at uh risks across the organization and it's it's really a math problem uh risk comes down to a math problem if you know what your inherent risk is or I'm sorry if you know what your risk cost is what what's the chance that you're going to lose something uh in that probability then you you've got what's called inherent risk you you know what that inherent risk is if you subtract out the mitigation value what uh mitigation uh you're putting in place minus the cost of that mitigation now you've got residual risk Todd will talk about both of those as he's moving forward but this is just a single risk vector and we know that if we're doing all of the these different types of work we're not going to have a single risk Vector it's going to be a multitude of risks and in this case it's probably you know in most cases it's probably more than four but we'll use four for this example so for this example you know we've got four risks uh risk three we've got no mitigation for it and we've probably got a higher level of risk than we want to to uh to to manage or or to place our our assets into so let's continue to look at different mitigation so we'll look at different ways to mitigate those risks um and now maybe we get to a level a moderate level risk where the residual risk is is uh is yellow for us and and maybe that's somewhere where we can say yeah that's that is a an acceptable risk it fits within our risk appetite but then we continue to look and we can see maybe we find a risk like Risk 3A that where we've got a you know it's a critical risk uh but it's it's not something that's been uh looked at before so um you know eventually we want to get to a place where we can get to an acceptable risk and we know government agencies are doing this today and it's um really uh a a in most cases a paper-based solution this is from uh uh a DOD format um for flight standards and it's really that's this is about whether I should uh as a pilot take off and as as a former pilot this this guy that resonates to me with me um you know whether you know you can uh whether you're aircraft's in good shape whether you're uh in good weather or bad weather uh whether you're uh really able to create the mission and what you can control down at the bottom one of the critical parts of it here is you know if the dynamic risk factors is was the flight turned down by someone else are you do you think you're a better pilot than somebody else that's probably a pretty high risk score so there are other kind of risk assessments I think this one's from NASA uh it's it's for one of their missions you know what equipment do you have what infrastructure what processes and then identifying the known hazards in the critical past how are they going to mitigate those we're up this is I think a uh a DOI form um and you know are your supervisors aware has there been adequate planning and this is just a basic one to ten scale uh for each of those uh um individual scores added up and you've got kind of your your overall green and red uh solution uh finally uh if you're really into mathematics miter put uh this table together for operational mission risk and you're able to do this math to ensure that you're driving in the right direction you you're you're capturing all of that uh okay all of the uh requirements all of the risks and all of the mitigation so that you can really drive forward into uh what you what you're trying to do servicenow wants to take that and because again we're a huge data Lake we're a uh a relational database sitting on top of that database or our data Lake what we can do is we can do that math we can bring in those values we can bring in all of those different pieces from those different types of risks and we can present them in a way that's understandable to everybody on the team uh everybody can see a heat map that's on the bottom of the phone picture there uh you know and red is bad green is good if it's likely or unlikely if if the risk is high so you know what risks do we have to mitigate in that top right box in order to make sure that the mission goes off really as well as possible with the least amount of risk possible so a couple more slides and then we'll get to Todd this one builds we start with this heat map we can open the the operational risk management heat map we're looking at uh control Effectiveness we can see the different controls inside of that heat map you can switch over to Enterprise risk management and see how this affects our same in the same uh platform we can see Enterprise risk and operational risk we can expand these things so that we can drive forward and understand the individual risks and mitigations we can look at trending data whether it's an inherent Trend there's your inherent risk moving to residual or even an inherent risk Trend we can see how your inherent risk is uh moving and this for a mission is probably instead of the months that we're showing here is probably hours or days apart or I'm sorry three hours or days apart because that's going to be critical in making sure that the mission comes off critically or well so we want to see risks moving in the direction that this is going um we're looking at uh how quickly you can make that happen and that's really because again we're sitting on this data Lake where changes can be brought in immediately we can make those changes and really drive through to understand a risk for a mission as you're moving forward so Landslide uh you know we've got um a bit of chaos we know that the government is doing things well we know that uh industry is making those decisions well because people are experienced in using what they've got as the amount of data as the amount of information it's the amount of of or size of organizations grows and expands um that's going to be become less and less tenable so you know as we can if we can offer the capability to bring information in to make those informed decisions those who risk his decisions using uh this this data lake with the uh data repository on top that's that single layer of single reusable data model we add in what in the intelligent automation the ability to use Ai and ml to offer suggested mitigations based known previous mitigations and then that real-time reporting the criticality of of knowing how that risk is trending and make sure that we're at a point where that makes sense for the organization to take that risk and what we're doing is we're putting that risk workflow across the top of that we're bringing people into that risk workflow in an orderly manner so that they can make their inputs and they can pull data down from it as needed in order to make those best judgments to make those best decisions so like to reintroduce Todd Todd is going to talk about basically three things he's going to go through uh Persona based workspaces so that we can talk about how you know a risk manager might see something different than someone who's entering data about risk he'll talk through the risk assessment that's going to be critical to those missions and then risk reporting again critical to those missions so we can drive that forward God thank you Brian so we will start out here in the risk workspace just like the last slide Brian showed we'll start out looking at the Persona based workspaces that folks will engage the risk management solution with then we'll get into how we can create risk assessments and we'll do uh use the risk assessment methodology to build out those templates and then we'll look at some risk reporting at the end and how we can respond to tasks and notifications and and workflow items so we'll start out here in the risk workspace and right now we're logged in as Andrew Andrew is a risk manager so this is the perspective Andrew will take when he first engages the platform so we call these Persona based workspaces for a reason and that is because the the content that is displayed can be displayed based on the person who's logged in their role or group membership so somebody like Andrew who's a risk manager this is the type of content that Andrew would see if if Andrew was more of a boots on the ground worker that's interested in tasks and and uh and iron issues then they can see that type of content but this is a this is content that we provide out of the box where the risk manager role and this has kind of a combination of of top down and and the nuts and bolts work of the risk program this can all be filtered on the risk assessment methodology that has been used to assess the risk across the organization right now we're filtering based on the Enterprise risk assessment and that is the methodology that we will stick with during the course of our our conversation here So based on the Enterprise risk assessment methodology we can see the overview of risk across the organization and that's going to be comprised of the entities at highest risk and when we scroll down we can see what constitutes highest risk out of the box and that of course that can be configured if there are parameters that customers need that deviate from what we provide then that definitely can be configured if risk is being managed in a quantitative fashion as well as qualitative then we can tie that back to dollar amounts I know in the federal space there is a push to tie all vulnerabilities and poems to dollar amounts so if the risk program has migrated towards that type of risk assessment then we can accommodate that as well and take into account any key risk indicator breaches that have occurred that need attention below that we have a breakdown of the types of risks and the the types of risk or these risk categories this is configurable in addition to what we provide and to the right of that is the heat map we'll see a lot of the heat map we have uh We've introduced a heat map workbench in a recent release that's really expanded upon the capabilities that the heat map provides and I'm looking forward to sharing that far right shows the tasks whoever is logged in they're going to have their tasks identified as well as the groups the group that they're assigned to their tasks especially important for people in leadership positions and and we have a task tab that we're going to look at later that goes into more detail this just provides a hard count but we have a detailed interface that can really dig into tasks so now this is what's going to constitute the high risks when we have the needs attention window in the middle of the screen so what we consider to be the highest risks are entities with key risk indicator breaches failed mitigating controls any risks that do not have controls assigned to them uh any mitigation tasks open issues risk events that the that are underway that the risk has been exploited in some way and that's how we quantify what is the highest risk and we can see those those entities when we when we uh drill into these uh UI action items here so we want to see the risks that do not have any open mini with open mitigation tasks then we can get brought to a list view of those records uh overdue tasks across the organization this is very important we want to know what slipped the based on the dates and there are notifications that go along with these overdue classifications so for records as they progress through the workflows we have notifications that can be configured for the reminder ahead of time the actual overdue notification even subsequent notifications that bring other people into the emails as well that's all uh all all included with the solution below we have the tracking information uh for the control related information anything that that ties back to those mitigating controls and the indicators that monitor risks as well as uh as well as control so the key risk indicators and key control indicators we can display that information and again anytime a risk is exploited and a risk event needs to be created we can tie that back to a Quantified dollar amount based on the risk and display that trending data the next thing we'll look at is the list library before we move into uh risk assessment methodology templates and this is I I really like this this part of the of the Persona based workspaces I have a spreadsheet brain I kind of see things in lists and columns and so this this side this really appeals to me so in this area we can filter down and kind of have like a favorites from the my items so the entities risks and controls for whoever is logged in in case we're still logged in as Andrew you can see those items kind of like his favorites but then below that we have the library so everything that pertains to risk and compliance that could have an impact on what we are looking at so the regulations those external Authority documents the the requirements from those external Authority documents like nist OMB fisma those can be found there as well as the uh these the uh the The Authority documents the risk Frameworks the uh the uh whether they're implemented from the federal government or self-implemented the Frameworks that are in place to manage risk the risk statements which are the templates that risk will be generated from the uh risk register here and we can see that there's a 11 000 uh 151 risks across this organization and and that's that's that might sound like a lot but in terms of monitoring risk the the process that we use the entity scoping process by scoping out risk statements which are these risk templates two entity types and say like an entity type could be data centers and we have a data center in New York one in Chicago one in San Francisco we want to apply physical and Environmental Protection to that data center which is like door locks and there's a risk that that door locks could be exploited by by scoping out the risk statement of door lock risk to those entities to The Entity type of data centers then we'll apply a risk in the risk register for every data center across the organization so New York gets a risk Chicago gets a risk San Francisco gets a risk and we can monitor those accordingly and granularly as opposed to from a Enterprise perspective we can take a detailed Enterprise perspective as we continue to look through this this uh list Library here we can see all of the controls across the organization risk identification so as risk is being triaged whether that risk comes in from the employee Center or other sources once that risk is identified then we can get those assigned out and triaged accordingly the risk assessments this is where we can find another view of the risk register so not just all of the risks that are being monitored across the organization that are applied to those different entities so not that 11 000 that that full list view for that continuous monitoring or risk but the the risk register of risks that have been assessed that are already assigned out to an entity so we can see like the uh we have different risk assessment methodologies and those are those risk assessment templates so like I T risk operational risk Enterprise risk the different types of risk assessment templates that are applied to these different accessible entities like the IT department or Acme Midwest which is a subdivision of our company or the retail department or Acme Asia which is another division of the company entirely uh the the risks that are being assessed that are drawn from that risk register like loss of Integrity the disclosure of business records and within this view we can see the residual risk the control Effectiveness inherent risk as well as the response and these columns these are of course these are configurable we can add in and remove columns and really display this risk register in a format that provides the data that's that's most relevant to the person logged in risk response is a is a big piece so we have a section devoted specifically for that so we can see all the open acceptance tasks mitigation transfer and avoidance the control testing which is separate from risk management but definitely important in terms of determining the status of the controls that are monitoring and mitigating these risks metrics for our data calls and Reporting the indicators risk events basically everything related to risk we can find in this risk library and it will display a list view of that data and that information so now we're going to move over and log in as Tina Tina is a a risk admin and Tina's somebody that puts together the risk assessment methodologies and and works the uh the risk program so I have this uh this list open right now just to show some more examples of these methodologies so we can test both risks in the risk register as well as objects and these are going to be objects in the configuration management database whether that's going to be an application or a project or a department or something other than an actual risk but that we want to run a risk assessment against we can make that selection and I'll show how we do that once we get in the template so the applicable entity classes these give some ideas here so organization asset business application project company line of business so it's it's very flexible and I'm emphasizing this to show that it's the system is very agnostic in terms of what we are assessing risk against we don't the system doesn't really care what type of risk it is it's still going to leverage automation it's going to leverage workflows and it's going to uh address the risk management process accordingly so I'll open up the Enterprise risk assessment this is what we looked at back on the home page when we were logged in as Andrew and I'll show how we can build these these risk assessment templates out so the top of the screen the assess item here that's where we can select whether it's going to be an object or risk and we can run these assessments against not not just uh like entities within in uh like a traditional Federal I.T Enterprise this could fall outside of those traditional use cases I know we have one in a uh a use case in a uh a foreign government a local foreign government where they used risk management with their uh with their Police Department to be able to to assess risk of calls that police officers go out on and they can determine the level of support that needs to be provided in the most efficient manner so these there are very broad use cases it's not just limited to or siled into specific types of risk assessments so in this case we're going to look at some we're assessing risk in the risk register and then we're going to apply this back to those entity classes so we're going to run this assessment against companies suppliers and business services in terms of the risk assessment workflows we can select inherent residual risk control Effectiveness enable a risk response or a combination thereof if we want to do just inherent risk assessments we can do that just inherit and control Effectiveness we can we can break that up as as the need arises roll-up configuration if we're going to do the quantitative risk then we can do our calculations on those annual loss expectancies this is grayed out because this has already been published and it's in use but if this wasn't grayed out then we have like min max average and those different types of options for business validations this is where we can build out the the assessment further so we can mandate the risk response and on different uh types of events so we can mandate the risk response any time the risk assessment is run or we can mandate that risk response to be provided in the event of a breach of appetite or tolerance so if that appetite what's been established as acceptable risk is uh is is is is exceeded then we can uh then then we can automate the process of kicking off a risk assessment same thing with the breach of Tolerance if we exceed that appetite go beyond that and then even go beyond the tolerance then we can even kick off additional workflows and and uh and uh and risk assessments for escalation in that type of event uh reference information I look at this kind of like pen testing like white box gray box Black Box pen testing so how much information do we want to provide to the risk assessor do we want to show the related risk events uh the related risk indicators things that could provide a more a full picture of what's going on in terms of risk show any open issues provide any previous assessments and the the answers that have been provided for that so how much data do we want to provide to that risk assessor and then we can expand on that copy in those previous responses and then we have some of the the thresholds here for the notifications that will go out as part of the reminders we discussed earlier now for setting up the risk assessment itself we have three factors selected here so we have inherent risk control Effectiveness and residual risk so we can click into these and see what they are going to entail so for the assessment contribution if you're doing qualitative and quantitative this is where we can make that selection right now this is just qualitative so we'll also establish what our factors are impact likelihood and risk velocity and for scoring we have our three-point scale here these scales can be changed if you do a four or five point scale then we can definitely deviate from three point if necessary and then how do you want your heat map put together so when we do our reporting at the end of the assessment what the heat map looks like so we can track our our our risk movement and our risk trending back into the main assessment we'll open up the control assessment here and see how this can be performed we have our qualitative rating we have our three-point scale again that's going to be uh that that's that can be configured to a four or five point scale and then the important calculator the important configuration item here is this calculate based on we can do assessments of the individual controls or controls as a group so if you have a large scale assessment and going through hundreds or thousands of controls is just not feasible we can do a uh we can do kind of like a bulk assessment of those controls and and do them in in large chunks residual assessments the last one we'll look at here this is where we can see the factors that are going to be included again the impact likelihood velocity these factors are totally configurable so if you have different types of risk assessments that would require different type of assessment factors this is where you would make those selections and you have complete control over that so this is kind of like adding Quest like uh adding questions from a question rank into an assessment same kind of principle here we just select factors from that factor bank and we can pull them into these uh these templates three-point scale over our impact rating and then our our heat map colors there so that's how we build out these uh these risk assessments that we will leverage when we get into uh actually uh managing and monitoring risk so now we've logged out as Tina and we have logged back in we're uh we're logged in as Thomas Henry and I right now he is an Enterprise risk manager so the this is the Thomas is going to be the person that's going to be able to actually carry out the risk assessments and and work with the people that are are in the field that are related to these entities that we're assessing so we're going to stick with our Enterprise risk assessment here is the filter on the risk assessment methodology because that's what Thomas is interested in and we're going to be able to select different entities so think of an entity as a noun it's a person place or thing anything that a risk can be applied to or a control is applicable to then that that can be an entity so a department a business process a service an application an information system asset anything that that that uh that risk can be applied to Across the organization not just cyber but Enterprise operational different types of risk that's what the uh that that's what the entity will be so in this case we're going to search on uh Acme Midwest because this is the uh Bitcoin yes there's a question saying what about a risk quantification Advanced risk management are you demoing that now we're gonna get to that uh in the risk assessment yep we are thank you Ryan we are we are going to get to that and then it then another question go uh asked does this work with high value assets absolutely I was just typing that answer in uh yes and it does work with high value assets both on the compliance side the RMF side as well as the risk management side so you know knowing which assets are your most valuable is critical to an organization and then so maybe that's where you spend more of your mitigation resources than a lower value guys thanks Brian and I'll I'm going to open up a couple of Records here and I can show where we can add in those fields to designate a high value Asset and even some uh ideas on how you can automate defining what a high value Asset is so uh back over to Thomas uh Thomas Henry we've selected Acme Midwest that's the uh The Entity that we're going to filter on so we filter down on the uh on that particular entity so now the values are going to change here and we can see the risk posture based on uh the inherent risk and when I I click to see what that high likelihood and uh extreme impact risk is then we see loss of Key Personnel so I can drill into that and and open up the actual risk record and see all the data related to that so the overview tab here is going to have some reports that look similar to what we saw in the main workspace homepage but it's going to be specific to the data related to this record so we can see the workflow that that this risk will follow right now we're in the assessed step of the workflow or the risk assessment will take place and then when we go below that we can see these reports like the residual risk who the assessor is the approver the risk response data the effectiveness of those mitigating controls and then like what needs attention so we have a key risk indicator failure we have uh 25 percent of the controls are failing we have seven open issues and we can drill into these data points to see everything related back to that risk on this details tab this is where you can you can add in like high value Asset or or high impact risk Fields into the form this is servicenow is just a it's a big data Lake a big database and everything in servicenow is a record and a table in the database so right now this record that we're looking at this loss of Key Personnel risk record this is uh data that comes from the risk table so all we would need to do is add a couple columns add a column or two into the risk table to capture the data that you're looking for and then we can filter on that data we can use that data to drive Automation and uh and and use those data points for reporting so if if any of the uh the out of the box fields and values that we provide don't meet that that need for data calls and reporting that you have then then you can just add those fields in and filter from that so now here we can see like the risk statement that this risk was generated from the loss of Key Personnel that's that risk template the risk statement The Entity that this is tied back to and as far as uh ownership we can tie these back to groups or individuals I know for continuity of operations it's best to not have that single point of failure so we can assign these records out to groups so if we want to override any type of uh of of risk assessment results there is the capability to do to override results in the platform and we can see what the risk risk appetite status currently is uh for risk assessments anytime a risk is assessed then we're going to be able to see that risk assessment here in this related list the Enterprise risk assessment is the template that we looked at and what we saw earlier so we can see the uh the risk assessment that was performed so here's our overview page we can see the different risk assessment steps inherent control assessment residual risk assessment and what the responses were we can either reassess this from this point or uh click or or view the assessment that was performed foreign so now we're looking at the assessment and this should look familiar because this is going to line up with the the factors and the template that we saw on the risk assessment methodology earlier so for this this Enterprise risk assessment for inherent risk we're going to look at the factors of impact likelihood and velocity so once these values have been put in then based on the the math on the back end for scoring with it has computed this to be a high a high score with a risk of of 64. we can continue to do that across all of the different areas of the assessment so the the mitigating controls we can see the controls like establish and Implement maintain critical Personnel list the controls that are in place what their status is whether or not their key controls tied back to financial data and uh what the weighting of those controls is the assessment results down here we can see it's effective across the board and we have our have our scoring here when we go back up to the original to the to the residual risk assessment we can see these values completed based on the mitigating factors and the controls that are put in place to manage the risk we can see We've Ended up with a low residual risk score lastly the risk response tab here is where we can see what the risk response is going to be in this case we select mitigate whatever the risk response is going to be that's going to drive the next step in the workflow which is going to be the tasks to address this risk whatever that is so when we go back to the uh to the risk itself then we can see the risk response tasks that have been generated from the system based on the assessment that has been performed so here we have to mitigate the risk of Lost Key Personnel tasks that have been uh that have been kicked off and signed out to different people this one's assigned to Thomas so we'll open the one that has been assigned to us and see the task that needs to be uh to be completed so whether it's this record or any other record wherever we see the activity tab here or the activity field in the screen this is going to be our paper trail for the record we're looking at and this isn't a like a substitute or a replacement for the system logs that we keep for everything every granular teeny tiny change that takes place in the platform this is just the any user or system generated changes to this record we're going to be able to see that here in this activity field so the risk mitigation we can see that it's assigned out to us whatever the plan is to mitigate this risk the risk that it's tied back to and our work notes for what we've done to complete the uh the the the the the mitigation task that's been assigned we'll enter those in here they'll be captured in the activity field in the middle of the screen and we can see how we've uh uh we can track the work that's been done to close out this uh this task if there's any controls that we want to add in to the risk as as part of our mitigation then we can add in those controls of that at that field right there so everything else related to the risk we can see in these related lists so those four compensating controls or mitigating controls we can see them here click them and drill into them the metrics definitions so how we're going to track these the the data points for our reporting and then the actual metrics that we're tracking so as as part of our monitoring of this risk we can see the average time it takes to fill a position so or this loss of Key Personnel that's going to be a uh like a critical Factor here so how long is it taking us to fill these positions that are that are that are either lost or added in new staff retention and the turnover rate that's also a quantifiable data that we can use to measure against this risk this is an important data point here the issues or poems in the federal space anytime a risk or a control has either exceeded its its uh every time a risk is exceeded its appetizers or tolerance or if a control has exceeded it's uh it's its measure for compliance then issues can be opened up to get those controls and risks back into a compliant and a acceptable state these are also um workflow driven as well I can open up one of these to see show what that poem record would look like this is the out of the box workflow that can be deviated from we have flow designer it's our low code no code workflow engine and that can be used to add in additional review or approval Gates so if your organization has a sophisticated review and approval process for poems we can replicate that process in the platform easily uh details tab the attribute specific to this uh to the to the poem or the issue that we're looking at we have the issue Source here in this case it was an indicator failure so the indicator monitoring this uh this control here has a failed which has led to this uh to this poem being opened up and the system has enough intelligence in the background to not open up redundant poems or redundant issues so if if we have an indicator that continues to fail it's not going to continually open poems it will it will update and append the existing poem so you don't have poem explosion anything related to the closure of the uh of the poem in terms of the remediation tasks will be captured here and uh if there are any observations that need to be recorded not necessarily something that uh that anytime something falls out of the predefined testing parameters I know like nist they provide testing or assessment procedures for how they do uh RMF controls and there are other uh redefined testing parameters in the federal space if something like deviates or it isn't necessarily required in those testing parameters or in their in the assessment of that risk but you still want to capture that as a historical record then you can capture that in there as in as an observation so back into the uh back into the risk here that that's a good look at the risk so now we'll we'll see what this risk has been tied back to and that is this Acme Midwest entity here and this is we do a lot of work in in irm and risk management at the entity level because this is where we're able to see all of the risks that have been applied to an entity all of those Downstream controls and uh and take that organizational approach to risk management so here again in this home page this overview page we have a lot of those reports that we'll see out on the main page but here just related to this record only displaying that uh that that that filter down data based on the record that we're looking at the details with the attributes of this entity and and what this rolls up to so what type of entity class it is who the owner is and then a look into that risk register so all of the downstream risks that have been applied to this entity can be found here and then we can scroll across and see the risk assessment methodology used to test who the owner is the risk statement the current status of the risk and uh the same thing with the controls so for how we can uh look and and this is just like uh like issues at the entity level issues at the uh at the risk level the way that we can track entities or or issues across the entire organization would be here in the uh in the issues tab so whoever is uh whoever's logged in can see the issues assigned to them in their group and this is kind of like your poem home page or your poem landing page so these are the dashboards and reports we provide out of the box again these can be modified you can add additional reports remove ones that don't work and really display the data that you need to for your environment so we can see the uh the issues by overview here and we can filter down by the state the issue type by the priority the overdue issues we can filter with the uh the same kind of criteria by the issue rating by the priority so issue triaging there no matter what the source of the issue is if that's uh if it's the result of like an IG audit or a uh or a financial audit result of an annual assessment on information system or if it's self-reported uh issue that comes in from the employee Center portal the as those issues come in if they are not put in by somebody on the risk team then they'll go into the issue triaging list and we'll be able to triage them and and get them assigned out accordingly tracking the same thing the remediation tasks across the organization that's this is where they can be tracked we can drill into these they're not just pretty pictures we can click into that and see the 95 over remediation tasks as well as the evidence request tasks uh at the very bottom we can see the performance uh Trends here for issues so the open and closed uh a poem trending data can be displayed down there at the bottom and for the tasks that are assigned out to folks like Andrew right now we're logged back in as Andrew and as we do our risk assessments and we kick things kick records over for approval and kick things over for review we'll need to be able to track that information so here's the task page and whoever's logged in can see that everything assigned to them as well as their group on the left column we can see the types of tasks assigned out to us so we can see like if we have risk assessments that have been assigned then we can see there's 21 different tasks related to risk assessment assigned to Andrew and we have one that requires his approval so we can click into this we see uh the accessible entity customer support has sent over a risk assessment for approval and this is where Andrew can come in view the risk assessment as we did earlier and then either approve it or kick that assessment back for rework the main home page here is I'll pull this is the last thing that I'll show and then I'll pass back to Brian is the uh is the differences that we have in the Persona workspaces so earlier when we were logged in as uh as as uh Thomas Henry we can see Thomas has a different uh Persona workspace than uh than than Andrew does so like Thomas's heat map here has the the list view of the uh of the risks that are that are captured in that heat map and then the operational risk Trends so the risks and controls and risk events and indicators it's different type of content displayed for Thomas because he's an Enterprise risk manager this is the data that is more important to him whereas with uh Andrew Taylor he's a uh a risk manager and overall risk manager so he's able to see uh different content displayed across the uh Summit based workspace so to recap what we discussed we went through these Persona based workspaces at length and then we talked about how we can build out risk assessment methodologies which are those risk assessment templates and how they can be applied to both risks and the risk register as well as objects in the configuration management database such as projects applications or other types of uh of use cases then we looked at the uh then we looked at a risk itself how the how that risk can be assessed how the risk can tie back to an entity record in that case it was the uh the Acme Midwest Division of the organization and then tie to tied everything up with how we can track the issues that are uncovered or issues or poems that are uncovered through the risk or compliance work and the uh the tasks that are uh that need to be completed as part of those workflows so with that I will stop talking and pass the uh past the the mic back to Brian are there any questions in the chat I mean let me check no no questions in the chat Todd but if you do have a question can you raise your hand virtually and may lean if they have their hand race can you unmute them sure not a problem it does look like a question just came in um how many ftes needed to manage track 11k risks how do you not acknowledge or accept the risk I'm not sure how to segregate project risk versus General environmental risk we shouldn't have risks in two different areas within service now the other complication is group being risked by funding availability risk can age out do they Auto close what's the process to evaluate the mitigation played out so a lot of questions in this chat and yeah to add to it feel free and yeah thank you Joseph I appreciate that those questions we'll be glad to spend uh you know another some more time with you specifically if needed but uh you know so what we find is it depends on the agency it depends on the level of risk uh you know most agencies are using three to five people not serviced now folks but their own people to manage their their risks across a a smaller agency obviously bigger across larger agencies um if you're looking at segregating you know we we do offer uh a lighter version of risk management a project version of risk management in uh our SPM product uh so those risks can be brought directly into the Enterprise risk uh register and uh it basically filtered in and filtered out it's necessary so I think we can kind of can bring those uh environmental and project risks together um in a funding availability is is something that's horrible across the government as we all know um so you know being able to uh I'm not sure I've got a good answer there uh funding is a risk for federal uh projects so you know is funding going to be available in uh the next fiscal year uh you know and that should be a risk that is tracked in your across your organization um if I didn't answer all of your questions I'll be glad to reach out again and and try to answer them uh more effectively um the uh aguera asked does the U.S federal use ESG solution as part of irm that's a great question uh we've had a couple of agencies look at it no one has uh bought it as yet we released it to General availability in October obviously that was after the fiscal year so ESG and provide environmental social governance is a capability that sits on top of risk management and our SPM or strategic portfolio management and uh acts as a basically an ESG control tower over the organization and helps you measure and monitor those ESG controls any other questions that we should answer I'm not seeing any in the uh any hands up or Emily no I don't see any and I don't see any in the chat as well so awesome well we really appreciate your time and your interaction uh you know hope this met your expectations uh if it did great reach out through your AE and let's have a further conversation if it didn't let's figure out how we can move forward and be glad to talk to you as well but uh again really appreciate your your time and attention especially those that asked those uh those questions and we'll certainly look forward to uh meeting you again either at industry events or uh our federal Forum or wherever we might around the uh uh around the federal space thanks for your time

View original source

https://www.youtube.com/watch?v=-jYqbxB7zdU