logo

NJP

Deep Dive: How to Effectively Plan and Manage Entities

Import · Jul 25, 2023 · video

all right guys it's 901 and we'll go ahead and get started welcome thanks for joining I see people are getting on um people will struggle in um but since this is a recorded session we'll go ahead and get started um so welcome uh I'll just do a quick intro my name is Anne-Marie Fernandez and I am the senior technical product marketing product Solutions marketing manager here at service now and we've got Drew with us today hey guys Drew Whittington I'm a solution consultant uh in the iron business unit so I represent our risk products for servicenow awesome so we've got a full uh schedule action packed with a ton of great information um by Drew but we've got a couple quick housekeeping things um so at the end um hopefully we'll have time for some q a but we do have a office hour scheduled next week which is about 30 minutes not recorded for you all to come in and just asking questions right um when you have questions during the session please use the Q a that way we can capture the question if we don't get to it we can send out the answers after and yes this recording this session will be recorded and sent out I usually just put the link in the chat if you want to grab that and also you'll get an email with the link to the the reported session and also a survey so please please fill out that survey so we can get some good feedback and know how to improve for next time thanks right it's over I'm still waking up good morning everybody all right so that was the Q a you can see the Q a button there if you want to put questions in there you can grab those and answer them either through the Q a um or we'll shaving for office hours next week so you could be one at a time um all right next slide all right all right so today's agenda today we're going to be talking about um diving into entities um and entity hierarchies um what why is one required in some of the basics of what does it help with but we really wanted today to be in a more of an advanced session we're kind of assuming that folks are familiar with them squeeze and work with them if you didn't that's okay we're hoping you'll still get a lot out of today but we want to really talk about governance things like should when should it should be used and when it shouldn't how you can set it up initially and plan and also a key thing that's near and dear to Jewish Hearts talked about a lot why we put this session together is how do we maintain entity and entity structures over time um so before we get started we've got a poll question um just to get us to better understand the audience here today if you could just quickly tell us um about your current irm implementation today so do you see the questions uh all right yeah I'll give you a couple of seconds awesome all right I think everybody's answer on our Pro stuff for all right yeah it's interesting it looks uh looking at the results over here looks like it's kind of split you know there's about as many people with the limited deployment as there are with a full deployment um and expected usage I see some folks evaluating us welcome glad you guys are here I hope this is useful for you as you're planning out your evaluations and then as you buy an Implement my license and undeployed folks I want y'all to pay attention very closely uh because this entity stuff will get you like this this entity entities are the best thing about the solution I think it's one of our differentiators uh you do have to pay attention to them you do have to get them right it's one of these things that you need to think about well in advance of kind of implementing and starting your journey so for that audience in particular I I I think you're going to get the most out of this awesome thanks for joining that poll guys and then let's get started all right cool so let's kick this thing off so the first thing we're going to do is kind of cover what what is an entity hierarchy so you know a lot of you folks if you've already implemented you have exposure to it uh you you may you may have a notion of what it is and what it's for uh but basically it is it's a hierarchy of entity so it is it is a relational framework between nodes that you can configure for your irm program uh to serve a multitude of of purposes and that's what we're going to come with what we're going to cover here so the first thing you you know you're setting up a framework that's unique to the risk and compliance teams so typically your risk and compliance groups have a different view of the organization than a simple or chart or or you know geographical map uh lends it to so it tends to be of those things but not necessarily Limited to those things then let's see it provides an abstraction layer so to my original point about uh risk and compliance kind of a different view of the world what the entity hierarchy does for irm and foreigners risk and compliance teams is it provides an abstraction layer that allows them to point at existing data without necessarily constraining that data unnaturally so they kind of leave it in place it gets to be managed by its own life cycle but irm gets to use it and benefit from that work uh where where it's appropriate and it can be anything and you've probably heard this from my for my deployed folks you've probably heard that an entity can be anything so it can represent anything an asset a process a person a location a department kind of whatever your risk and compliance folks need to manage it can represent those things so it's similar in function to a cmdb so for those of you who are familiar with our itsm side you know it's kind of cmdb was our bread and butter for a long time that cmdb was a conceptual framework of either virtual or physical nodes and then the relationships between them and so it's so you know the The Entity hierarchy serves a similar purpose but it's much more broad than the cmdb you know the cmdb tends to serve as that framework for IT service management and for them to operate uh so it's it's it's it can refer to the cmdb um but it's not it's not limited to the cdb it tends to consider the the entire business now something else irm does with this entity hierarchy is it'll combine the entity hierarchy with other hierarchies inside of irm and this is where some of the magic starts to happen where once you add that entity hierarchy to something like your risk hierarchy so you might have a hierarchy of risks that have been defined by your risk folks and that you know you can do things like roll up and all that kind of stuff um but when you combine these two then you get kind of the benefit of both and the output is a highly orchestrated risk and compliance program okay managed at kind of a data layer and then those two data layers are combined to get to your risks and controls that you're going to need now why do we need these at all like so I I see the hierarchies like what's what's the whole point well this this is where the entity hierarchy fits inside of the irm structure so the the risks and controls are the base element that risk and compliance teams operate by okay they drive all kinds of things they're related to one another they drive risk assessments they drive control attestations they try indicators they drive test plans so risks and controls are that base unit of that we're managing to but we need to understand what they apply to so those risks and controls don't exist in in The Ether we need to understand what they're for and that's what entities do for us so let's take the example of Sox impacted processes as a scope so what we need to do is identify our socks impacted processes and then lay risks and controls on top of those so that we can manage first thing we do is we tell servicenow what a Sox impacted process looks like and then service now runs out and identifies every one of those processes for us by that definition once it identifies those processes what it can do is it can assign risks and it can assign controls to that process on our behalf so this is not something that's manually happening the system's doing it for us so because we told the system that this process is Sox impacted servicenow creates that payload of risks and controls that are appropriate now that mapping the way we do that magic it comes from our other two Frameworks remember I told you we combine hierarchies so one of those is the risk framework where you may have a Sox risk framework and underneath that all of your socks risks you attach the framework to that scope and that's what it's that's that's where all these risks come from that's where these risks get instantiated then we do the same thing on the policy side you're going to have policies internally your business that represent what you need to do to be compliant with socks from there you make that relationship to your scope and it creates the controls for you then what we do with these entities is we bring that into an audit engagement so when it comes time to audit my socks processes what I'm doing is I'm creating those process actually I'm not even creating I'm just moving those processes into an audit engagement to scope that engagement so I'm doing my socks audit let me get these processes involved in that audit and then continuing on I bring over the good work I've done all year so think about test plans think about indicators and then think about doing the rest of the field work based on the fact that I brought over my my processes and I brought over everything that I've been doing all year so this is the way that that we we scope our programs onto the business is by using these entities think about for a second the risk and effort of doing all that manually so if you think about what what servicenow just did for you even in the initial application of the risk and control payloads think about the automation right the next time that's another socks process comes online servicenow is going to recognize that stand up those risks and controls do all the notifications for you it's a vastly different starting point for your risk and compliance folks then doing something manually now entity should be created when these are your desired outcomes all right so kind of when do we use them and when do we not use them for the entity if you want it to be the subject of a control so I need to apply a control to this thing or I need to assess the risk of this thing excuse me or I need to audit this thing or I need to aggregate risk to this point so that one's a little that that one's a little less straightforward than the previous three so we have a function called risk roll up inside of servicenow and one of the ways you can roll up risks is in that entity hierarchy so you you could conceive of an entity that exists where maybe you didn't assess it for risk or maybe you didn't create a control for it but you need to aggregate risk there because it supports a decision right so there's some executive that needs to make a decision about what they're going to do next and aggregating risk at that level is Meaningful so how do we stand these up initially actually I skipped a couple steps here so um first question do we have to always use existing records for entity so remember I told you that an entity can refer to an existing record but it doesn't necessarily have to you can start with a standalone entity and we'll kind of get into how we do that later do I have to use the automated scoping so recall how I showed you that we can automatically create risks and controls and scope processes in the answer to this is no you do not have to you don't have to do that um you can you can instead create a manual one and then relate that manual uh relate that manual entity to your risk and controls manually and bypass that entire automation um and then what I want to do is talk to you about how do we stand up this entity hierarchy initially all right so we've talked about where the entity hierarchy sits we've talked about a little bit about what it does in terms of where it fits in the architecture and what we do with it so the first step in managing your entity hierarchy is going to be establishing an oversight committee so this is where I'm kind of speaking to if you've either implemented and you haven't done this or if you've implemented uh I mean if you haven't implemented this is an important First Step um what you need to do here is is establish who all is going to have a say in what entities we create okay now these are some I'm not going to read I'm not going to read the slide these are some usual uh suspects in that so that's the first thing is understand who's going to participate in the committee and that's going to be your your oversight group right then this oversight group is going to have a scope of of work it's going to have a scope of these are the things that it needs to do so this oversight committee is going to have to define the outcomes this oversight committee is going to have to define the process for managing these entities who gets to make changes who how do you relate to one another uh how do you relate them to one another what's the life cycle management is you know what happens when something needs to be removed and we'll talk about that in a minute um this group needs to determine the starting point so lots of organizations might have something that works for them already and they want to lift that in and shift it into service now um that might be a good starting point there's no way for servicenow to kind of tell you that because you know your own business but other organizations might say you know what we've been looking at it this way for too long maybe we need to change something up maybe we need to instead of you know instead of relying on our work chart maybe we need to line up to kind of uh what what the board report requires or some other some other requirement um you're going to have to approve the rule sets and data models so that's something we're going to get into like how do we set these up what are the control points um test the configurations approve changes so lots of organizations aren't doing a good job of this if we use the cmdb as an as an analogy uh where you've got that you know you basically got a hierarchy of records and then you use change to to modify those uh we should establish some kind of change process for for entities and we'll take a look at what that might look like and then we want to establish that execution group now the execution group is going to basically execute the wishes of the the oversight committee so these are going to be the people that manage filters create entities if you choose to consolidate that activity and my recommendation here is to keep that execution group relative to your risk and audit and compliance teams if you consolidate that function out into some Central core of of Administrators um a you're gonna You're Gonna Lose prioritization so you know risk and compliance is critical work but you know if you if you if you slide this work over to the admins you're in their queue and and they may have a different prioritization schema um and the other thing is not every sys admin or it person really understands risk and compliance it's kind of a language of its own nor do they understand the architecture of irm so servicenow irm is architected differently than a lot of the other requests for fill applications that you might be familiar with so you might have a person with 13 years of servicenow experience but they may not be best suited to manage your irm solution because they don't know risk they don't know compliance and they don't know irm we even see this with Partners where they've got a long history of implementing service now and they think they can just step into irm and it tends not to work that way okay can I just use I get this one a lot can I just use my my org chart as my entity hierarchy this is a very common mistake um do not let your your it Department be the one dictating this I see this happen all the time where the service analysis admin just determines that the department structure the organizational structure should be the entity structure they lay that out and it causes all manner of problems so just to give you an example of what a hierarchy looks like this is an example that I came up with uh for for for another customer um and so you can see how you can have first of all you can have several hierarchies okay you can have a you can have a regional roll up for location and then you're gonna have a business roll up for your organization um but you see how you can collapse so you can have many entities collapse into one that's the trick with these entity hierarchies is that oftentimes that consolidation happens that the risk and compliance part where they'll they'll see a group of locations and that's all one location to them so do we need to instantiate those in the entity hierarchy or can we just create a reference record and use that these decisions need to be made by your risk and compliance teams all right this is where you really need to collaborate with those stakeholders I told you about so that you get this right the um the risks to getting this wrong can can be can be can be drastic so um if we think about that some of the risks are improper configuration of risk and control so now I'm uh you know I'm a first line person excuse me I'm a first-line person and I get uh I get I get risks I should have never had or my aggregation fails so now because my relationships were off my my aggregation fails or my appetite fails remember guys automation is going to do what you tell it to every time so we kind of have to automate responsibly here and what I want to do now is kind of look at some of the um some of the features of of entities in in the application um as well as how to configure some of those sorry awesome all right gotta learn how to uh I gotta learn how to do power you want to fire off poll question two while I yeah sure all right so we've got another Pro guys um we want to know how is your entity hierarchy populated today so people just give us a quick answer oh can you does this show for everybody or should I show it here this polls thing um you're talking about the answers coming in correct I don't think they can see it until we end the poll I don't know okay yeah all right so awesome people are fast uh we've got some questions in um the chat some good questions I know we've got a lot of content um so we'll try to get to them uh all right so I think we're good it looks like we've got folks that are most of them are using the manual creation of entity image of relationships in a hybrid scenario it's not oh I got pull results with everyone and that that's that's pretty good I mean that's that's the responsible way of of doing it where you know you've got a high degree of control uh when you do that uh you're not over scoping you're not sending people risk assessments they didn't need or notifications they didn't need um so let's walk through how some of this looks in an instance okay so where do we you know where do we see some of these benefits from uh from The Entity structure and in the entity hierarchy itself um so what I have here is is an entity record right this is an empty entity record in the system um and kind of the first thing you notice is that it gives you an overview of this entire entity so that entity becomes a collection point for all kinds of activities you see I've got risks I've got controls I've got audits I've got tasks assigned to this entity I've got policy exceptions assigned to this entity I've got any number of things that I can you know that that this entity it valuable information that this entity can summarize for me I can see what it is related to so that any point I can understand what the upstream and downstream entities are doing to me from a risk and compliance standpoint um I've got I've got information on the entity but I also have information on the related records okay so your entity oftentimes can point to an existing record as I told you before so one of the ways in which folks get confused is they will they will create a uh they'll create an entity when they didn't need to okay so if we think of the applies to record here right so uh you know this is Acme Midwest it applies to a company record called Acme that has attribution of its own okay so it it has location information by itself so this is a case where you might actually not create an entity because you can get to the location information by using a DOT Locker by referring to that same thing with ownership so lots of times folks will create a department where maybe they didn't need to because you always have the department information of the owner and so is that attribute what you really need to to report on remember remember our rules am I going to assign a control am I going to assign a risk am I going to audit if that location or department is going to be subject department is going to be subject to those things create your entity if it's not then maybe maybe you bypass that that time um some other things that we're looking at are the relationships between Upstream well actually let's just see the the hierarchy um so the hierarchy is where we're going to be able to see the upstream and downstream relationships um what we can do is either show the directly related ones or we can show all so all would be the the parents the grandparents and everything or the or the children the grandchildren I'll be down or just the related ones this is where you can actually come in and this is probably how most of you are adding your relationships you're doing it here or here all right so um just some basic questions since you're here so can a child entity have child entities as well correct it can go all the way up and down so you're not restricted into the number of levels I will say that you know if you're getting past six seven levels you're probably going to get into a management conundrum uh but yeah there's no restriction all right and then how do we Define the grand entity can there only be one nope you can have two so if we come back to this diagram you're only going to have one top okay so picture this is your Global this is your Global all right when I say you can have more than one you can have a regional you can have a business or you can have multiple businesses like maybe there's one parent you know your alphabet and then you've got Google and and whatever else here um so you're not limited in the number that you can do kind of horizontally here I guess vertically in my chart um but it is a good idea to have like one at the top because usually that that one is what you're reporting on at the board level usually that's what the board wants to understand and then so how does the risk and these are basic questions let's do some some trending um uh people are asking about entity types um if you can just quickly show an ITT type and because it might be related to another question which is asking how do you automatically import entities and their relationships from the cmdb does it have to be to the workbench that's a great segue um so this is an entity type The Entity type is the definition of an entity so you remember in my Sox example where I was automating uh identify identification of the processes this would be the thing that's doing that so you define an entity type that type can have a class that type can have a tier those are just uh those are just Dimensions like it's it's conceptual data um where where we create entities automatically is with entity filters so entity filters are what Define your socks impacted processes or your your critical um your your critical um your critical services like we're doing here and so basically it's just a definition of what the thing is and you need to pay special attention to your entity filters because fewer narrow ones uh more than that like multiple well-defined entities are a little bit more precise than fewer broad entities you do fewer broad entities you run that risk of overscoping and hitting people with a bunch of work now that's how I'm establishing what to create an entity of so for critical Business Services these records passed these filters all right so now I've created my internet of course I could I could create an entity by myself like if I just wanted to add one I can always do it manually but then what we have to do is relate risk statements and control objectives to The Entity type now we can do this two ways this is this is what creates those risks and controls that I showed you earlier if I attach at the risk framework then everything in that risk framework is gonna is gonna create a risk for this entity type if I attach it the risk statement I can be a little more granular and say this entity type needs these individual risks instead of this entity type ease this entire framework and I can do the same thing for policies and objectives policies like you know everything under that policy is going to get created or I can be precise and relate control objectives here and so the definition of the entity type with its filter and relationship to statements and control objectives should be a critical management point for your change management process like of everything that you need to put under Change Control this this form I'm showing you and the filter statement and control objective that needs to be tightly tightly regulated all right then there's questions around risk workbench um can you also do this through the risk workbench or is that obsolete by risk workbench I think I think they're talking about the GRC workbench um honestly guys I don't use that a ton um that is that is a kind of a legacy conceptual Vestige in my mind um this you know that kind of defines how you would relate things um but it's a little it's a little hard to manage and I'd be afraid of losing information like I'd be afraid of having too many management points and I would rather understand the relationships in this screen you know looking at the hierarchy of the entities looking at the relationships to risk statements and control objectives because that's where the rubber meets the road yeah thanks yeah and the risk workbench isn't necessarily used to create and decrease anyways right it was more formal response the relationships between between the types not necessarily between yes yeah all right okay thanks thanks okay um so we've kind of talked about what entities do we talked about what they can give us you know kind of back to back to where I was over here um don't ignore the fact that you know you're aggregating risks to entities as well so and your entity hierarchy is critical to that risk aggregation you know you start messing with those relationships it'll throw off that aggregation and now you've misinformed someone of a critical decision if they were steering by their you know by their their lost expectancies in making business decisions you don't want to you know you don't want to do that to them right so you want to make sure that this is all under control and so back to kind of how do we control this what should we do um to to get a control mechanic mechanism in place um that's where I would offer something like foreign case so risk income it's like the the risk uh the irm released next month is gonna is gonna have compliance case management so this is kind of being this is going to be a new feature it's going to be a case management feature and it does present itself as an iron specific ticket if you will to capture this unit of work so you might report a case you might come up with different types of cases like you know let me let me create you know let me put in a request to create a new one or a modify one or or delete one are we going to talk about the lead specifically in a second here um and then you just you manage it out through a life cycle just like you do everything else that case can have tasks um you know you can have the individual tasks for that case you can have approval so think about what that might look like you know maybe it's got to go through that Advisory Board we stood up for an approval and then the task needs to be created for that execution group to actually go implement the changes maybe we want to try this in Dev before we start making mass changes in in prod you know onesie Tuesday stuff yeah great maybe we can do that also think about ACLS so you ought to have at least three groups you ought to have a stakeholder group like the oversight group a maintenance crew but the execution group and then the owners you know because you've got you've got entity owners out there who need to do certain things and so ACLS should be wrapped around those groups workflows should be wrapped around those groups um and it's also a good idea to let everybody know what their job is going to be right so you know if you're on the oversight you're going to be doing this if you're going to be if you're on the execution you're going to be doing this if you're an owner what are the expectations of me now that I'm an entity owner you know it's going to be things like you know responding to control attestations or delegating those it's going to be responding to risk assessments or delegating those it's going to be participating in audits it's going to be all this kind of stuff um so we kind of talked about who does what we kind of talked about how to get this under management um I've got a ton more content I'm going to start cherry picking just because we might run out of time I want to talk about deletes um because if we think about the maintenance of the entity hierarchy over time you're going to add you're going to modify you're going to delete you know ad you can create a manual one or you can use the automation I showed you um modify you know kind of the same thing you can you can either do something manually or you can use flow designer to kind of keep things in check someone asked a question about how do we reconcile relationships from the cmdb into the entity hierarchy um I I propose flow designer to do that I mean I actually propose flow designer to do a lot of your data management for you because you can just set up a for each Loop and then you know have it Loop through the related records and then you know create where they're not there or delete if it's not there come on wherever you want to do that um but if you take a look at so like this is about irm the irm is really the entity client here uh but if you look at our BCM product it takes advantage of those seem to be relationships automatically because of the nature um the nature of BCM um but then you get to delete okay so when you delete an entity you run the risk of orphaning its children right so as you approach deletes uh take caution if you get a you know so you set up that compliance case and you get a delete I think it's something that you want to take caution with um and I think it's something you want to plan for Now understand there is a uh there is a scheduled job for uh I think it's called profile cleanup um but there is there is an out of the box feature that's going to clean up your profiles and entity types when the reference record deletes so remember I had an applies to you know I had a company entity and it applied to a company record that company record gets deleted the system understands to go deactivate that entity it understands to retire risks and controls related to that entity so all that Downstream stuff um the thing it doesn't do so well and I'm actually talking to the developers about this right now um I haven't seen where it um it deletes the relationships so you've got that M to M table out there that's holding the relationships I haven't seen where this utility is going to delete that now I'm calling this this scheduled job out just because it's supposed to be an advanced class and so this is this is me telling you where it's at um but this scheduled job is insufficient to manage your entities because think about if an entity reaches a retired state but it doesn't get deleted you know what do you want to do then that that's a flow designer thing that's that's a business decision first of all I mean you got to talk to your risk people because the risk and compliance people may be hesitant to just outright me remove it because something to be aware of for your risk and compliance customers is that often they need to understand what this what the risk posture is today but also what the risk posture was six months ago six years ago whatever that is um servicenow is really good at telling you what the risk posture is telling you what the wrist posture was we're not we're not so good at that's where you have to start thinking through things like feel like table auditing or thinking through things like using performance Analytics we're thinking through things like actually data warehousing because just because you delete something today you know if that thing's gone today it doesn't mean it wasn't present last year and impacting last year's compliance status or risk status so all of this is to say when someone wants to take an entity out of service it's a very good idea to analyze the impacts of it understand what they're really trying to do like are they trying to wipe it out forever or is it just taking it out from here forward those are important the the decision uh decision points yeah and then just a point of clarification we're not suggesting necessarily to delete um The Entity more inactivate them right so people think great um you know maybe a particular data center or server is not active anymore but the recent controls that the NC may exist as an active the risk and controls that were created from that entity will still be available for audits The Entity yeah you're right I mean the entity record will be in a deactivated State yeah and then the related controls there's that but uh yeah but it it's it's still the case that and again that it that's a great feature I'm glad you said that it's still like that that doesn't meet the risk and compliance team's need of understanding of what was six months ago a year ago two years ago it'll just be yeah this thing ended um and then you know don't forget those relationships because as that entity gets deactivated and you know it is it's the active button um yeah as you can see activated it it it's still going to be there but it's that's not going to be enough to remove it from from your entire process especially where those relationships are concerned right right and then just so that folks know when that entity is inactivated the controls and risks that are related to become retired correct right so you're talking about how to manage that post right now the um the last thing that I want to kind of mention here um well actually I think we probably have a poll question at this point Didn't we yeah you want to throw up whole question three yeah all right so poll question three is what has been your biggest challenge with entities is it printing them in the first place relating them we do have a question on that managing changes to production retiring them or the data quality of the reference data what you're using to create the entities all right good stuff we've got a lot of good questions um in the chat and I don't know if we'll be able to get to all of them but we'll definitely try to get back to um or at least try to cover them in office hours in our truth yeah so while that poll is getting completed the the last point that that I like to make in this is you know if you've done this right think about what you've got you've got an entity hierarchy it may or may not be referencing other data and other tables and all this kind of stuff uh you might have dependencies on attributes of related records so your applies to record or your owner record you've created a data model right and I think it's a good idea you may recall that on my slide of who should be participating in the oversight committee those data owners I think they need to understand that you know you have a dependency on them um and I also think that you need to maybe think about the maintenance of that data model so how do you ensure completeness how do you ensure accuracy of the reference data and the irm data um and so some things that come up over time one of them's audit right you can you can you can audit here um some you know to to to kind of maintain values over time and be sure that things are changing the the way that they should um but some other things you could do are um okay good so it looks like most people are the biggest challenges are around creating them in the first place so planning and scoping and then data quality so does that surprise you no no that's why I was making the data quality point is is you know use use servicenow to help you there create scheduled reports for data you know for data owners that shows gaps um for you know for completeness you can put dashboards together uh you can do notifications for when fields are blank you know that there's lots of things you can do there for accuracy um you can schedule reports for for people to review so you know you put something in their inbox at the beginning of the quarter or the year or whatever to certify the data and don't ignore data certification so servicenow data certification on the platform what it'll do is it'll it'll show the data owner the data as it exists and give them the opportunity to either say yes this is correct or know I need to change it so think about you know think about entity relationships like maybe putting the relationships of entities in front of that owner um so that you know you have some kind of attestation as of six months ago that this but still this was still correct so don't ignore the the power of the platform when it comes to maintaining that data model and then as far as identifying entities to create in the first place that's a that that's that that's a typical issue um so some some common places to start looking for for entities is you know think about previous audits think about asset inventories think about process inventories um think about board reporting like huh you know there's a board report out there somewhere that's getting populated and it's probably got some you know some entities inside of it um think about those spreadsheets that are hanging out there you know you've got those you've got those risk owners those control owners they all have their little spreadsheet of what they're managing lots of times there's an answer in the institution but it just hasn't surfaced because it's nested down in these little stove pipes of information that you kind of have to you have to uncover like you have to go digging for him yeah and we were we had some slides of try to talk about that right through but then we're thinking we need to have a full session because we can't yeah talk about entities without the contracts of either risk or compliance and the things that you just mentioned so you know maybe that is really just something that we will have a separate session on but if you can throw in the chat you're in the Q a the particular questions or problems that you're having during your planning that will help us as well put some content together for you do you want to start rifling through the Q a maybe we can get through uh yeah we've got a couple things though yeah um um I I'd rather I'd rather get to the questions you ready all right yeah let's let's answer everybody's questions rather than me talk at them um all right see so they wanted to know actually so we you asked about the you answered the red entity but how do you define it specifically is there a place in the tour that you add the grand entity to define the energy yeah you talked about it before how you think about it um and how you can to show how they can be related on your um the zero chart thingy but in the actual entity record how do we relate them up oh how do we relate them at the end on the entity record okay so that's back here so remember I showed you the hierarchy this is an entity record that I'm on now you come to the hierarchy button you've got the Upstream entity so these the parents you got the downstream these are the children um I'm I'm just showing the directly related ones if I click show all Upstream that's going to show me the parents and the you know the grandparents and whatever um and the ad I mean doing adding them is just as simple you click that add button you find the entity that you want to parent The Entity that you're on the current one and check the box and add or if you need to define a child for this for Acme Midwest you do the same thing down here add it that way um and then your visuals over here so your your hierarchy kind of at least the downstream is going to be um it's going to be over here for you oh what's the next question folks want to know about the role of the entity so let's just say the parent entity does not have a risk of risk or control but it has two child entities that may have risk of controls will those compliance scores go up to the parent right so yeah so if you've got let me go back to my mural board here so let's say that the UK and I we're not we're not doing controls at the UK and I level we're not doing risks at the UK 9 level we're doing controls and risks in Ireland and UK and then we're doing like Enterprise stuff up at Regional this node will aggregate everything below it even though it doesn't have its own risk assessments and controls and that's what I was saying before where it's it's an important distinction where if you're trying to aggregate loss events all the way up this hierarchy to here let's say um if you the aggregation points are entities okay so in your roll up as you're rolling risks up all this way each aggregation point is an entity that you can have controls or not but that's where you put it now contrast that with like operational reporting like I don't need to create a node in my entity hierarchy to report on risks in Ireland or risks in UK I don't need a node here to report activity like maybe you know loss events in Ireland and lost events in UK the only thing I need to have a UK and I for is if I want to aggregate residual and inherent loss expectancies at this level because it's important for somebody making a decision super important like you can use at the attributes of Ireland and UK to get to a lot of that operational reporting but where you want to use risk rule up in its formal sense that's where you would need a UK and I and what that looks like is back here so Acme Midwest all my aggregated risks will show up here awesome all right so um there's a couple some really good questions I'm just kind of picking and choosing one that we can get through yeah there's just a quick what is the difference between an entity type and an entity class okay so an entity type is this guy here an entity type is going to have entity filters that Define what this entity is the entity type is going to have the relationships to risk statements so I can create risks and control objectives so I can create controls The Entity class is just conceptual information about The Entity it's it's it's essentially attack and you can set up rules for it and all that kind of business but when you think of entity classes and you think of entity tiers those are essentially tags that you can further differentiate entities from one another with if you start thinking around talking about compliance today but on the compliance side you can do Roll-Ups of compliance um and on the wrist side you can do Roll-Ups of risks um but they don't roll up and you can do Roll-Ups of entities that those are my hierarchies um but you're not really going to roll up to classes in a meaningful way not in the system out of the box today yeah so like I might have a compliance score for a you know a control objective let's say um or an entity or whatever and I might be able to roll that up but the class it's really think of class is as more of a tag and then and then as a like a meaningful member of The Entity hierarchy it's a reference inside of the entity hierarchy but it doesn't impact things the way it's not functional the way this is functional I got a filter I got relationships yeah yeah that's a good point um all right so we've got one more poll do you want to launch that one um or Google I'd rather do questions let's let's all right I mean if we got questions let's do that um we have if we're not using the GRC workbench jams asking this where can I go to see the full hierarchy the full hierarchy of entities [Music] um well that's the workbench so if you need to see in hierarchy of entity types and then and and and and risks and all that kind of stuff that's over in the the GRC workbench um I I just haven't seen where that workbench is entirely useful to for instance like one of the questions is if we don't if we don't use the GRC workbench how how else can we see it um that's a good question yeah I know yeah I mean so at the entities you know we can view we can view the entities here at the hierarchy um if you want I guess the question I'd ask is why do you want to see The Entity the relationships between the entity types because remember now we're talking about the relationships between the types we're not talking about the relationships between the entities yes um well I don't have a good answer for that one yeah I think there isn't really a good place right yeah it's not a great place it's hard so a lot of folks what they do is they'll use their Physio and plan it out before they put it into the instance yeah all right so we've got three minutes left let's go through a couple I wish we had more time but we do have office hours and again if you have specific questions we can go over again in a follow-up session please put those in the chat or in the Q a um so let's start to wrap it up Drew about three minutes left if you want to go through that because oh yeah what are your key takeaways for today so key takeaways number one The Entity hierarchy is fundamental to deriving full value um I I have seen companies try to not use it and it's it's just you you ignore a lot of the Automation and a lot of the roll up and everything that the entity hierarchy provide so test your assumptions and collaborate widely because it's important to get the Val I mean you made the investment you might as well get the value out of the investment you made um work to your risk and compliance outcomes and then apply the capabilities of servicenow to it don't start at the capabilities and then work your way back that's where and I see it happen all the time the service now sys admin will go oh well I have this entity hierarchy thing I can put together I have this capability let me lay this out in terms of the org chart or some other notion that I have and it doesn't really meet the outcomes again you know rely on your oversight committee but you know start your outcomes and then work to that and then that governance Factor so you know do you have to have the full you know the the full Love Circle of everybody involves like in Kumbaya maybe not everybody's going to have different variations but at least have some kind of discussion around how you're gonna how you're gonna manage these things and then try to at least maintain visibility even just for Bare audit requirements like if you go make this change to the entity hierarchy and it substantially impacts your compliance with something you're going to want to know who made that change um you know auditing Services there um as a way to track it but you know you really want to know that somebody wanted to make the change and why they wanted to make it so put that in the process and put up the committee how we want to put governments around the cndb you're basically uh yeah copy of the cndb it's a good it's a good it's a good analogy so like if you think of you know if you think of the entity hierarchy as peer to the cmdb hierarchy and the way it seemed to be used as change I'm not saying you have to use change I'm also not saying go put your entities inside of your cmdb so that you can use change against them that's not a good idea because entities don't apply to I.T the way they apply to risk I've seen people try to do that you know use case management use the catalog item if you have to um but but but manage it manage it somehow and you've probably got some experience in data management like that through the cmdb awesome all right the last couple of slides again um office hours um next week registration was in the Q a um and then when that next one is the last last slide which is um just a couple resources for you to follow up on we've got the service now YouTube list uh the GRC YouTube list is um being revamped so but the content that we're keeping on there is still relevant um we are working on updating it just takes all update all those videos um but you can see all the GRC Community webinars by using that QR code there um and again this stuff will be sent out um so you'll have it and see you guys in office hours next week thanks guys I'll bring you questions next week awesome

View original source

https://www.youtube.com/watch?v=ItB7LkVqstw