Santa's Secrets: Automating Entity Management with ServiceNow
so good morning everybody we're going to get started my name is an Marie Fernandez and I am a senior technical product marketing manager here at service now supporting the risk business hi I'm Drew Whittington I'm the global risk architect for solution Consulting in the risk business unit all right so just a couple housekeeping items um as you're joining I'll be monitoring the Q&A um try to put the questions in the Q&A not the chat that way we can if we don't get a chance to answer all of them um we can still grab them after the um session and we can um respond we can save the questions and respond to them um on the community um so this session is recorded um and will be shared on the community uh all the uh present this presentation and a couple goodies for you are going to be on a community article that I'll throw in the Q&A in just a second and then at the end of the event we'll have a little survey that uh would be really awesome if you could fill that out for us um it's a great way to understand the content and uh what you liked and any areas that we can improve uh all right oops wrong one all right so our quick agenda is um we're going to talk a little bit about entities just to level set everyone on entity management um and then uh answer the question if there's a basis to qualify uh what should be modeled as entities Drew um we'll talk about that and uh Drew's got some tricks up his sleeve that he's gonna talk to you about automating and um managing some of the challenges that most folks have with entity management and then we'll wrap it up with a couple takeaways for you all so we've got a quick Poll for you all today um which is and let me get that started uh what has been your biggest challenge with entities and let me launch that now so folks that are joining if you could quickly fill that in so we can get an idea of where you're all sitting at awesome okay looks like we've got a good amount of the folks answering and Drew can you see the the poll how how it's looking yeah yeah yeah I'm looking at it and I'm intrigued that there's a zero on retiring entities that that kind of tells me where where we are in the kind of in the life cycle of um you know customers using entities from end to end it doesn't sound like we've made it to the second end in a lot of cases yeah well perfect because uh looks like most people are find biggest challenges are around identifying entities to create in the first place and relating entities to one another so uh that that's good news um because that's what we're going to be talking about today that's pretty common team that that that that those answers are pretty consistent with what we what we see elsewhere yep yep absolutely so we'll just start with a level set quick qu quick question is what is an entity um you know even though folks understand it it's really you know trying to simplify it um so that folks can um better address and um Implement entity management so we've got tons of risks in our organizations risk data privacy Cloud availability or workplace safety and then folks have tons of policies and controls or using U monitoring tools to mitigate these risks or maybe they are implementing these policies and controls in response to regulation so an entity is really just where do these apply specifically right um and so um there's a lot of terminology around entities that's pretty new even for you know really seasoned risk and compliance and audit professionals um this slide is more of a take-home for you guys um I just wanted to highlight that we'll be talking about entities specifically um entity types is how we generate entities and then entity classes on the back end which is used um once entities are created how do we group them for reporting um and then these definitions will um have it laid out for you in the presentation you can take home um so at the start this is just a you know a higher uh maturity model um and so at the start many folks will take a very tactical approach and then the end goal eventually is operational resilience so Drew while this is a good way of looking at maturity and how folks can Implement um entity management um how do you see many people end up approaching entity management like what does it end up looking like for many folks yeah so the major I mean we have to crawl first right guys so the the majority of customers that I've worked with are starting at a point where they understand the data quality of the underlying of the like the applies to records so for some companies they have a really tight process inventories other companies might have a really tight uh application inventory you know there's usually some level in the hierarchy at which the the the the customer feels comfortable with the data set and so that's the most common starting point is you know depending on what you know which which you know if you're going digital or if you're going business usually there's a process inventory or usually there's an application inventory uh and that becomes the basis that customers will start with and then they're build out from there so you get your starting point you roll out some risks you roll out some controls you figure out life cycles and how you're going to use the solution and then from there you can start to build either parents or children based on you know some stuff we're going to cover later I'll save that for those later slides but yeah just start with you know start with the data that that you know uh a lot you know we had a lot of answers that said we you know we're struggling with what to make entities out of in the first place um they are somewhere in your organization I promise you somebody's got a spreadsheet somewhere or there's a previous system of record or there's a service management tool out there that folks are using they they're they're there like your risk and compliance people know what they're protecting with their risk and compliance programs and that's usually your best place to start when you're trying to populate the entity hierarchy I agree and uh and usually this this first part is the hardest because there's so much uh so much data right there's certain level of processes and services that you may know but it's all this stuff down below and so that takes us to the next slide which is you know if we think of operational resilience as the end goal a lot of folks will use say for example um this might look familiar to some folks um use a csdm to inform where they may be coming from so um all the it infrastructure um just getting that set of data uh using that tactical approach is where we'll be focusing on today um but eventually as you mature and um the next level is to understand how those support your processes and eventually your critical products but it's not not just it data it's customer data employee data um location data and supplier data so um these all together will end up creating um a resilience program for you and really being on one platform um is you know we kind of think of this uh as you know a scalable risk program because all the data is in the one platform so that eventually um you can anticipate prevent recover um and really understand how you can um protect your critical Services um all right can you go back to that that one so what the the the comment I have here is that you know when you're planning these things out of course we're all going to start at some tactical starting point that we know you know we've got that know good starting point what I like to ask customers to Think Through when they go down this journey is start to think of the question that you're going to be trying to answer in the future and then map to answering those questions now those questions are likely going to come from risk staff compliance staff executive staff audit staff like those are the people that you should be Consulting when you're setting this up because the thing you don't want to do and I've seen it happen you don't want to start with a you know technologist uh kind of basic logic oh this seems logical to me and then you implement something using just kind of common knowledge or sense and you put it in the way you think it needs to be because you did some word association and maybe confused some definitions um so don't you know as you're putting this in be working with the appropriate staff understand the questions that they're interested in and then build build to that so try to get to a point where you know you're coming top down like like Amar is showing you here as opposed to working bottom up from things like your cmdb or your foundational data absolutely good advice Drew um so service now risk is almost another language right so I feel like Risk and entities really go together you can't just talk about risk but not say where they apply and you can't talk about the objects that are at risk without specifically um you know calling out the types of risk and so this kind of overlays the csdm with levels of risk so approaching things tactically I you know um as it risk management or at the operational risk level or at the Enterprise strategic level so uh just different ways to um align your data with where you want to go and ultimately you'll have an endtoend view um and so entities are really the heart of the irm data model when you uh look at even architectural level entities are the center and no other GRC solution provides the Insight or provides this level of granularity all right but with great functionality comes great responsibility and this is uh getting to the fond stuff now um so Drew talk about more about the use cases of when entities should be created right so there you know these are the four times when you should be thinking about creating an entity um the the my tagline here is you know don't feel like you have to shoehorn every data element into the entity because somebody mentioned it that they want to report on it when you make an entity it needs to either be the subject of a control the subject of a risk or the subject of an audit if it doesn't meet any three of those criteria you really want to second guess making an entity out of this thing location is a very good example of what I'm talking about where someone will say well I need to be able to report on Risk by locations and so they'll automatically try to shoehorn a location entity into the hierarchy to serve that purpose and that's the one where you may or may not need to make that entity because that brings us to the fourth step where I need to aggregate at a certain point so irm offers risk rollup which is where you're aggregating in a meaningful way the loss expectancies for all the underlying risks and you can a you can aggregate those all the way up your hierarchy so you can have a base risk and then have child parent grandparent great-grandparent on up and aggregate the risk the whole way now if you need to report on Risk by location to say how much activity is in a particular Geo you don't really need that to be an entity node because you can use the reference data the ENT the thing you're protecting has a location so if it's a person or if it's an asset it probably has a location somewhere so don't forget you can dot walk into that attribution to be able to satisfy a lot of the reporting now contrast that with I want to be able to aggregate my Risk by Goo so let's say I want a you know I want a total aggregation of my risk scores by county and then by country and then by geographical area well in that case because you're trying to roll up to that level you'll want to make an entity out of that location so it's really two different use cases if you just need to report on risk in areas and what's happening and what risks are out there and and and that's all not walking to a location if you need to aggregate to that location then you need to think about making that entity node in your hierarchy yep good advice all right so let's talk about the two common challenges we find when folks are getting started with entity management right so the the first one is the question of volume um because we use entities the way we do so we're saying that if you have a control you have a risk you have an audit we want you to have an entity um that drives a lot of volume into the system so you end up with a bunch of records that a the risk teams may not have been used to handling so this you know this this idea of an entity hierarchy that's something service now does um that not a lot of others do and so your risk business partners may not be used to that Concept in managing those records um but there's a lot of automation that we provide to help so you end up you have to uh you have to balance things so you have to automate responsibly because you run the risk of creating too many entities and we'll get into a bunch of you know examples and and kind of how to get around it um the second thing I see a lot of is just the the general maintenance of the entity hierarchy so you've got the nodes and you've got the relationships um and and managing the life cycle of those records so again we're presenting this new you know this new data type to an audience of of of risk and compliance professionals who may not be used to managing records over a life cycle like that um so you know verifying ownership verifying relationships certifying data that whole thing um that there there's a lot on the platform that can help um but it doesn't necessarily come set up out of the box so we need to think through you know entity hierarchy we get it set up on day one great how are we going to keep that data quality up over time that's where the maintenance of the entity hierarchy comes in awesome all right so we've got two more slides and um I don't know if you want to go through this and then jump into the demo Drew or yeah let's do that we'll we'll go through and kind of tell them what I'm gonna show so the first thing we're goingon to talk about is the right level of control placement so making sure that you're creating entities where you need to and assigning controls and kind of how to automate some of this creation um using pointers so that's where the CMD groups and the people groups come in so is there a way that you can point to a group that has a population and then certify that population uh common controls which is a newer feature for service now where entities can share a control and then we have continuous authorization and monitoring out there which is another one of these grouping mechanisms where we Define a group and then we certify to that group um that's really targeted toward RMF in in the FED space but that doesn't mean we can't use it in in private sector if the use case mat matches what you're trying to accomplish awesome all right and then for maintenance um so for maintenance this is the this is the forward management of the data set because you're essentially creating a data model and you you want to maintain that data model over time um so using flow designer to do some reconciliation have an example of that using data certification have an example of that we'll go through decommissioning um and then we'll talk about how to use case management so compliance case management which is one of our newer features as a request mechanism to handle this when you when you can't automate gotcha all right so we're ready to jump into the demo yep let's do it okay Team all right we should be looking at let me know if you can't see this instance Amry let's see not yet I don't see it my screen is a little I don't know why I can't see it folks can you guys see uh Drew's screen throw in the chat can y'all see um okay everybody's good all right they can see it cool all right so this is the um this is the compliance management workspace which are probably all of super familiar with by this point um not going to spend a lot of time here what I'm going to do is kind of Step you through everything that I described in the first couple of slides so let's talk about entity filters and let's talk about putting entities uh controls at the right level so to help you create entities in the first place which was you know one of the predominant answers to our poll uh we provide an entity filter so this filter is basically a definition of what a particular entity type looks like so if we're looking at business applications we might build a filter condition from the business application table to say where it's active now this is an oversimplified one because you can start to build out new criteria to say where it's active and it's internet facing or where it's active and it's socks impacted so you could start to build those filter conditions out to where you know the system is creating entities correctly because you've got a narrow definition of the entity that you're actually trying to create so the more specific you can get with this the more accurate it can be um and also understand that you can be a member of more than one particular entity type now as far as getting controls at the right level what I see a lot of here is you've got customers so let's take a technology example let's take uh virtual machines so those virtual servers that are spinning up and and down all day long and they might be here one second and gone the next one of the things that you can do is instead of trying to create those VMS as particular entities unless you need to this is where I go back to consult with your compliance and risk staff but rather than trying to create an entity for every one of those particular CIS could we instead use an indicator and monitor all of those for compliance at the population level so imagine you've got a control against all of your you know your virtual servers and then there's an indicator on that control where you define a definition to tell it what is a s you know what does a virtual server look like or or whatever we're solving for here um and then let the system monitor that population of records that are popping in and out of existence to where what you're essentially doing is you're taking a snapshot of the records at the time you can even Define the population so how many records you're you're you're assessing and you can look for I call indicators they look for bad basically you define what the bad condition is in those in those in those uh virtual machines and service now will sit there and monitor the entire population for you and it'll call out when it sees a problem so that's an example of including every record in your program by way of using an indicator without creating an entity for every single one of those virtual machines so it's a little bit of a balancing act when you do that so you know for volume think about it you know we created one control for all of our virtual machines that means there's one control owner that means there's one attestation now we're still monitoring the entire population but we're only creating enough of the artifacts that we need to manage it so that we can we can comply contrast that with if we created a control or if we created an entity for every one of those virtual machines that's a control for every one of those virtual machines that's an attestation for that control so you can see how you can drive a lot of kind of erroneous activity out into the field if you get these initial configurations wrong same thing on the wrist side where you know if you've got you know if you've over created entities let's say you could be driving out a lot of risk assessments that didn't need to happen or maybe hadn't happened before um and and you know you can confuse the field that way so now the business is getting all these risk assessments they've never had before so that's the thing you know create your controls and risks at the right level ens sure you need the entity and then use indicators for inclusion purposes I like that now the next thing I wanted to talk about to help reduce uh volume of you know controls attestations testing all that is um using a group as the entity so in this case I have c a cmdb group group up here so this is an this is a tech example where instead of using the application as the CI in this case do we want to use a group of applications I'm sorry instead of using the application as the entity do we instead want Define a group of applications and use that as the entity so use that group as the thing that we're attesting to as the thing that we're issuing control tests against as the thing that we're either compliant or non-compliant or we lowrisk or highrisk and so cmdb offers that functionality out of the box this is an example of a cdb group um what you do with these is you can either Define it by using the the query mechanisms so you can Define quer there's queries out here so you've got an actual query builder for the cmdb you can set up any number of queries here and then what you can do is include those in the definition of this group and so this will actually be dynamic you know as things spin up and and spin down the population of this will change um this one way to include records another way is to just do a saved query from here so you can build out a query here and another way is to edit it manually sometimes those filters don't catch everything so typical with service now we're going to want you to automate to to the extent that you can responsibly uh but where you can't automate we want to give you that that manual back stop to where you've got a way out of a pickle um if you need it so this would be one way of defining a group and you can think of a million other ways think of a department you know think of instead of certifying individuals maybe you're going to certify a department maybe maybe the control resides at the department level so you don't have to put it on individual people um and on and on you know look ations GEOS kind of whatever makes sense and and the the thing to remember here is we're doing this for a reason and so work with your risk and compliance staff to be sure that the group you set up is going to answer the question that they're asking for later true so you've got this CNB group called applications but they don't have to be all necessarily applications right you can get a mix it's and so what you're saying is look at the ownership level um you can mix you know hybrid classes of entities y here yeah and there's a couple of other examples of that um later on too so that's another way to control volume because we are defining a group and we are certifying the group and we're allowing that certification to certify the population inside of the group another way that we can kind of group things together and get away with fewer controls is to use a common control so this is on the doc site this isn't anything internal that I'm I have just for me um the way common controls work is that you have a primary entity and then you have a control you can turn that control to a common control and then you can allow Reliant entities so these guys down here to inherit that actual control and when they do that they inherit they inherit the the status of that control so if it's compliant they're compliant if it's compliant they are not I'm sorry if it's not compliant they are not compliant um so that's the you know in principle that's what the common control will do for us and to see what that looks like in the system this is a this is a control record and when you want to make a a control so this if this one's already common you see I've got my function here of common controls I'm not going to do it but this is you know this is it'll say convert to common in the UI action and what that does is it gives you these Reliant entity and Reliant entity type related lists and so what you can start to do if you want to do it kind of the manual way and and pull entities in one at a time you can do it from here and you're just filtering entities and pulling them in you can pull it in from an existing control so you can pick a control and pull the entities in that way um this is the manual way so you know being that this common controls are precise beasts so I would imagine there's a lot of of manual preference here for your risk and business partners however if you wanted to automate it we could use entity types so we could say that a particular type of entity gets this common control and then those entities in that type would inherit this control so a lot of power in this there's a lot of power where if you set entity type up right and you know you can rely on it for this Reliant entity on a common control we've provided you the opportunity to do it I go back to being responsible and automating responsibly because you want to be sure it's answering the question that your your your compliance staff have uh just quick question on terminology just um because this is new functional newer functionality standard control versus common control so so standard control does not have the feature of inheritance common control does right so and I think by default all the controls are standard right until you convert it to Common that's right awesome okay um continuous authorization and monitoring this is another way of of doing this grouping that we're talking about so if you know how fed and RMF work works at all you have an authorization boundary and that boundary is essentially your group all right so you get to Define either by filters the way we do here same kind of filter mechanism that I've showed you before it pulls in the system element so this defines all of the S the the the elements of the system inside of the boundary so this is your group and this can be any number of CIS it doesn't have to just be CI you know computers um and then what you you do here is you authorize you have authorization packages these packages are your entities so rather than have entities for all of those I'm sorry for all of those CIS that we showed you you've got a boundary defined you've got a package and the package is what you start to pass through and this is this is what the package looks like um this is what you start to to uh assess for compliance right and so you see controls are assigned at at the package level my impact assessments are assigned at the package level and that package references the boundary that I showed you which defines the population of uh of of almost said entities of of CIS that were act actually uh certifying okay so that was the um that's the volume question um I'm not really watching the Q&A if you want to call those out to me okay um so from here I'm gonna go into the the automation piece so the maintenance piece um this this first window if if you think about if you have any service now experience at all you know what a cmdb is and you know the cmdb is a CI table and a relationship table like that's the that's the Crux of your cmdb that's that's the foundational data structure you've got your nodes and you've got your relationship between those nodes entity hierarchy is set up the same way you've got your entities which these are your nodes and this is the relationship between those nodes so it's the same deal you got a parent and a child actually well we call them upstream and downstream over here um but it's the same deal where you've got you know you've got a record and then you it's got parents and it's got children and that's defined in that second table so if you're familiar with managing the cmdb on service now you kind of already know how to apply that logic to this data set on The Entity hierarchy side um and and a lot of the rules still apply now this will be new to your risk and compliance Partners um you know this is something service now this differentiates difference differentiates us um it aligns to you know SEC guidance where they start talking about entity based controls and all that um but what we didn't necessarily do a great job of is informing the risk and compliance business people so those those risk and compliance staff of how to manage this through a life cycle now luckily we're serviced now so a lot of that exists on the CI side and what I've done is I've gone through and I've worked up some examples that I want to show you on how to use platform features to maintain the quality of the data model you've created over time um with you know as little effort as possible so the first thing that comes to mind obviously is flow designer now what I've built out here is an example of using flow designer basically to synchronize relationships between an application and its and its children um this one you know that's all this one does you you can you know there's some smart folks on the on the call here I mean you could see a lot of application here you could even build this out more broadly to reconcile all relationships um but just to have something to discuss today you know this what this is doing is it's basically if if a relationship and the entity hierarchy gets updated it's going to go look at the cmdb for that record it's going to find it it's going to start to assess the relationships that's what my for each Loop is doing here if y'all been on a platform a while you don't have to do those uh those while Loops anymore in business rules this works really well um and then basically what you're doing is you're going to grab those records you're going to look for each one and make sure it's an entity and then you're going to look to make sure there's a relationship and if there isn't a relationship then you'll go ahead and create it now this is just one way of using flow designer to keep this data up to date something else that occurs to me is for instance ownership entity ownership control ownership any one of those things if an employee goes away we get ask this all the time like if an employee goes away what happens to those entities what happens to those risk and controls and my answer is always flow designer you know the answer is what do you want to happen at that point because what you can do with flow designer is if that if that record go you know if that employee record so if that user record goes to retire or some State we don't want it in what we can do with flow designer is crawl through all of the controls all of the entities all of the risks or whatever else and assign those to maybe that person's manager until until the new employee can come in or if we know who that replacement is we can assign it to them or if we have a delegate set up maybe we assign it to the delegate but flow designer is the thing that's going to help you make all those kind of automated data changes behind the scenes in a no code way that's going to have lots of visibility and that your business partners will be able to understand one of the things I like about this is that if I'm trying to explain to somebody what I'm doing with this flow this is human readable whereas if I was using a business rule like we used to have to do in the wild Loops that that doesn't translate as well to to non-technical folks so don't forget about flow designer it's available on the platform and it it can do a lot of this cleanup for you um if it's not happening kind of already now the other thing I mentioned that we have a data model and that we need to ensure the quality of this data model because think about this like this is our risk and compliance data if the underlying data and when I say underlying data remember that entities refer they can be Standalone let me correct that so you can can have entities that are Standalone but by and large they're designed to refer to something else on the platform so let's let's take that location example let's say we make entities out of locations we're going to look at the foundational location table create an entity for that and our entity is going to point to it or our entity is going to point to an asset or it's going to point to a process or whatever um because we're pointing to something we need we've now Loop that into our model and because our model is supporting compliance and risk it becomes really critical that we have you know we have certainty in the underlying data and so there's a feature called Data certification on the platform where it just it does just that where you can put certification tasks in front of of of owners and ask them to say hey is this still right you know do you still own these entities or does this application still refer to these servers or whatever that question is now again ideally you're doing this through some kind of API through some kind of automation that's that's the ideal State this is a little more manual we're automating the task creation and we're giving the user kind of a UI to get through it uh but it's still it's still I consider this the back stop the manual back stop but anyway um what you do here is you define a rule set the rule set looks like this this is where you create the certification schedule you tell it you know who do we assign the task to and what do we want to do um and then we Define an instance and that starts to define the definition of what information is presented but what this starts to do is it'll fire off those tasks to say hey Drew are these all still your entities or hey Drew is your entity still related to all of these other entities um and you know typical service now we're going to give you insight into the process and who's doing it and what the age is and all that business um but data certification is just one of these platform P pieces that not everybody remembers or thinks about so if you're in a situation where you can't automatically verified data or there's some you know there's some scope of data that you don't want to automatically do it but you need eyes on it you know every six months annually whatever remember data certifications out here to help you certify that and then you've got that audit log to say yeah Drew certified you know as of December that these are still his entities and that these relationships are still correct that's an option out there for you now the last thing I want to cover as far as automation is cleanup deletion so you know we've talked about creation we've talked about updating and managing and making sure things are are correct um on the other side so remember this was this was the goose egg on the on the um on the survey nobody had trouble retiring entities um so you know a lot not a lot of people have gotten here yet but there's some cleanup routines um that we provide where if your entity applies to so in that example where I create an entity against a process let's say if that process retires service now will retire The Entity as well um there's a cleanup job so if you go to scheduled jobs there's a cleanup job in here and you know it'll it'll point to some functions and everything you can go through that you can set the time when you want it to happen and all this kind of stuff um the the thing I want to point out here though is that the automation that we provide is not going to automatically delete the relationship records and so whereas we're we're retiring entities we're not necessarily retiring the relationships to those entities um that's you know it's in the backlog it's something we're aware of uh but it's something that I want you guys aware of because you know that creates orphan records so flow designer presents itself as a good solution to this that maybe when your entity gets retired you go ahead and Mark those relationships as retired uh but something to be aware of that if you get to the point where you're end of life for entities give that a little bit of extra thought um because we're not we're not doing the whole job for you necessarily out of the box right now um couple of road map items so for instance when I showed you this flow where we're reconciling against CIS that's actually on our road map for upcoming release where we're going to have that feature kind of out of the box um something we didn't really talk about was uh making sure that your control owners and risk owners and Auditors all have the right access inside of the system uh there's some things on the road map that'll start to help address that where like if you're the owner of the entity you would get you would get access to the records related to that entity so all these things you know we're aware of it's it's on the road map we're going to get to it I just want to be as transparent as possible for you because managing this is um is something that you know you need to you really need to think through because if you know service now you know how important the cmdb is and the entity hierarchy is basically that for risk and controls now the last piece so the manual back stop this is this is where I end um we have a new you know a newer feature came out called uh compliance case management and what this is meant to represent is kind of that thing the thing that GRC didn't or that irm didn't have until now was that request record that incident record that that thing where I have a problem and I want you to help me with it can you know where do I go for that we didn't really have a good way to capture that a lot of customers were using issue or using even like catalog item requests for that well now we have it in the in the system and so my my offer to you is that where you have to interact with the business or with owners entity owners over The Entity hierarchy you know and you can't automate it well then go ahead and set up a request mechanism to do that because the thing you don't want to happen is for that entity owner or that entity consumer to reach a dead end and then walk away from poorly configured data because remember how important it is like if if you're if you're satisfying some kind of audit um you want that data to be correct so I encourage you even if you're not using compliance case to do it you know set up that public not publicly but set up that enterprise-wide request item for the you know the field to interact with whoever's maintaining that entity hierarchy when they when they need help and when they need to make changes so that's just a great stop Gap to fill in where automation can't you know necessarily always yeah automation you know it can't do for us it can do a lot um but the you know it's it's going to do what you tell it to do every time and so I I like to have these these back stops available so that my my my people don't feel abandoned and I I can maintain you know data quality awesome um so we did have a question um TMO um sorry we didn't get to it earlier I believe this was was this around indicators or common control um his question was with that solution which I think is common control but I'm not sure any indicator that fails will make the control non-compliant correct correct correct yeah um all right so that was it um if you have any other questions please type them in the Q&A otherwise I think we're doing good on time um we got a raised hand oh oh there it is I can't see it can you want to ask your question in the there you go I've unmuted you emmer if you wanted to talk you can um unmute yourself and then ask the question live oh maybe it was a just a hand up so [Music] Amer okay I'll keep going if if we you want to put the question in the chat we'll get to it that way um so key takeaways um you know the entities are important um like I said you can have Standalone entities if if if you're you know if you don't have that reference data but even if you do that it's still critical to get those entities right and I would point you to the first webinar we did on this topic around you know standing up that that governing Council giving you know some thought into how you're rolling it out um you know if you if you get entities wrong you could get a bad result when you're trying to prove compliance or or risk level um try to establish that service Centric road mapap so where we showed you the maturity curve and admittedly everybody's got to start with you know that known good that tactical you got to start there but think ahead understand the questions that senior staff are going to ask so that you can build into that road map where you've got the right entities assigned and created and maintained to prove those result resilience activities that you're inevitably going to have to do at some point and then automate responsively you know we said that a few times it's going to do what you tell it to do every time um and you you want to be sure um of those outcomes uh so certainly I I take an automation first approach but it's not necessarily automation always okay great so there was a question um when do you recommend the use of entity class rule filters okay so if you're going to go with entity classes um your entity classes are ways to group entities I think we covered that in the the first the first one of these um so if you are using entity classes uh we do offer filters the same way we offered filters for CB inclusion the same way we offered filters for entity type inclusion there are class filters that will go ahead and assign those classes using those filters for you um if you've got your your classes defined we didn't really go over that here but if you have them defined certainly use those filters because it's better to automate that part that's actually a bit a bit safer um than entity creation automation because those classifications will be easier to change later um and you don't have controls on CL classifications so that that classification think of it as metadata think of it as context data for the entities um and if you if you've got that defined great good on you go ahead and use those filters to keep those updated gotcha so you can use the filters if it's not right where you want it you can redo them it's not going to generate more controls right or anything like that right so good question um so there's two more um how can you use business app tied to application service and you're using Dev test prod instances to create a single entity okay business app tied to application service and use Dev Test Pro say to create a single entity if we are trying to create an entity for the the overall system so you got a business app and an application service um you you might want to start at the application service and then work your way down from there into the you know the underlying bits like the business application and all that um as far as Dev test prod if you're talking about including those environments so your Dev environment your test environment your prod environment as part you know as related to that that that that application service well then you could create relationships between those CIS so you know the underlying environments to the application service and then materialize those on the entity side and then what you would be able to do is roll up compliance and risk to the business service I'm sorry to the application service and it would be inclusive of everything underneath it I think that's the nature of the question if you're asking around how to you're not you're not asking about how to promote Dev test prod I'm I'm gonna go with my first answer right right we're we're assuming that the control ownership is at the highest level not necessarily at the entities yeah um Dev test prod but those could be tested differently as well um all right so hope that answered your question um the next one is do you need to set up parent child classes or just use Upstream Downstream entity relationships you um okay you must have Upstream Downstream entity relationships entity relationships to inherit risk and compliance scores up and down the hierarchy the the parent child entity classes remember those classes are my metadata that's context data so you those are optional like the system will work just fine without an entity class if you're using entity classes to provide that context then you might very well want to establish those parent child relationships especially if you're getting into like the GRC workbench and all that then yeah go ahead and set those up but everything will work without that you do need the entity the relationship between entities are key to making all of the inheritance work right so the actual generation of the compliance score and ratings is through the relationships yeah the classes won't affect any of that scoring it's just going to report out uh the result yeah the classes will report out results the classes like if you're using GRC workbench the classes will restrict which children you can assign to which parents it does that that feature like that restriction doesn't necessarily work out in the application it's just a function of of workbench uh which is why I say the the class relationships are way less important than the entity relationships inre in creating the complient scoring okay last question is does the risk assessment methodology rely on classes no yeah no all right um thanks for your question you can include it like if you want it to consider class I think there's a way to include that in the definition of the you know what you're trying to assess with that methodology but you it's not it's not required right so instead of doing it at the class level it seems like it would make more sense to do it at the um entity level right or the risk or control level like the object that's actually being subject to a risk or control or audit um all right so I think we are almost out of time so let's just uh start to wrap this up we've got a couple resources for you all to follow up um specifically on entity management our top five community webinars on entities these are older uh webinars but they're still very relevant um and they're not all some of them are are short so U if you need a refresher please go there um and then our um expert Services team has a new offering for um that can work with your organization they can work with your organization to do uh the irm data model designing um and there is also a link uh this is linkable in the in the slide that's attached to the community article that I sent out um and then another great resource if you haven't already um gone to the now learning site there's the fundamentals the implementation classes have a lot of the you know how to approach requirements around entity management um and so there's the on demand and instructor read Le courses for those as well um that are really great and um I think that's it uh oh and next week if you've got more questions next week we've got a follow-up same time next week at 9 o'clock it's just a short 30 minute not recorded session very informal if you guys want to come in and bring in a couple particular questions uh we'll be there to to answer them and um here is a link or QR code to look at any future webinars not just an entity management but all things risk and compliance um and I believe that is it and these are just additional resources again the community our YouTube playlists and uh the additional webinar link is there so we are right on time Drew uh this was awesome thanks for all your questions thanks Drew for all the tips and tricks and hope you guys have a great holiday yeah thanks for coming
https://www.youtube.com/watch?v=rmpUDzUjTxo