logo

NJP

How To - Risk Management

Import · Mar 04, 2022 · video

hello and thank you for joining me for our how-to clinic for integrated risk management today we'll be focusing on risk management specifically my name is adelina richards i'm a solution consultant here at servicenow specializing in integrated risk management in a previous life i used to work for deloitte consulting i had my risk register in a number of different excel spreadsheets and on sharepoint so i'm excited to talk to you today about how you can automate those processes using servicenow what are we going to cover in our session first we're going to talk about how to get started with your risk management implementation then we'll go over key concepts and skills for using risk management lastly we're going to look at best practices and additional resources what's our agenda first we're going to go through an overview of risk management as a whole we'll talk about what a risk is how we can assess risks on the now platform etc then we'll talk about specific features within servicenow we'll go through how each and every one of those features works best practices for implementation then we'll run through a live demo where you can follow along in your own instance where we'll import a risk register from excel and we'll create some risk frameworks and risk statements as well lastly we'll go ahead and take a look at some supplemental resources to help you get started let's start out by talking about risk management as a whole here at servicenow we have an integrated risk management solution that means that we have a number of different integrated risk management applications built on the now platform today we're going to be focusing on risk specifically but irm includes policy compliance audit vendor risk business continuity and privacy as well no matter which one of these applications you're going to be working in in servicenow you're going to be using that now platform so we'll talk a couple about a couple of those key components here whether that'll be our dashboards and reports or things like orchestration and automation on the now platform let's start out by talking about what a risk is well a risk is a vulnerability that can be exploited by a threat so some classic examples of a risk are what's the risk of a global pandemic occurring what if i have a loss of availability what if i get a ddos attack for example and how do we run through risk management on the now platform up at the top you can see the life cycle of a risk the first thing that we'll do is ingest a risk register into service now what do i mean by that well we can build our risk registers right on service now manually but if we already have one pre-existing maybe it's an excel maybe it's in a third-party system we can pull that information into the now platform once we have that list of all of our different risks we can start assessing those so we can automate risk assessments to take a look at things like my inherent and residual risk scores once i get those scores i can choose my risk responses am i going to accept these risks choose to mitigate them how am i going to avoid these risks we can even add in different mitigating controls say we've already implemented compliance we might have a number of different controls that we can add to our toolbox to help us mitigate particular risks of course we're going to be able to look at those control postures and assessments to take a look at how that impacts our residual risk and we can use indicators to make sure we have continuous risk monitoring so we're able to look at things like all right if my main website is down for over three hours i might want to open up an issue lastly we'll run through different reports and dashboards that we can look at to get that overview look into our current risk posture as an organization now how does all of this work i wanted to really quickly run through the architecture of governance risk and compliance of course policy and compliance management which we see down here in the bottom left is not included within that risk management application but it still interacts with it the main place that it interacts is with these entity types our entity types are going to be how we categorize our risks policies and controls across the now platform we can connect our different entity types to things like a service aware cmdb or configuration management database in this way i can have specific risks tied to those different assets business services etc that i might have in a pre-existing cmdb let's say we don't have that maybe we want to go ahead and build our risk architecture from scratch what we can do is start out with a risk framework so we can have a hierarchy to our risks we'll start with our overall risk framework maybe i want to have operational risk that i'm looking at underneath that i might want to look at particular risk statements so those risk statements might be um the risk of a pandemic for example then if i go a step further i might want to tie that risk statement to different entities so that risk of a pandemic is going to affect each and every one of my different office locations in this way i can create different risks so i'll have a risk of a pandemic occurring at my new york city office location at my los angeles office location kansas city etc now within each and every one of those risks we can then create an issue what we'll do here is check to see if these risks have occurred so here we can have indicators set up that'll say is there a pandemic yes or no if there is that risk has been realized that risk has occurred it's going to become an issue and we might choose different risk response tasks based off of the assessed score of that risk out of the box we have the most classic risk responses mitigation acceptance transference and avoidance we'll run through this a little bit later in our demonstration here today as well based off of which response you choose you can kick off a different workflow so i can have different tasks assigned to different individuals to figure out how i'm going to deal with these particular risks so let's talk about the different features that come with risk management on the now platform the first thing we'll talk about is our risk overview dashboard similar to other dashboards on the now platform a risk overview dashboard is highly dynamic so i'm able to look at my full risk posture as an organization here i can see all of the different risks posed to my organization and their associated scores up at the top we talked about entity types so what we're able to do as well is tie each of these risks to specific entities so that i can look at this report maybe i just want to see one of my office locations i can put in that entity type and i'll update that report accordingly here's where i'm also getting that enterprise view of my risk so here you can see that i'm not just looking at it risks i'm looking at all of my operational legal hr etc risks so this really gives me visibility into my overall risk posture and it's only one of several different reports that come with servicenow here is a list of the different face risk reports that will come once you activate that risk management plug-in on service now some examples that can be really helpful are looking at your risk by entity we discussed that your risk by framework total risk exposure etc the next thing we'll talk through is our risk register your risk register is going to be a full list of all of the risks posed to your organization now you can have any status for your different risks so if you want to have archived risks as well you can include those as retired in your risk register i love having my risk register on the now platform because as i said before i used to have it in an excel spreadsheet and whenever i updated one risk i had to go in update it on excel save it upload it to sharepoint versus here when i make any changes in my risks it's going to dynamically update so i get that real-time data not just in this list view but also in those reports that we just mentioned now once we go through and click on one of those risks we can manage the full life cycle of our different risks we can have a number of different workflows for this what exactly do i mean well the life cycle of a risk on the now platform starts with when we draft it out we can have specific risk identification so we can give the ability for people throughout our organization to say hey i think that i have a new risk on a particular project and create a risk identification record then you can have someone within your own team approve that or you can draft out a risk by having someone within your risk team create a new risk on the now platform and we'll run through that during our demo a little later today after we draft our risk out we'll then have an inherent risk assessment this is where our workflows start coming in handy when it's time to assess a particular risk we'll automatically send out a particular email some sort of notification to that risk assessor letting them know hey it's time to fill out this risk assessment once that risk assessment is completed we'll choose how to respond again we'll use one of those classic risk responses whether that be acceptance mitigation etc the risk will be reviewed and then we'll monitor it over time in that monitor phase that's where those indicators are going to be extremely powerful to see things like all right when has my risk actually occurred as we mentioned a little bit earlier we can also retire our risks this is helpful in terms of auditing if i want to go back and see every risk assessment that i've ever sent out while i might want to filter that out when i'm looking at my current risk posture for example now for everyone's favorite part of risk management let's talk about assessing risks out of the box our risk assessments are just going to ask what's the probability of this risk occurring and what's the impact to our business if this risk does occur one question i get all the time is that's great but i'm i want to have additional questions added into my different risk assessments how do i do that well what we're able to do is use our assessment designer so we can add in as many questions as we'd like remove questions and we can change the scale so again out of the box that's going to be a scale of one to five with very low low moderate high and very high being your options but you can change that scale usually i see two different kinds of risk scoring on the now platform will either go quantitative or qualitative so the question's up to you how would you like to score your risks when we're looking at quantitative scores that's where we're looking at things like single loss expectancy annualized rate of occurrence average loss expectancy if these are the kinds of statistics that you'd like to see we do have the ability for you to score your risks in a quantitative fashion now if you want to look at these in a more qualitative point of view you can do that as well i've seen plenty of customers have both qualitative and quantitative risk scoring when we're looking at qualitative that's when we're talking about having inherent and residual risk on a scale of one to five based off of those questions that um are centered around likelihood impact maybe um the reputational impact to your particular business now once we decide whether we want to do qualitative or quantitative risk scoring what we're able to do is create risk criteria for example we might want to assign specific amount or dollar amounts for that overall risk score i might want to say a one is very low and here you can see we've put in a specific maximum value so i would challenge you to take a look at this particular slide and tell yourself all right do i agree with these metrics do i believe that a very low impact is equal to a million dollars do i believe that a very high likelihood is equal to a hundred percent i would say a hundred percent is very likely but you can change all of these values as well all right once we have an ability to assess our particular risks we might want to create a hierarchy as well here we're taking a look at the grc work bench basically what we're doing here is looking at the hierarchy of our different risks as we said before we're going to have that risk framework excuse me then we're going to have our particular risk statements and then our risks here we can also link with our cmdb so we can look at things like the relationships between our different applications and those associated risks here we can see our risk management architecture that we discussed earlier a little more visually we'll start out with that overall risk framework then we have our risk statements so again maybe i'm looking at operational risks that risk statement is risk of an earthquake i might have different control objectives from compliance that tie into this particular risk statement maybe that means i want to have a disaster recovery plan in place in case there's an earthquake in my la office for example now i might want to have particular indicator templates for any risks underneath that wrist statement so underneath this risk statement i'm going to have the risk of earthquake down here in my san diego office or maybe i want to have the risk of earthquake in tulsa for instance then i can have those indicators that are basically looking out to see if that risk has occurred then i can track that using reporting tools tied to each and every one of my wrists are going to be those risk response tasks so let's say that we accept the risk that there might be an earthquake there's nothing that we can quite do to avoid it maybe we want to mitigate it so we can't do anything to avoid that risk occurring but what we can do is be ready to clean up the mass once it happens so those risk response tasks might be to create a mitigation plan and to add in any mitigating controls here you can see where we can tie in those controls link it to policy exceptions again these are all going to be other parts of the now platform now you can also tie to risk events so risk events can be any kind of risk that isn't related to it up to you how you want to differentiate risks and risk events on the now platform now when we're taking a look at those risk statements here's a classic example from those cia risks out of the box we have three different risk statements loss of confidentiality loss of integrity and loss of availability these were statements can be extremely helpful and we'll see a little bit later in our presentation that what we can do is say all right i'm going to have a loss of availability risk for each and every one of my business applications and websites now if i have a cmdb in place what i can do is link these risk statements to every business application that i have and then automatically build out my risk register if i don't have a cmdb in place that's not a problem i just won't add in that particular business application here if it's not helpful to me now underneath my risk statements i might want to add in risks so you can see all the different parts of my risk statement i can tie it to that framework i can add an associated scoring and categorize it accordingly then underneath that i'll have those risks here i can see a classic risk form up at the top you'll recognize that life cycle of a risk so you'll see here now that we have that loss of confidentiality risk for a particular entity type it's going to be a piece of software here in this particular example similarly here we're going to see all those different aspects of my risk form some important things to note here you can have a particular risk owner or owning groups you can tie in that entity again that's how we're going to be categorizing our particular risks and controls across the now platform the state or status of your risk is going to completely depend on what part of that life cycle you're in and over here on the right you can see that we have that risk scoring available as well we can dive a little bit deeper into those scoring and response tabs within a risk so here we can see those calculated values and as we choose different responses maybe i'll choose to make this a mitigation i can add in my mitigation plan here as well now if i want to track all changes on my wrists if i want to see different work notes version history etc that's going to be in my activity journal now let's talk about responding to our risk we've mentioned in passing our risk responses so again on the now platform a risk can be accepted avoided mitigated or transferred and then we can create different workflows based off of those risk responses so that might mean we need to create a plan it needs to get approved reviewed etc here we can see exactly what that looks like so here over here on the right we're taking a look at accepting a particular risk so risk response is just going to be that process by which a risk has been determined following a formal risk assessment so this is how we're going to really look at that residual risk now in practice what we're going to do is have different actions based off of the different risk responses that we choose so here you can see mitigating that risk i'm adding in those mitigating controls accepting that risk i need someone to go ahead and sign off on it i'm not just gonna say ah here's a risk i i have no plan for it and i'm just going to bury it deep and no one will look at it we want to get that reviewed and approved if i'm choosing to avoid a risk looks like we're going to reject that risk and deploy measures to avoid it now of course these are just best practices if you have different options here you can do that as well we have a number of different workflows that are kicked off based off of which one of those different risk responses you choose so here you can see again based off of acceptance avoidance mitigation transfer we can change the state have a different approval process and create different tasks now let's talk about our indicators indicators allow us to have continuous monitoring of our particular risks usually our key risks and controls now what we're able to do is automate our issue collection based off of these indicators it's going to be really helpful when it comes time for audit or even for control testing i want to take a minute here i know we've talked about workflows what does that look like at servicenow we have a couple of different ways to change our workflows here you can see a graphic workflow we have both our workflow designer and our workflow editor if you're interested in learning more about how do i set up these different workflows let us know let your account team know always happy to run you through a lab or your sc can run you through a demo here we're showing some examples of out of the box workflows for grc that's going to include things like issue workflows that's the one we're seeing here now but if we're looking at compliance you also have some out of the box workflows for policy exceptions for example and last but certainly not least let's talk about issue management issues occur when a risk is realized so again that classic example covid19 we had a risk of a global pandemic occurring and here it is it's an issue now what we're able to do with our issues is what we is automate that process of issue remediation now what i can do here is i can automatically assign different individuals to issues and have suggested tasks on how to fix them so let's say that i have an issue with my developers are testing their own code over and over again right if adelina is always the one going out making sure that they're not doing that i might automatically assign any new issues that come up with developers testing their own code to avelina and i can always have that workflow that i used last time copy and paste it onto this issue so i can fix it quickly now that we've run through the different features of risk management we talked about what a risk is what are those different mitigation strategies those risk response strategies to deal with our risks let's talk about implementation best practices we have a number of keys to deployment success the first thing that we're do going to do is determine our business case so we want to make sure we know what outcomes we're looking for in today's example that outcome is going to be i want to have that risk register up and running i want to be able to create new risks and risk statements so that i have that hierarchy of risk built out and ready to go we want to have defined success criteria so maybe that means i'm able to assess all of my different risks and i have that risk register in place we want to make sure that we're planning for adoption of outcomes so that might mean things like before we run through and just say here you go here's a risk register changing things like branding on your servicenow instance lastly for that business case we want to make sure we're aligning on your strategy and culture so if again we're looking at things like those logos to make sure we have user adoption high and we can make sure that we're following your current processes of course we recommend some preparation we do have servicenow fundamentals and grc fundamentals training i recommend both the grc and risk compliance implementation training that is an excellent training and really dives in deep with the different technical aspects of implementing risk and compliance on your own instance and we want to make sure most importantly that we're identifying a product owner so we want to know who we're giving that admin role to or maybe we have an overall platform owner at our organization once we have that product owner we can move into the planning stage here's where we're going to identify a team with their own who will own and maintain the grc product you might already have all of this complete if you do good job and if you don't we have some work to do we'll make sure to take a look at our different stakeholders and define a plan and timeline for that grc product implementation at the end of our presentation here today i'm going to give you some resources that can help you create those different implementation plans as well on now create next we'll run through collaboration so we're going to take every single part of risking compliance across our organization and make sure that we're all on the same page lastly we're going to get up and running so let's make sure we have some process guides ready and that we know that our users know how to use integrated risk management on the now platform as well now we have a number of different stages of maturity when it comes to implementation so i never recommend anybody go in and let's do every use case within irm i usually say you know i started out in the manual stage i had spreadsheets crossed my fingers hoped nothing horrible would happen i want to start out by getting people to basic and repeatable that means i'm taking the use case that's giving you the biggest headache today we're talking through that headache of i have an excel spreadsheet for my wrists whenever i update them it doesn't always save i don't always update the risk realization date on time so here we're going to be looking at that one use case implementing it getting value right then we're going to start expanding so we'll look at things like all right maybe i can add in policies into service now i can add in my different compliance requirements maybe i'll take a look at socks for example as you keep building out you're going to gain that functionality and you're going to say wow audits are so much easier than they used to be i can't believe i don't have to email people a million times to make sure that my risk assessments are actually completed etc all right the last thing we're going to focus on before we take a look at a demonstration is looking at those risk roles that we're going to assign to our different users so we mentioned building out that team the first thing that we're going to do is create a risk admin your grc admin is going to usually be your risk managers and they have god privileges within grc that means they don't have quite the level of access as a system administrator they can't change um huge platform level things they can't make any changes if you have itsm or hr for example but they can make a lot of changes in governance risk and compliance so here you can see they have the ability to delete risk frameworks for statements risks that's something not everybody can do you can assign this to multiple individuals i usually recommend saving this for one or two people then we'll have our generic risk user user usually what they're going to do is i'm going to be filling out those risk assessments i want to take a look at a report etc then your risk manager is going to be able to create those risk frameworks for statements and risks we're going to see exactly what that looks like in our demo today we do have a number of supplemental roles as well so here you can see just read access that main risk user a little more information for you here of course they're going to have that read access as well you can have a specific assessment creator so that's looking at things like i might want to have different risk assessments for financial versus legal risks for example i have that risk manager who's able to create risk managers can also take a look at most of your different reports and edit them accordingly and most importantly that risk admin so they can delete they can also import so while we're running through our demonstration here today we will be as a risk all right thanks so much for taking the time to run through those slides what we'll do now is run through a demonstration on how we can set up a risk register make some different risk frameworks high in risk statements and risk there and we'll run through an example assessment and see how we can change those assessments as well here we can see servicenow on a standard web browser i'm logged in today as myself and i've given myself grc admin privileges the first thing that we want to do is activate our plugin for risk management so we'll go over to our application navigator and type in plugins this is going to bring us to a list of all applications when i go to search i'm going to take a look at risk management as i scroll down here i can see there's a couple but the one i want to download is grc risk management you'll have to take a look at what licensing that you have to see if you can get things like use case accelerators for nist rmf socks content packs etc so once you go ahead and click install give your instance a little bit of time to go ahead and download that data once you've installed risk management let's start out by uploading our excel spreadsheet risk register so once that's installed i should be able to click risk one thing i'll note everything here is going to be alpha alphabetized so if i want to look at my wrists i got to scroll all the way down here and i'm going to be able to take a look at my risks here we go so here we're looking at each of my applications on service now i want to look within that risk application underneath here i'm going to see all those different links that i get that's going to include that overview dashboard as well as all of my different risks so things we talked about overview dashboard that grc work bench that shows me um that list of my different risks kind of visualizing it by linking it to the cmdb of course none of this is going to be populated until we add our risks so i want to go to this risk register tab and click all risks you can see i already have some risks in here if i wanted to manually create some risks on their own i could go ahead and click new here you can see i've created a new risk record this should look very similar to those powerpoint slides that i just showed so you can see again up at the top that life cycle of my risk can add in the name of a particular risk and the entity type associated we'll run through what this looks like a little bit later in our demonstration today let's go back to our risk register what i might want to do here is favorite this that means i'm going to be able to easily get back to this wrist register whenever i need to i like to always make my wrists red you can make it whatever color you'd like now if i want to add in more risks i can go here right click i'm going to see i have the option to import so i'm going to click import there now here i can insert or update data you can create an excel template so if i want to have different um options available for the columns that i need to create so that i can have a seamless transform map going here i can do that let's say today i've already done that go ahead and choose a file and here i've cleverly named my risk register servicenow risk risk so let's go ahead and upload this now note this might take a little bit of time so as it's going through and uploading make sure that you gave the exact right names for your columns that way it'll populate correctly now once i've imported this i'm going to get a nice success message and i can continue on and i can start creating some risk frameworks all right there we go here i can see i've populated all of those different risks and i have all the associated information needed now let's say i want to change this information that i have available i can click on my settings tab and add or remove any information so let's see let's say i want to see only my wrists that are active i can add that in you can see i can add in any of these available lists so if i want to add in as well what risk response i choose maybe i want to have that right next to the state or the owner you can see i've added in that information over here on the right now i can report off of any of this information and filter it accordingly so maybe i only want to see different risks that i'm choosing to mitigate i can right click show matching and i can see that report again this is still coming from my excel spreadsheet now let's say i want to bolster this risk register a little bit by adding in different risk frameworks and risk statements again we're going to go over here we can type in in our application navigator risk frameworks you might want to favorite it it's within my risk library so here you can see i have a number of different frameworks my favorite of course is this demo example you can see some examples are departmental risks business service loss events physical and environmental threats let's create one and use that example we've been using all day for um health risks so that's going to be pandemics or any other kind of major public health crisis let's say public health risks so what i'm going to choose to do is save i always recommend that you go ahead and save so that you can see if any additional information comes up on these forms if you click submit it'll take you back to the previous screen i can add in a description here i'm going to save you from having to watch me type but we can add in any of those entity types or categorizations so i can create new entities here or if i already have this created because of the cmdb i can add in anything here so maybe it means i want to add in companies office locations departments data centers etc most importantly what i can do is create risk statements so let's create a new risk statement so first we have our overarching umbrella of a risk framework then we can have risk statements so underneath that here let's say pandemic not the best phrasing but just for example you can make parent and child risk statements as well as parent-child risks and then you can have upstream and downstream risks as well we can categorize our different risks again these are those out-of-the-box categories let's say today that this one's going to be operational and here's where we can tie in different kinds of assessments again i'm going to go ahead and right click save if you would like you can add in default scoring again this is where we're getting together as a team and we're saying do we want to have those default scores as i scroll down i'm seeing my related lists these are going to give me any information across the now platform related to this particular risk statement here's where i can go a step further and add in particular risks underneath this risk statement if i wanted to add this automatically to different sections of our different assets within my cmdb that's where i can click on information objects so here you can note as i scroll down that i can tie this to anything within that cmdb whether that be um again that loss of availability risk maybe i want to go ahead excuse me and have that linked to all of my different websites for example now let's add a new risk here we're going to say we have a pandemic risk and we're tying it to a particular entity so i'm going to do my new york data center that i have to make sure that i have a disaster recovery plan in place maybe a business continuity plan i should say for if there is a global pandemic and everyone has to work from home how are we going to keep our data centers up and running we can see we can add in a specific owning group so i'm going to make that my risk managers that group is going to be created from your system admin as this particular group i recommend making that it's just based off the number of user roles you have so again i'm going to click save i like to click on my hamburger there you can also right click and our new risk will be created so you'll know every single one of these different risks will have the same name but the entity type will be different as i scroll down you can see who i have filling out this particular assessment so i'm going to make it me just for demonstration purposes today and then what i can do is choose to assess a particular risk this is how i go through this life cycle so what i'm going to do is i'm going to favorite this so we can come back to this risk and again i'm going to make it red once i fill out that assessment what i can do is choose how to respond so here if i go to my risk response let's say we're going to mitigate this particular risk so let's move it into the monitor stage now i'm just going to see whether or not this risk has occurred so that's how simple it is to go ahead and run through creating a risk framework or a statement and then a risk now let's talk through risk assessments so to get to your risk assessments you can go to this risk application and when i scroll down you can see i can get to my different kinds of assessments so of course we have our different assessment types if you type in assessment types that'll come up a little bit faster as well so here we can see our particular risk assessment let's jump into our risk assessment designer this is where we can create different kinds of risk assessments or edit existing risk assessments this is all going to be drag and drop so if i want to provide um a different scale say we want to have a numeric scale i want to say reputational risk again you're gonna have a little bit better wording than i am right now and you'll spell reputational correctly and that's not even right either no worries all right let's call this question one there we go we can add in the different ratings here if you need them to provide an attachment you can add that in as well so that's how easy it is to add in different questions different needs for attachments booleans um options as well now when i want to look at my particular risk assessment the one that comes out of the box right let's click in here and see my different options it's going to show me both in here and residual risk so let's take a look specifically at inherent risk here you can see those different questions that might come here's the reputational impact spelled correctly and here we can take a look at financial impact as well one thing that i want to note you can have the order and we can prescribe a particular weight here we haven't they all have an equal weight however what we can do is say all right the reputational impact is more important to me than the financial impact so i can give it a higher weight for the overall inherent risk for example so you're absolutely able to go ahead and change this however you want so that when you go ahead and send these risk assessments out it looks familiar to your users again that's just going to be helping out with user adoption all right so we were able to see how we could create that risk hierarchy add in an excel spreadsheet to go ahead and import all of our different risks now let's talk about additional resources all right what else can we do now i encourage you to go to now create that will have different implementation um use cases and timelines please feel free to go over all of these different materials that i'm sending out especially these links to supporting documents these can be really helpful because they're going to send you right to our documents website so if you have particular questions please feel free to reach out here or go into our community as well of course your account teams are always going to be there to help you out so never um hesitate to go ahead and reach out with any questions or concerns thanks so much to take the time today to learn a little bit more about how to implement specifically risk management i hope you were able to gain some insight into how we can get started with some simple use cases like setting up a risk register and how to change our different risk assessments

View original source

https://www.youtube.com/watch?v=bWS7YULw6SE