ServiceNow CIS-RC General Info
Content packs for GRC - Answer-- SOX: prepackaged policies, controls, risks, audits, and dashboards.
- NIST
- CMF
- NIST RMF
- GDPR
- Performance Analytics - provides GRC options in Interactive Filters to homepage/dashboards
Who can edit GRC content packs? - Answer-Compliance, Audit, and Risk admins can edit content packs.
GRC use case accelerators - Answer-- NIST RMF
- NIST CSF
- GDPR DPIA
Can plugins be uninstalled? - Answer-Plug cannot be uninstalled
Can applications be uninstalled? - Answer-Applications can be uninstalled within the plugin
, What is TOI? - Answer-Transfer of Information - recorded sessions that communicate new features for
product releases
Name three templates - Answer-- Control Objectives
- Risk Statements
- Indicator Templates
What can be created from templates? - Answer-- Risks
- Controls
- Indicators
What is used to scope an Audit? - Answer-Entities
What is used to scope Risks? - Answer-Entity Types
Risk Assessment Methodology (RAM) is defined for an Entity Class. What application is used for RAM
definition? - Answer-Advanced Risk
What is best practice for Entity Type, Control Objective, and Policy Mapping? - Answer-Entity types are
mapped to control objectives, not to policies. Map policies to control objectives
Is it best practice to check the box, 'Have controls created automatically' on Control Objectives? -
Answer-Yes
What role do Attestations play in ServiceNow? - Answer-Attestations ensure the control has
implemented in the organization
Content packs for GRC - Answer-- SOX: prepackaged policies, controls, risks, audits, and dashboards.
- NIST
- CMF
- NIST RMF
- GDPR
- Performance Analytics - provides GRC options in Interactive Filters to homepage/dashboards
Who can edit GRC content packs? - Answer-Compliance, Audit, and Risk admins can edit content packs.
GRC use case accelerators - Answer-- NIST RMF
- NIST CSF
- GDPR DPIA
Can plugins be uninstalled? - Answer-Plug cannot be uninstalled
Can applications be uninstalled? - Answer-Applications can be uninstalled within the plugin
, What is TOI? - Answer-Transfer of Information - recorded sessions that communicate new features for
product releases
Name three templates - Answer-- Control Objectives
- Risk Statements
- Indicator Templates
What can be created from templates? - Answer-- Risks
- Controls
- Indicators
What is used to scope an Audit? - Answer-Entities
What is used to scope Risks? - Answer-Entity Types
Risk Assessment Methodology (RAM) is defined for an Entity Class. What application is used for RAM
definition? - Answer-Advanced Risk
What is best practice for Entity Type, Control Objective, and Policy Mapping? - Answer-Entity types are
mapped to control objectives, not to policies. Map policies to control objectives
Is it best practice to check the box, 'Have controls created automatically' on Control Objectives? -
Answer-Yes
What role do Attestations play in ServiceNow? - Answer-Attestations ensure the control has
implemented in the organization