How to use ServiceNow Control Attestations to Streamline Compliance Management
Cerna is Now Thirdera
·
Sep 20, 2020
·
video
[Music] hi i'm matt mays senior technical consultant for cerner solutions today we're going to explore attestations for integrated risk management on the servicenow platform what does the attestation feature in servicenow do for your integrated risk management team it reduces questions and back and forth emails between control owners and irm team members by bringing the entire control attestation process into the servicenow platform it makes it easy to get responses from busy control owners with trackable and assigned assessments and finally it automatically sets the compliant state of controls and keeps a record of the evidence collected from your control owners on this screen we see our security analyst grace is looking at the control manage visitor identification inside the facility she's trying to determine how the control is implemented and whether it's in place normally grace would have to go through a series of back and forth emails with the control owner patty to determine if this control is in place and how it's implemented with the attestation module this process is greatly simplified grace simply comes up clicks the attest button and now an attestation has been created and sent to the control owner patty to complete control owners are busy people paddy included the attestation module will save paddy time from the irm portal she comes to the attestations button clicks it and she's presented with her attestations she clicks take attestation she clicks get started and she's printed presented with the manage visitor identification inside the facility she clicks yes the controls implemented she attaches evidence she provides an explanation guards check ids at the door she clicks submit and her job is done lots of time saved after our control owner patty completes the attestation our security analyst grace returns to the control and finds it in a review state the status is compliant and grace can come to the attestations related list and click view responses to see patty's responses she sees the question is the control implemented as marked yes she can review the evidence provided by patty and review her explanation guards check ids at the door from here grace clicks the monitor button and our control is now in a monitor state all of this has been completed without a single email between grace and patty saving both our control owner and our security analyst a lot of time next we'll look at the attestation grouping capability this gives the control owner patty the ability to attest to multiple controls at one time for example if she had results from an audit patty navigates to the my attestation page selects the desired attestations to complete and clicks group she picks the desired response in this case provides same response for all assessments and the criteria we'll next patty clicks the link for attestation group has been created and clicks take assessment paddy picks the appropriate response in this case yes she attaches the evidence and provides the appropriate response completed during audit after patty completes the group attestation grace is able to come to the servicenow list view and see that all of the controls in that attestation have been completed and they're in a review state and mark compliant thank you for watching control attestations presented by cerna like this video and subscribe to our channel for more great integrated risk management on servicenow content for information or to contact us see the information on the screen
https://www.youtube.com/watch?v=aoJcGf_Wpck