Security and risk · LessonBy Praveen T, ServiceNow Trainer, 9 yrs · Published · ServiceNow · all levels
Policy and Compliance
Map authority documents to controls, test them, and evidence compliance without a spreadsheet.
Quick answer
Map authority documents to controls, test them, and evidence compliance without a spreadsheet.
Key takeaways
- Authority document, citation, policy, control, entity is the chain
- Automated control tests replace annual evidence gathering
- Issues need owners and dates like any other work
- Overlapping frameworks create duplicate controls, consolidate them
The model
An authority document such as ISO 27001 or PCI DSS contains citations. Citations map to policies and to controls. Controls attach to entities, which are the parts of your business in scope. That chain is what lets you answer which systems are covered by which requirement.
Testing controls
Control tests can be manual attestation, an automated indicator or a continuous monitoring check that queries the platform. Automated tests are the difference between annual panic and continuous assurance.
Issues and evidence
Failed tests create issues with owners and due dates.
- Keep evidence attached to the control test result, not in a shared drive
- Use entity types so scope changes do not require rebuilding controls
- Report by authority document for auditors and by entity for owners
- Retire duplicated controls that came from overlapping frameworks
Practice challenge
+0 XPStreak ×0
Question 1 of 2
What creates an issue in compliance?
Frequently asked questions
Can one control satisfy several frameworks?
Yes, that is the point of the model. Map one control to citations in multiple authority documents.
What is an entity?
The thing in scope, for example a business service, a location or an application. Controls apply to entities through entity types.