Policy and Compliance
Quick answer
Map authority documents to controls, test them, and evidence compliance without a spreadsheet.
Key takeaways
- Authority document, citation, policy, control, entity is the chain
- Automated control tests replace annual evidence gathering
- Issues need owners and dates like any other work
- Overlapping frameworks create duplicate controls, consolidate them
The model
An authority document such as ISO 27001 or PCI DSS contains citations. Citations map to policies and to controls. Controls attach to entities, which are the parts of your business in scope. That chain is what lets you answer which systems are covered by which requirement.
Testing controls
Control tests can be manual attestation, an automated indicator or a continuous monitoring check that queries the platform. Automated tests are the difference between annual panic and continuous assurance.
Issues and evidence
Failed tests create issues with owners and due dates.
- Keep evidence attached to the control test result, not in a shared drive
- Use entity types so scope changes do not require rebuilding controls
- Report by authority document for auditors and by entity for owners
- Retire duplicated controls that came from overlapping frameworks
Want to learn this properly?
Our live, instructor-led ServiceNow Training covers this hands-on, with real projects and a certification path.
Check your understanding
What creates an issue in compliance?
- A. A passed test
- B. A failed control test
- C. A new citation
- D. A policy update
Show answer
B. A failed control test
Failed tests raise issues for remediation.
What links a framework requirement to your control?
- A. A citation
- B. A knowledge article
- C. An SLA
- D. A CI relationship
Show answer
A. A citation
Citations are the requirement level records mapped to controls.