Control objectives, the golden thread of IRM

If you look at a ServiceNow IRM implementation, it may be hard at first to realise just how important control objectives are.

They literally hold everything together.

  • If you want to show your compliance to regulations, you need them as they connect to citations, and control tests.
  • If you want to mitigate your risks consistently you need them, as they will be linked to risk statements.
  • If you want to populate policies and reduce duplication and extra effort, you need them. As they form the bulk of a policies content.

Just like the foundations of IRM, Control objectives can be the key between a powerful and valuable IRM implementation and a mediocre and impact installation.

Let’s look at why we need to use control objectives and why putting that little extra time and effort will add so much.

Let’s build a scenario, you have your Authority document from the regulator, it’s broken down into its citations and the words are in legalise. So you start analysing and asking questions:

  • You know you must do something; it tells you what to do but it doesn’t tell you exactly how to do it.
  • Maybe your company has regulation experts such as the privacy experts Wrangu has?
  • In which case they will have told you what their interpretation of regulation is and what each citation is looking for.
  • Maybe you are using downloaded the content?
  • All that is a start, but now comes the hard part.
  • Are you already doing this or not?
  • How do you know?
  • Is there something in a policy you have already implemented that would cover this?

That’s where Control Objectives come in.

Multiple citations can be linked to a control objective, if you are using UCF (Unified Compliance Framework) you probably already know this. You probably also know that the content provider control objectives are usually light touch and minimal.

They are a starting point.

What I feel is a huge mistake, which I commonly see, is people trying to use them as they are… DONT!

Now bear with me, I am asking you to take time and do some more work up front, but I promise you there is a very good reason.

Because Control Objectives are so key, the deserve time spent on them to make them work properly.

They are the voice of the company, explaining to employees how to implement a control, not the regulation but how YOU, YOUR company intends to comply with the regulation it.

The more information, guidance and support you put in these records, the better you will find your end users, your team will understand what is being asked of them and make the right call.

Knowledge is power and here is a prime example of putting that power in the hands of your teams.

The more detail and clarity you put in the control objectives the easier it will be to understand if it meets multiple regulations.

The more detail and clarity you put in the control objectives the more value the policies you generate from control objectives will be.

You will be able to publish them in confidence and be able to search through them with a greater degree of success.

The better your control objectives the easier it will be to map the to the right risk statements and feel confident in mitigating threats against your business.

Good quality control objectives can be the difference between a poor and a great experience on the ServiceNow IRM platform.

So, whether a customer or a ServiceNow consultant.

The next time the question comes up, give control objectives the respect they deserve.

I promise you; you won’t regret it.

They are after all, the golden thread that links everything together.

I borrowed the phrase from a client, he knows who he is and I hope he doesn’t mind, as it was too good to pass up.

Disclaimer: This content was not produced using AI but it the random outpouring of my brain which I hope was of use to someone.

Author

  • Lee has worked in the IT industry for over 23 years. He is ServiceNow architect with over 14 years ServiceNow Experience. For the last five years he has specialised in Integrated Risk Management. As a Certified specialist, trainer and solutions consultant, Lee has Worked with some of the biggest and smallest companies in the world helping the with their IRM journey. He currently acts as the Head of Solutions Consulting and a ServiceNow Architect at Wrangu.

    View all posts

Author

  • Lee has worked in the IT industry for over 23 years. He is ServiceNow architect with over 14 years ServiceNow Experience. For the last five years he has specialised in Integrated Risk Management. As a Certified specialist, trainer and solutions consultant, Lee has Worked with some of the biggest and smallest companies in the world helping the with their IRM journey. He currently acts as the Head of Solutions Consulting and a ServiceNow Architect at Wrangu.

    View all posts