Learn how to set the whole of your GRC infrastructure in motion to save time with this episode of the "Get started with GRC" on audits.
Controls, Entities, Indicators etc. all come together in this beautiful conclusion of your compliance or risk journey.
The demo uses Sarbanes Oxley as an example.
This includes a link to a free Audit class.
-----------------------------------------------------
Video content
00:01 Introductions.
00:56 The audit is when everything comes together.
01:40 Refreshers: Maturity journey, the overview of your GRC universe (print this slide), previous tutorials.
03:09 What is an audit, why you need one.
05:20 Audit logic and best practices. Say what you do, do what you say, prove that you've done it.
07:10 What an audit looks like in ServiceNow. Audit Engagement. Control Test, Tasks, Evidence, Output.
09:07 Let's get into the details. The life-cycle of a Control (also view tutorials on Controls, Compliance Scoring, Indicators).
09:39 Deep dive on the Control Test. To confirm the effectiveness of a Control. The auditor will need to know the steps.
10:44 How to generate the Control Test. 1- Template (Control Objective), 2- Test Plan (Control), 3- Control Test.
11:31 Internal or external audit.
12:36 Some use cases: Full internal audit, partial audit, to keep track of audit findings and issues.
14:01 Demo (the example of SOX): Create the Engagement, select the Entities, select the Test Plan, to generate the Control Test, Create audit activities, Close the audit, publish the findings and report.
30:40 The main take-aways: Start with Entities, this brings in the Risks and Controls automatically, set the audit dates,
31:21 What to do right now. Free audit class, create an Engagement, ask questions on the community forum.
32:29 GRC cheat-sheet to print.
32:50 Thank you.
For questions and to download the slides in PDF format:
https://community.servicenow.com/community?id=community_article&sys_id=274ed1c4dbf39050f21f5583ca961992