The goal of this lab is to understand General Data Protection
Regulation (GDPR) requirements, its impact on your organization, and how
ServiceNow can help your compliance journey to GDPR. ServiceNow
Governance, Risk, and Compliance (GRC) helps bring order to an
enterprise's compliance requirements to GDPR. It provides best practices
to meet the GDPR requirements.
This lab explains key ServiceNow
application to support GDPR and names the key citations (regulatory
requirements) for GDPR.
-
Navigate to the unique instance URL provided to you.
-
Log on with the provided credentials.
-
Review your homepage.
You can change your homepage to System Administration by selecting it from the dropdown list in the top-left of the page.
-
Review your favorite applications by clicking the star next to the application.
-
Discover the GRC applications and its modules by typing the first few letters of Policy and Compliance, Risk Management, or Audit Management.
-
Click the ServiceNow logo.
-
In the homepage window (1), from the dropdown list, search for compliance.
-
Select Compliance Overview.
-
Review the initial Compliance status.
You should see the GDPR Compliance report as empty for now. The related gauges/reports are updated as you progress with the lab.
This lab explores the GDPR authority document. It also explains the different citations for regulatory requirements.
-
In the Filter Navigator, enter authority, and then click Authority Documents.
-
Under Authority Documents, in the Common Name field, search for *EU (3).
Note: Refer to the example below. If your Type field for EU GDPR Authority Document is empty, you can add the relevant type by double-clicking on the empty field.
-
Click the EU General Data Protection link (begins with AD00).
You might have different authority document number. -
Review the overall GDPR information.
-
Scroll to Related Lists and click Citations.
-
In the Reference field, search for Art. 35.
-
Review the relevant article, information, and respective subsections.
This lab explains how to create an organizational policy and policy statements that matches requirements and describes the outlines for GDPR.
-
Navigate to the Policy & Management application.
-
Search for Policies, and then click Policies to list them.
-
At the top of the policies page, click New.
On the top of the record, a full Policy Life Cycle Stages list appears.
-
Fill out the new policy record with the following information.
You can click the icon to add yourself (System Administrator) or click the lock icon to add Policy Approver.-
Name: Data Protection Policy
-
Owner: Policy Owner
-
Type: Policy
-
Owning group: Policy Management
-
Description: Data Protection Policy
Note: For the purpose of this lab, you can provide any valid dates. For simplicity, we have skipped any additional policy reviewer step here.
-
-
To save the record, right-click the policy header bar, and then from the dropdown menu click Save.
-
In the Filter Navigator (1), enter Knowledge, and then click the Knowledge application (2).
-
In the search bar, search for *gdpr (3), and then press enter to continue.
The Lab Data Protection Policy appears.
-
Open the Policy.
The Lab Data Protection Policy (4) describes the different sections required for a Data Protection policy. -
Review the policy content.
-
Copy the content of the Lab Data Protection Policy.
-
To return to your policy, click the Your history icon (1), and then click the Policy (2) you just created.
You should now be back in the policy record.
-
Paste the copied content into the Policy Text field.
-
To save the record, right-click the header bar and then click Save from the dropdown menu.
-
Assign relevant Policy Statements to the policy.
-
In the top-right of the page, click Add Statements to generate Policy Statements that are defined for the policy.
a. Scroll to Related Lists and click Policy Statements.
You should see nine policy statements added to the policy.
b. Click any Reference number; for example 1. A Policy Statement window opens with underlying reference number.
c. Under related lists, click the Citations tab and verify that at least one EU GDPR Regulation citation is aligned with that policy statement.
-
Navigate back to your policy.
-
Move forward into Policy Life Cycle.
-
Go to the next stage and click Ready for Review.
The policy moves to the Review stage in the Life Cycle Flow. A reviewer can now review the policy.
-
For this lab, go directly to the Approval step.
-
Click Request Approval.
The approval request goes to Policy Approver & System Administrator.
The policy form field now becomes read-only as shown below in the second example.
After requesting approval, policy life cycle state changes to Awaiting approval as shown below.
-
Scroll to related lists and click Policy approvals.
There are two records waiting for approval.
-
Double-click next to Requested at the end of the word and then select Approved for each approver.
-
Reload the form.
The Policy Record has moved to the Published state. Also, a Knowledge Article has been published. -
Scroll to KB article and click the information icon at the end of the line.
A Knowledge record window opens.
-
Under Related Links, scroll to View Articles.
-
Click View Article.
The KB Article has automatically been created with related requirements listed at the bottom of the article.
You have just created a policy aligned with regulation requirements. You have completed a full Policy Life Cycle.
This lab explains how to create a Profile Type and assign a Risk Framework to assess compliance requirements for a profile. A profile -- An entity we need to check for compliance requirements --- will then have the associated policy and policy statements you just created. You add risks to the Profile Type and see what could be the potential impact of noncompliance to a profile.
-
Click the history icon to return to the Policy Record. (as in Lab 2.0)
-
Scroll to related lists and then, in the Policy record, click Profile Types (1).
-
Under Profile Types, click Edit (2).
-
In the left-hand selection list, click Organizations (3), move it into the right-hand selection list, and then click Save (4).
You return to the policy record.
-
Scroll down to the Profile Types related list and click Organizations.
The Profile Type record opens in a new window. A profile, ACME Inc., is assigned to this Profile Type.
The Policies and Policy Statements created in earlier steps appear in the related list.
-
Return to the Dashboard and check the Compliance Overview.
The GDPR Compliance gauge is created with an empty status. -
Add a Risk Framework to the Profile Types as shown below.
-
Add a Corporate Risks to the Profile Type and then click Save.
Corporate risks are related to the regulation requirements. The Risk Framework is now assigned to the Profile Type. -
Reload the form.
The Risk Statements are also automatically added to that Profile Type. -
Click Risk Statements to see the assigned Risk Statements.
You should have some Risk Statements (6), including Non-compliance with Law/ Regulations. We will revisit this Risk Statement later. -
Under related lists, return to Profiles, and then click the profile ACME Inc.
The Profile window contains Organizations in the Profile Types related list.
-
Click the Controls tab next to Profile Types.
There are nine controls allocated to this Profile as requirements described in the policy.To see the assigned Risks, click Risks.
-
Click the Non-compliance with Law/ Regulations risk.
You are now in the Risk record. -
Change the Risk Life Cycle status in the form from none to Not Assessed, and then save the record.
-
Review all the fields in this risk record.
a. Scroll down and click the Scoring tab.
b. Check your inherent, residual, and calculated scores. c. Write down the Calculated scores! (ALE = Annual Loss Expectancy)Without having any controls implemented to reduce this risk, the likelihood to incur this risk, and in turn the impact, is high. The objective we want to achieve is to reduce the risk.
-
Change the Scoring record for Inherent and Residual impact & Likelihood as follows:
-
Save the record, and then Reload the risk record form to see the new values.
-
Add controls to associate GDPR requirements to the risk.
a. Scroll down to related lists, click Controls, and then click Add.
A new window opens allowing you to select controls to associate with the risk.
b. Select All controls and then click Add Relationship.
There are nine controls associated to that risk.
-
After adding these controls, save the record.
The risk score remains the same since you have not yet executed controls.
As you have prepared everything to test the compliance and risk states in previous labs, let start executing. This lab explains how to generate attestations for Data Protection requirements described in the Policy for the ACME Inc. Depending on attestations responses, controls status changes from draft to compliant or noncompliant, and has an effect on risk scoring (the more non-compliant controls, the higher the risk!).
-
Return to your Profile.
-
Click ACME Inc.
The current state of all controls should be in Draft. -
Click Generate DPIAs (Data Protection Impact Assessments, requirement from §35 EU GDPR).
The Controls now shows changes to Attest.There are nine attestations created. Certainly, with ServiceNow GRC application, you can also create just one attestation by different category or different attestations by different categories for different stakeholders!
-
In the Filter Navigator, search for, and then click, My Attestations.
-
Expand the Profile ACME Inc profile to see the full record.
You should now have nine attestations in the Ready to Take state. -
Take one attestation (1,2,and 3) and submit it. If asked to attach evidence, attach any (small size) file from your laptop.
You can also provide multiple attachments for the evidence. -
Go back to the Acme Inc. Profile (2) and then click Controls (3).
Depending on your response to that attestation, you should see the control status as Compliant or Noncompliant.
-
Return to the Dashboard (Compliance Overview) and then refresh your browser.
-
Note the GDPR Compliance status.
-
On the GDPR Compliance gauge, click the green part of pie chart (or red for non-compliant).
There are additional citations related to that particular control in Compliant/Non-compliant status. -
Return to the attestations and take remaining attestations.
-
Check the Controls status time-to-time and dashboards as in the previous steps (next example).
-
Check the Compliance Overview Dashboard.
Your dashboard might look different than what is shown below. You may need to refresh your browser window. -
After having 2-3 noncompliant controls, check the risk status as described in following steps:
b. Select Profile ACME Inc.
c. Under the Risks tab in related lists, select the Non-Compliance with Laws/Regulations risk.
d. In the Non-Compliance with Laws/Regulations risk window, select Scoring.
There is a new score for the risk. Because of some noncompliant controls, Calculated Score is now higher. You may have a different score than shown below.
-
After finishing all attestations, go back to the Dashboard to see the latest status of GDPR Compliance.
Your dashboard might be different than what is shown below. -
Go back to your risk - Non-compliance with Laws/Regulations; find it using the Your history icon.
-
Check the final risk scoring.
-
Click the Monitoring tab to see the control compliance metrics.
-
Scroll down and locate one of the noncompliant controls (if you have any) by clicking the Controls tab in the related list.
-
Click the Name of a noncompliant control.
-
In the related list, click the Issues tab.
An issue is automatically generated as a result of this noncompliant control. -
Open the issue record.
The record is in the New state in the Life Cycle (next example).Under the Details tab, the reason appears in the Description box. Now, an assignee can start working on resolving the issue (not part of this lab).
You can also check out the Task SLA information under related lists on this form.
This lab explains how to create and add new content to the Risk Dashboard to get visibility on high impact risks instantly.
-
In te Filter Navigator, search for Risks.
-
Click All Risks.
-
Filter the Risks records by Profile: ACME Inc. as shown below.
All the risks related to ACME Inc are listed (not in retired stage). Non-compliance with Laws/Regulations is also listed. -
Make the following changes to see these risks by Calculated Score in the Risk Dashboard.
-
Right-click the Calculated Score field and then select Pie Chart.
A new window opens.
-
Enter the report name in the Report Title (e.g., ACME Risks) field and then click Save.
-
On the Style tab, check the box Display data labels.
-
At the top-right of the report window, click Save and review the ACME Risks report.
-
Select Add to Dashboard by clicking on the Sharing button on the header bar.
-
Add to the report on your Homepage (Risk Overview) as shown below.
You are automatically directed to the Risk Overview homepage.
This lab illustrates further elements -- DPO Dashboard, Portal, etc. - of the overall GDPR Lab. The DPO dashboard gives you as a DPO (or controller or processor) full visibility and transparency on current GDPR exposure.