Designers propose a second, audit-only catalog of controls that duplicates Policy and Compliance. What architecture guidance should CIS-RC favor?
Select an answer to reveal the explanation.
Short Explanation
Two control catalogs are like two conflicting street maps for the same city. Audit should ride the existing entity and control framework—and reuse tests—rather than inventing a parallel universe. One model, many uses.
Full Explanation
ServiceNow Audit Management is architected to reuse Entity Framework objects and control-related evidence from Policy and Compliance/Risk rather than maintaining a wholly separate control catalog. That reuse improves consistency and reduces duplicate testing effort. Cloning into audit-only tables, spreadsheet controls, or replacing entities with assignment groups fights that architecture.