Leadership asks whether Vendor Risk, Business Continuity, and Privacy apps invent their own unrelated data models. What accurate purpose-level answer should the CIS-RC implementer give?
Select an answer to reveal the explanation.
Short Explanation
Think of Vendor Risk, BCM, and Privacy as extra rooms on the same house, not separate cabins in the woods. They lean on the same entity, control, and issue foundations as core IRM. Purpose-level awareness beats diving into a full TPRM specialty exam.
Full Explanation
ServiceNow’s extended IRM suite applications (such as Vendor Risk, Business Continuity, and Privacy) are positioned to reuse core GRC/IRM foundations—entities, controls, and issues—rather than maintaining wholly separate control universes. CIS-RC expects purpose-level awareness of that shared model, not deep CIS-TPRM implementation detail. Claiming they only use ITSM tables, replace Entity Framework, or sit outside IRM with zero shared objects is incorrect.