A county compliance program must apply policies to IT assets and to non-IT objects such as business processes and physical facilities. How should entity architecture be designed?
Select an answer to reveal the explanation.
Short Explanation
Policies do not only hug servers—they hug clinics, cash-handling processes, and buildings too. Civic GRC needs an entity model that can hold those non-IT objects alongside IT assets. If the framework is IT-only, half the city’s real obligations never get a home.
Full Explanation
IRM entity architecture is not limited to configuration items. Civic and regulated programs routinely govern processes, facilities, and other non-IT objects alongside applications and infrastructure. The model should therefore include entity types for those objects so policies, control objectives, and risks can scope correctly. IT-only entity designs leave significant compliance obligations outside the framework.