A new compliance analyst treats a published policy PDF as identical to a control in ServiceNow IRM. What distinction should be corrected?
Select an answer to reveal the explanation.
Short Explanation
The PDF says what leadership wants; the control is the living lock on the door—owned, scoped to a place, and testable. Reading the policy is not the same as proving the control.
Full Explanation
In IRM terminology, a policy (or policy document) expresses governance intent and requirements. A control is a scoped instance of a safeguard on an entity, with ownership and testing. Conflating the document with the implemented control breaks the content chain from authority and objectives down to evidence.