A CMDB owner asks how IRM relates technically to configuration items in a regulated city environment. Which explanation is correct?
Select an answer to reveal the explanation.
Short Explanation
Entities are the GRC name tags hanging on real org and CMDB objects—not a second mystery inventory. When those source records are clean, risk and control scoping stay trustworthy. Junk in the CMDB shows up as junk in compliance coverage.
Full Explanation
IRM entities commonly source from or reference CMDB CIs and organizational structures so policies, risks, and audits attach to the same real-world objects the platform already tracks. That linkage means GRC quality depends on CMDB and org-data quality. Entities are not free-text silos, automatic audit engagements, or a transfer of CMDB ownership to audit.