A consultant proposes a separate ‘compliance-only CMDB’ so IRM never touches the enterprise CMDB. What should the implementation lead answer?
Select an answer to reveal the explanation.
Short Explanation
Two maps of the same city that disagree are worse than one good map. IRM should use the shared entity framework tied to trusted enterprise sources—not a shadow compliance CMDB that drifts the moment IT updates reality.
Full Explanation
IRM’s entity framework is designed to scope policies, risks, and audits against a consistent set of organizational and technical objects, commonly sourced from CMDB/org data. A parallel compliance-only CMDB creates divergence, duplicate maintenance, and conflicting scope. The architecture answer is shared entities, not a second inventory universe.