A tax authority maps SOX, NIST, and local statute citations to one privileged-access control objective for the tax system. What should the compliance implementer configure?
Select an answer to reveal the explanation.
Short Explanation
Think of one lock that satisfies three building codes—you do not install three identical locks side by side. Map those citations onto the same privileged-access control objective and let one control carry the shared intent. Cloning a control per citation just multiplies busywork without changing the safeguard.
Full Explanation
In ServiceNow Policy and Compliance, citations from authority documents map to control objectives, and controls generate from those objectives for in-scope entities. Mapping multiple related citations to one privileged-access control objective preserves many-to-one traceability while avoiding duplicate control designs. Creating a separate objective per citation when the safeguard is identical produces redundant controls and testing overhead. Knowledge articles and deleted citations do not establish examiner-ready citation-to-control linkage.