Common Elements and Extended Capabilities
CIS-RC · 25 questions
- A county wants newly discovered critical business applications in the CMDB to become GRC entities without weekly spreadsheet imports. What integration pattern should the implementer use?
- A municipal compliance issue needs a change window and assignment group that already live in ITSM for a firewall rule fix. How should IRM touch ITSM without turning the item into an ITSM-process exam?
- A hospital access-review KRI must show whether privileged AD groups still match approved membership. Where should those membership signals feed?
- A utility risk owner wants open critical findings from security tooling to nudge a ransomware residual indicator—without redesigning the item as a CIS-SIR or CIS-VR configuration exam. What is the appropriate IRM use of that data?
- Auditors ask control testers at a county clerk's office to attach the authoritative SOP PDF from a document repository rather than email attachments. What integration pattern supports that?
- A regional health district is starting Policy and Compliance and wants a fast baseline of ISO-style citations and common control objectives. What should they install?
- A city must show HIPAA, state privacy, and PCI-aligned obligations but wants fewer duplicate control objectives to test. How do common-controls content packs help?
- Before a content pack's hundreds of citations are scoped to every production civic entity, what should the GRC team do?
- When a framework version updates and the publisher revises dozens of citations, what is the preferred IRM maintenance approach versus hand-editing thousands of rows?
- Executives at a port authority ask for GRC posture—open issues, control failures, residual risk—on the same platform reporting they already trust. What capability addresses that purpose?
- A GRC admin needs overdue control-test owners at a school district to get email notifications without writing a scripted application. Which platform capability fits at configuration depth?
- Compliance analysts, risk owners, and auditors at a municipal hospital each need role-appropriate modern UI experiences rather than only classic list forms. What platform capability should the implementer emphasize?
- A new state privacy bill moves from proposed to signed and then effective. What should Regulatory Change Management in IRM emphasize for the county privacy office?
- After a regulatory-change record adds a new citation, who should decide whether existing controls already cover it?
- A standard revision publishes and several authority-document sections change. What should the GRC team do in IRM?
- A state privacy regulation becomes effective next quarter, and the CIO wants a list of which city departments and systems are in scope before briefing council. In ServiceNow IRM Regulatory Change Management, what should the GRC lead use?
- Control tests, risk responses, and audit fieldwork all surface remediation work for the same utility. How should the IRM design treat those remediation items?
- Several encryption and access controls for a county EHR need recurring evidence from the same system owners. Which common IRM capability should the implementer rely on?
- The risk office wants measurable signals on both a payment-card control and a fraud risk for the transit authority. What IRM common object fits that need?
- Leadership asks whether Vendor Risk, Business Continuity, and Privacy apps invent their own unrelated data models. What accurate purpose-level answer should the CIS-RC implementer give?
- A municipal IRM rollout spans Policy and Compliance, Risk, and Audit. How should roles and groups be patterned?
- A hospital wants encryption-at-rest indicators to re-evaluate every week instead of waiting for quarterly attestations. What should the implementer configure?
- A continuous monitoring indicator for backup success fails mid-quarter for the water utility SCADA support entity. What should happen next in a well-designed IRM setup?
- A county compliance program already runs automated encryption indicators and still needs owners to confirm process controls that cannot be fully instrumented. Which assurance design fits?
- Noisy civic telemetry keeps flipping a fraud KRI between green and red every few hours, and the risk committee is ignoring alerts. What should the implementer do?