GRC: Audit Management Flashcards
What is the recommended GRC module implementation order?
- Policy and Compliance, 2. Risk Management, 3. Audit Management
What additional functionality does Advanced Audit provide?
integrates with the PPM module to help plan engagements. Enhances engagements with the Cost Plan, Resource Plan and timecard functionality. Milestones and observations are also enhanced.
What does the engagements module allow?
Allows for the viewing and creation of engagements
What is the use for Milestones?
Milestones allow the tracking of engagement progress and contain Audit tasks for completion
What is the purpose of audit tasks?
They are added to milestones and track the progress towards that milestone
What is the purpose of Audit Universe?
It allows for the creation of Auditable Units which are based off of entities and help to scope the engagements
What is the scoping module?
It is a common module across all of the GRC applications for the creation of both Entity Types, Entity Classes, and entities
What is the purpose of sn_audit.glide.script.block.client.globals?
The audit module requires the use of Jquery to function; this system property must remain false for the audit module to work
What table does sn_audit_task extend?
sn_audit_task extends the planned task table
what is the purpose of the sn_audit_task table?
This is a generic task table for all of the audit module. sn_audit_control_test, sn_audit_interview, and sn_audit_walkthrough all extend from this table
What are the various options for loading content into the audit management module?
- Manual Entry/HTML
- Import Data
- Integrations with Content Providers
- Inclusion of certain Accelerator Content Packs, such as, NIST CSF, SOX content from ServiceNow
What is required for the approval of an Engagement?
All approvers that are added to an engagement need to approve in ServiceNow for it to move to the Follow Up state
What occurs if an approved engagement has no open tasks or items?
The engagement skips the Follow Up state and autocloses
What is the purpose of the sn_grc.enable_record_confidentiality system property?
This system property enables the confidentiality tab on engagement records and allows for the restriction of access to the records based on a list of allowed users
What is the default Knowledge base used to publish Audit reports?
sn_audit.knowledge_base