After ServiceNow and ZenGRC are connected, you can create and manage audits inside ZenGRC while requests for audit information show up in visual task boards inside ServiceNow. This documentation outlines that process.
TIP
Existing audits cannot be converted to ServiceNow. The option can only be selected during the creation of a new audit after the ZenGRC and ServiceNow integration is complete.
Step 1: Adding Basic Audit Information
To create a ServiceNow audit, complete the following steps:
In the left-hand navigation, click New | Audit.
Complete the fields. If you prefer to have all controls available for selection in Step 2, then leave the Related Program field empty.
Select ServiceNow, in the Managed in drop-down. The audit will be represented as a guided visual task board in ServiceNow, with each request shown as a task.
To access comments and attachments added by ServiceNow users from within ZenGRC, click the Synchronize comments and Synchronize attachments toggles. In most cases, customers will want to enable both toggles. However, they default to disabled in case there are privacy or security concerns around bringing this information into certain audits. Note that if the toggles are enabled at any point during the audit, comments and attachments submitted prior to enabling the toggles will become accessible within ZenGRC.
The majority of Step 3 follows the general instructions for importing requests into any ZenGRC audit. The differences are described below.
The requests CSV import template for ServiceNow-managed audits differs from the CSV import template for ZenGRC-managed audits, so be certain to use the ServiceNow-specific CSV import template when importing ServiceNow requests. When an audit is designated as a ServeiNow audit, the CSV template provided in Step 3: Setting up Audit Requests will be tailored to ServiceNow.
The template supports the following user assignments for requests:
ServiceNow individual users can populate the Assigned To column.
ServiceNow groups can populate the Assignment column.
Use these users and groups together or separately on requests. If used together, be certain the user exists in the group assignment, as ZenGRC does not validate these combinations.
ServiveNow users adn assignment groups need to exist in ServiceNow, but they do not need to exist in ZenGRC.
Import the CSV as normal.
Click Import Data.
In our CSV example, requests are mapped to controls in the Mapped Controls column, which allows you to skip the mapping done after import. If this column is blank, you will need to map controls at this point.