Control Objectives: Periodic Review

No control objectives match the current filters.
Create/maintain System Documentation
SNow
State: Published
All lifecycle deliverables/artefacts are documented.
Define Backup & Restore procedures
SNow
State: Published
Documented Backup & Restore procedures exist and are tested on a regular basis.
Define Data Archiving
SNow
State: Published
Process for accessing and retrieving of archived data exists (if required). NOTE: only applicable if data from this system is archived into an archive.
Define Disaster Recovery (if applicable)
SNow
State: Published
Documented Disaster Recovery procedures exist and are tested/exercised on a regular basis.
Define Key Roles
SNow
State: Published
All key roles and responsiblities for the system are defined and assigned and are trained in the relevant CSV procedures. Key roles: - Business Process Owner - System Owner
Define Service Agreements
SNow
State: Published
Adequate Service Agreements are established with internal and external suppliers.
Define Training Requirements
SNow
State: Published
Training Requirements for the users prior to system access are defined
Define applicable operational support processes & procedures
SNow
State: Published
The applicable operational support processes & procedures are defined in the Validation/Qualification Registry and/or the Operational Support Plan
Execute Problem Management
SNow
State: Published
Problems are monitored and resolved following effective procedures.
Follow-up on Previous Corrective Actions
SNow
State: Published
Corrective actions from a previous Periodic Review, a Validation Report or performed internal audits and external inspections are followed up and closed
IT Security Checklist is fully assessed
SNow
State: Published
The IT Security Checklist attached to this control is completed
Perform Audit Trail Review
SNow
State: Published
An Audit Trail review process exists and is executed, if needed based on a documented assessment.
Perform Change Management
SNow
State: Published
Changes are implemented following effective procedures.
Perform System Performance Monitoring
SNow
State: Published
The performance and availability of the CS application, server(s), network, security, and other supporting infrastructure is monitored as part of day-to-day operations.
Perform System Risk Assessment (SRA)
SNow
State: Published
SRA kept up-to-date in regards to intended use of the system and resulting controls are implemented as needed.
Perform User Access Review
SNow
State: Published
User access of End-users and IT technical personnel, including privileged users, is reviewed on a regular basis.
User accounts and the associated permissions should be reviewed regularly
SNow
Classification: ProtectState: Published
User accounts and the associated permissions should be reviewed regularly
Graph Explorer