Implementation Planning
About 10% of the CIS-RC exam — see all 7 domains.
Covers how to scope and deliver an IRM implementation: requirements gathering, identifying which applications (Policy & Compliance, Risk, Audit, Advanced Risk, Vendor Risk) the customer needs, phasing, data sources (CMDB, HR, vendor data) feeding profiles/entities, plugin activation, and roles.
Common roles: GRC Admin, GRC Manager, Risk Manager, Compliance Manager, Audit Manager, plus reader/user roles. Match the role to the application and least-privilege principle.
Now Create / best practices: scope narrowly first, use out-of-box content packs, design the profile/entity model early (it drives everything downstream), and plan integrations (CMDB, identity, ticketing) and reporting (Performance Analytics) up front.
Sample questions from this domain
Three of the 30 in this domain, with the reasoning. The full set is in the question bank.
During GRC implementation planning, what is the recommended first step before configuring entities and profiles?
- A. Build every risk statement in production
- B. Define the organization's GRC scope, objectives, and stakeholders ✓
- C. Delete the out-of-box roles
- D. Immediately import all available content packs
Why: Successful implementations begin by defining scope, objectives, and stakeholders so configuration aligns to business needs. Importing all content, building directly in production, or deleting baseline roles are premature and risky actions.
Which ServiceNow role is typically required to perform GRC administration and configuration tasks?
- A. catalog_admin
- B. knowledge_admin
- C. sn_grc.admin ✓
- D. itil
Why: The sn_grc.admin role grants administrative access to the GRC framework for configuration. itil, catalog_admin, and knowledge_admin govern other applications (incident/request, service catalog, knowledge) and do not provide GRC administration.
Which activities belong in the planning/design phase of a GRC implementation? (Choose two)
- A. Configuring the email server for a different application
- B. Upgrading unrelated hardware
- C. Defining the entity types and profile types to be used ✓
- D. Identifying authority documents and frameworks in scope ✓
- E. Closing all production incidents
Why: Planning should identify which authority documents/frameworks are in scope and define the entity types and profile types that structure the data model. Closing incidents, configuring unrelated email, and hardware upgrades are not GRC design activities.