Policy and Compliance Implementation
About 25% of the CIS-RC exam — see all 7 domains.
Policy & Compliance Management (PCM) lets an organization create and manage policies, map them to external/internal mandates, define what "good" looks like, and continuously test that controls operate effectively.
The PCM content chain (memorize the order): Authoritative Source → Citation → Control Objective → Control → Control Test (and results).
- Authoritative Source. The mandate or document of authority — a regulation, standard, framework, law, or internal policy library (e.g., PCI DSS, ISO 27001, SOX, NIST). It is the "where the requirement comes from."
- Citation. A specific requirement/clause within an authoritative source (e.g., "PCI DSS Requirement 8.2"). Citations break a source into discrete, testable obligations.
- Control Objective. A statement of intent describing the desired outcome to satisfy one or more citations (the "what we want to achieve," e.g., "Access to cardholder data is restricted"). Control objectives map to citations.
- Control. The actual implemented safeguard/activity that satisfies a control objective for a given profile/entity (the "how, here"). Controls are generated when a control objective is scoped to profiles. A control is the testable, owned instance.
- Control Test. The procedure used to evaluate whether a control is operating effectively; produces control test results (pass/fail, with attestation, evidence, or automated indicator data). Failed/ineffective controls can spawn issues and remediation tasks.
Policies and policy exceptions. Organizations store corporate policies and procedures; users can request policy exceptions that route through approval workflow and carry expiration.
Compliance scoping. Control objectives are attached to profiles/entities (via Entity Scoping), which generates controls per in-scope entity. This is where Entity Scoping and PCM intersect — heavily tested.
Attestation and indicators. Compliance can be evidenced through attestations (manual sign-off) or indicators (automated tests against platform data / configuration). Continuous configuration monitoring lets controls be evaluated automatically and on a schedule.
Content packs / Common Controls. Pre-built citation and control-objective content (e.g., via the Unified Compliance Framework (UCF) Common Controls Hub) accelerates mapping many regulations to a deduplicated set of common controls.
Exam gotchas:
- Control = scoped instance; Control Objective = reusable definition. Don't swap them.
- Citation lives inside an authoritative source; control objectives map to citations.
- Scoping a control objective to profiles is what creates controls.
Sample questions from this domain
Three of the 75 in this domain, with the reasoning. The full set is in the question bank.
In Policy and Compliance Management, what is an authority document?
- A. A risk score calculation
- B. A source of requirements such as a regulation, standard, or framework that organizations must comply with ✓
- C. A user manual for the ServiceNow platform
- D. An incident resolution template
Why: An authority document represents an external (or internal) source of requirements such as a regulation, standard, or framework (e.g., PCI DSS, ISO 27001). It is not a platform manual, a risk score, or an incident template.
What is a citation in Policy and Compliance Management?
- A. A risk register entry
- B. A profile type
- C. A control test result
- D. A specific requirement or section within an authority document ✓
Why: A citation is a specific requirement/section within an authority document that controls can satisfy. It is not a test result, a risk register entry, or a profile type.
What is the relationship between control objectives and controls in Policy and Compliance Management?
- A. They are identical records with different names
- B. Controls are never linked to control objectives
- C. A control objective is a test result and a control is an authority document
- D. A control objective is a reusable statement of intent; controls are the specific instances generated/associated to profiles to meet that objective ✓
Why: Control objectives are reusable definitions of intent, and controls are the instances associated to profiles to fulfill them. They are not identical, the roles described in C are wrong, and controls are linked to objectives.