Edgile Releases ArC Q1 2022 Update for ServiceNow
By Giovanni Sparacio
Last week, Edgile, the leading cyber risk and regulatory compliance consulting firm and ServiceNow Elite partner, announced the Q1 2022 release of its Automated Regulatory Compliance (ArC) Content Service for ServiceNow.
Edgile’s award-winning ArC service delivers more than 650 harmonized laws, regulations and industry standards and automatically loads them into ServiceNow IRM.
The Q1 2022 report includes actionable information on mandates and precedents, enabling an up-to-date risk and compliance readiness posture that is proactive instead of reactive. ArC subscribers also receive a quarterly summary of noteworthy regulatory news, risk trends and enforcement activities.
What’s new with ArC in Q1?
Edgile’s harmonized ArC Content Library now contains over 650 laws, regulations and best-practice frameworks. The Q1 2022 content update adds 14 new authoritative sources to the ArC Master Library across Edgile’s three core risk taxonomies—Information Technology Risk Management (ITRM), Operational Risk Management (ORM) and Enterprise Risk Management (ERM) requirements.
Additions to the ArC Master Library for this quarter include:
A package of Cybersecurity Maturity Model Certification (CMMC) sources that provide a framework model overview, plus guidance for conducting both self-assessments and formal assessments that focus on CMMC Level 1 and CMMC Level 2, including:
- Cybersecurity Maturity Model Certification (CMMC) v2.0
- Cybersecurity Maturity Model Certification (CMMC) Self-Assessment Guide – Level 1 v2.0
- Cybersecurity Maturity Model Certification (CMMC) Assessment Guide – Level 2 v2.0
A series of NIST sources that address standardized approaches to improve organizational security, privacy and risk management postures, including:
- NIST SP 800-160 Vol. 2 Rev. 1 – Developing Cyber-Resilient Systems: A Systems Security Engineering Approach
- NIST SP 800-213 – IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements
- NIST SP 800-213A – IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog
- NIST SP 800-53A r5 – Assessing Security and Privacy Controls in Information Systems and Organizations
Additional Center for Information Security (CIS) Benchmarks sources, including:
- CIS Kubernetes Benchmark v1.4.0
- CIS Amazon Linux Benchmark v2.1.0
A set of financial-focused sources that aim to establish and operationalize security controls to reduce information security risks and improve organizational risk postures, including:
- Society for Worldwide Interbank Financial Telecommunication (SWIFT) Customer Security Controls Framework v2022
- National Automated Clearing House Association (NACHA) Operating Rules – 2021 – Section 1.6 Security Requirements
- 16 CFR Part 314 – Standards for Safeguarding Customer Information
A pair of sources that expand consumer protection requirements vis-à-vis organizational data privacy and debt collection requirements:
- Brazilian General Data Protection Law
- Fair Debt Collection Practices Act (FDCPA)
Managing regulatory changes with Edgile ArC apps
Included in the ArC Content Service subscription is the Built on Now® Edgile Regulatory Change Management application. The solution provides a closed-loop process to surgically identify necessary changes to policies, standards, and controls across the organization based on new statutes, regulations, and standards. Intelligent automation and sustainment workflows are leveraged to load the desired regulatory content changes into ServiceNow IRM using an easy-to-navigate IT risk management framework.
The ArC Content Service is maintained by Edgile’s compliance experts in PCI DSS, Sarbanes Oxley, FFIEC, GLBA, FRB Reg A-YY, HIPAA, Privacy, FDA, NERC CIP, and more. ArC monitors federal regulatory amendments and state privacy laws, including state sources for personal information protection, security breaches, data sharing, identity theft, and notification.
ArC subscriptions are available on a paid annual basis for the following 21 verticals: Medical Device Manufacturer, Pharmaceutical Life Sciences, Healthcare Provider, Healthcare Provider + Research, Healthcare Payer, Healthcare Payer + Medicaid, Financial Services – Banking, Financial Services – Banking and Broker/Dealer, Insurance – Property and Casualty, Insurance – Property, Casualty and Life, Casino Gaming, Utilities, Oil and Gas, Manufacturing, Technology, Retail, Government, Media, Transportation, Real Estate, and Privacy.
ServiceNow IRM Quick Start Packages
ArC Content is the backbone of Edgile’s comprehensive ServiceNow IRM Quick Start packages. Quick Starts help clients avoid the costs of integrating content with ServiceNow, and the expense (both time and money) of continuously monitoring, updating and operationalizing regulatory changes.
For details on ArC ServiceNow apps and solutions, or if you want to know if a particular regulation in your industry is covered, please contact Edgile’s Risk and Security team.
Accelerate and automate your risk and compliance management program with ServiceNow edgile-servicenow-automated-regulatory-compliance-arc-apps
Enable ServiceNow Risk and Security solutions within a matter of weeks Managing governance, risk and compliance in highly-regulated markets using manual processes requires significant effort to realize value and achieve a truly integrated risk and compliance foundation. Edgile-ServiceNow-QuickStarts
Connect with Edgile to get started
For details on how to optimize your risk and security programs, please contact your Edgile representative.