4
1.0.13
Yokohama
Standalone Application
ComplySyncATO is designed to enhance and automate compliance assessments within ServiceNow’s GRC module and the Continuous Authorization and Monitoring (CAM) framework leveraging Generative AI to Boost Security and Governance Controls for Cyber Risk Management. By integrating directly with ServiceNow, the application extends the CAM module by adding advanced automation for compliance evaluations, control implementation, and continuous monitoring.
- Compliance Checks: Automated AI analysis evaluates the control compliance levels and accurately determines the preliminary compliance statuses (Fully Implemented, Partially Implemented and Not Implemented). This supports audit readiness and accelerates the ATO process by identifying gaps early with minimal effort.
- ImportSSP: Automatically populates or modifies implementation statements for all controls (needed for control implementation) by extracting data from the SSP Baseline Template. This eliminates the need for manual data entry, ensuring faster control implementation, reduced workload, and improved consistency.
- ACAS Report Analysis: Loads and parses the Nessus scanner report post regular vulnerability scans to analyze new vulnerabilities, configuration drifts, and control gaps. Maps these to associated controls and updates compliance levels with justifications automatically, supporting continuous monitoring and compliance assurance after systems updates and code deployments.
This is the 'Initial Release' of ComplySyncATO to the ServiceNow Store for certification. ComplySyncATO automates compliance analysis by integrating with external AI compliance engines and vulnerability scanning tools. It supports:
- Importing SSP templates to update implementation details for security controls
- Executing AI-driven compliance checks on security controls
- Mapping results into the GRC: Policy and Compliance Management module for continuous control monitoring
- Middleware Installation
- MID Server
- GRC: Continuous Authorization and Monitoring (Version: 21.0.1)
- GRC: Continuous Authorization and Monitoring Workspace (Version: 21.0.1)
- System Import Sets (Version: 1.0.0)