Skip to content
Notifications
Clear all

Step-by-step: Creating a custom risk matrix that our CISO actually likes.

1 Posts
1 Users
0 Reactions
33 Views
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
Topic starter   [#13389]

Hey folks, data_shipper_joe here. I've been deep in our GRC implementation for the past year, and while I usually talk about moving data *into* ServiceNow, this time it's about making it work once it's there. Our CISO is... let's say "particular" about risk scoring. The out-of-the-box risk matrix in ServiceNow GRC just didn't map to how our org thinks about impact and likelihood.

After a few iterations (and some rejected prototypes 😅), we landed on a custom matrix that finally got a nod of approval. Here’s how we built it, focusing on the practical steps in ServiceNow.

First, we had to define our own scales. The default 5x5 matrix used generic terms. We needed something tied to our business processes. We created custom choices for 'Impact' and 'Probability' in the Choice Table.

We went to `System Definition -> Choice` and created new entries. For Impact, ours are:
- **I1: Regulatory Notice** (low)
- **I2: Operational Delay**
- **I3: Financial Loss = 40) rating = 'Critical';
else if (numericScore >= 25) rating = 'High';
else if (numericScore >= 10) rating = 'Medium';
else rating = 'Low';

return { score: numericScore, rating: rating };
})(impact, probability);
```

The hardest part wasn't the tech, but getting the business logic right. We sat with the security team and mapped real past incidents to the matrix to calibrate it. For example, a "P3: Possible" probability combined with an "I4: Reputational Damage" impact had to land squarely in the "High" risk category per our CISO's mandate.

Finally, we attached this new matrix to the relevant Risk tables and workflows. The beauty is that once it's set, all the risk assessments, issue intake forms, and reports just use the new scoring automatically.

The lesson? Don't be afraid to customize. The default configurations are a starting point, but tailoring them to your organization's language and risk appetite is what makes the tool powerful. Has anyone else gone down this path? I'm curious about how you handled the change management side when you introduced a new calculation model.

ship it


ship it


   
Quote