Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Verify the NIST CSF Use Case Accelerator

After installing the GRC: NIST Cybersecurity Framework (CSF) Use Case Accelerator, review the NIST CSF application structure, core content, and demo data, if selected during installation.

Before you begin

Role required: admin

Procedure

  1. Navigate to All > User Administration > Roles and review the roles installed with the NIST CSF application.

    These roles contain nist_csf in their names; for example, sn_irm_nist_csf.security_officer. The roles are associated with NIST CSF application modules to provide access based on the user's role.

    Note: The basic NIST CSF user role is needed to access the application. This role contains the reader or user roles from the ServiceNow® GRC suite of applications.

  2. In the Application Navigator, type NIST CSF, and verify the application core content.

Navigate toVerify
NIST CSF > Content > Authority DocumentsReview the Authority Documents installed for NIST CSF.
NIST CSF > Content > CitationsReview the Citations installed for NIST CSF.
NIST CSF > Content > Control ObjectivesReview the Control objectives installed for NIST CSF.
NIST CSF > Content > Risk StatementsReview the Risk Frameworks and Risk Statements installed for NIST CSF.
NIST CSF > Content > Test TemplatesReview the Test Templates installed for NIST CSF.
NIST CSF > Content > Indicator TemplatesReview the Indicator Templates installed for NIST CSF.
NIST CSF > Content > Attestation TypesReview the Control Attestation Types installed for NIST CSF.
NIST CSF > Content > Assessment TypesReview the Risk Assessment Types installed for NIST CSF.
  1. Validate the application demo content, if loaded.
Navigate toVerify
NIST CSF > Orient TargetsReview the sample Targets installed in the system for use with the NIST CSF application.
User Administration > UsersReview the sample Persona users installed in the system for use with the NIST CSF application. The User IDs for these users end with .CSF and their name contains CSF.
Policy and Compliance > Scoping > Profile ClassesPerform a search for profile classes with the Name field containing with NIST. Review their relationships by reviewing their roll up to field in respective profile classes.
Policy and Compliance > Scoping > entity typesPerform a search for entity types with the Name field starting with NIST CSF.
Policy and Compliance > Policies and Procedures > All ControlsPerform a search for all controls referencing Control Objectives with a Source = NIST CSF.
Risk > Risk Register > All RisksPerform a search for all risks referencing Risk Statements with a Source = NIST CSF.
Audit > Audit Testing > Test PlansPerform a search for test plans with Test Templates that begin with NIST CSF.
Policy and Compliance > Indicators > IndicatorsPerform a search for all indicators where Item.Content.Source = NIST CSF.
Risk > Indicators > IndicatorsPerform a search for all indicators where Item.Content.Source = NIST CSF.
Policy and Compliance > Issues > All IssuesPerform a search for all issues whereItem.Content.Source = NIST CSF.
Risk > Issues > All IssuesPerform a search for all issues where Item.Content.Source = NIST CSF.
Policy and Compliance > Remediation Tasks > All Open Remediation TasksPerform a search for all Remediation tasks where an issue identified on the remediation task hasItem.Content.Source = NIST CSF.
Risk > Remediation Tasks > All Open Remediation TasksPerform a search for all Remediation tasks where an issue identified on the remediation task has Item.Content.Source = NIST CSF.

Parent Topic:NIST CSF Use Case Accelerator