Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Verify the NIST RMF Use Case Accelerator

After installing the GRC: NIST RMF Use Case Accelerator, review the NIST RMF application structure, core content, and demo data, if selected during installation.

Before you begin

Note: Starting with version 10.1.0, the NIST RMF Use Case Accelerator will be supported only for customers who currently use the product. New and existing customers should consider using the GRC: Continuous Authorization Monitoring application. For details, Continuous Authorization and Monitoring.

Role required: admin

Procedure

  1. Navigate to All > User Administration > Roles and review the roles installed with the NIST RMF application.

    These roles contain nist_rmf in their names; for example, sn_irm_nist_rmf.security_officer. The roles are associated with NIST RMF application modules to provide access based on the user's role.

    Note: Use the basic NIST RMF user role is to access the application. This role contains the reader or user roles from the ServiceNow® GRC suite of applications.

  2. In the Application Navigator, type NIST RMF, and verify the application core content.

    Navigate toVerify
    NIST RMF > Content > Control ObjectiveReview the Policies and Control objectives installed for NIST RMF.
    NIST RMF > Content > Risk StatementsReview the Risk Frameworks and Risk Statements installed for NIST RMF.
    NIST RMF > Content > Test TemplatesReview the Test Templates installed for NIST RMF.
    NIST RMF > Content > Indicator TemplatesReview the Indicator Templates installed for NIST RMF.
    NIST RMF > Content > Attestation TypesReview the Control Attestation Types installed for NIST RMF.
    NIST RMF > Content > Assessment TypesReview the Risk Assessment Types installed for NIST RMF.
  3. Validate the application demo content, if loaded.

    Navigate toVerify
    NIST RMF > Impact AnalysisReview the sample Targets installed in the system for use with the NIST RMF application.
    User Administration > UsersReview the sample Persona users installed in the system for use with the NIST RMF application. The User IDs for these users end with .RMF and their names contain RMF.
    Policy and Compliance > Scoping > Profile ClassesPerform a search for profile classes with the Name field containing with NIST. Review their relationships by reviewing their roll up to field in respective profile classes.
    Policy and Compliance > Scoping > Profile typesPerform a search for profile types with the Name field starting with NIST RMF.
    Policy and Compliance > Policies and Procedures > All ControlsPerform a search for all controls referencing Control Objectives with a Source = NIST 800-53-r4.
    Risk > Risk Register > All RisksPerform a search for all risks referencing Risk Statements with a Source = NIST 800-53-r4.
    Audit > Audit Testing > Test PlansPerform a search for test plans with Test Templates that begin with NIST RMF.
    Policy and Compliance > Indicators > IndicatorsPerform a search for all indicators where Item.Content.Source = NIST 800-53-r4.
    Risk > Indicators > IndicatorsPerform a search for all indicators where Item.Content.Source = NIST RMF.
    Policy and Compliance > Issues > All IssuesPerform a search for all issues whereItem.Content.Source = NIST 800-53-r4.
    Risk > Issues > All IssuesPerform a search for all issues where Item.Content.Source = NIST 800-53-r4.
    Policy and Compliance > Remediation Tasks > All Open Remediation TasksPerform a search for all Remediation tasks where an issue identified on the remediation task hasItem.Content.Source = NIST 800-53-r4.
    Risk > Remediation Tasks > All Open Remediation TasksPerform a search for all Remediation tasks where an issue identified on the remediation task has Item.Content.Source = NIST 800-53-r4.

Parent Topic:NIST RMF Use Case Accelerator