Close
Thank you for your feedback.

Unified Compliance Framework (UCF) content

Unified Compliance Framework (UCF) content

Compliance administrators can download regulatory compliance guidelines from the Unified Compliance Framework (UCF) and transform selected data into GRC tables for authority documents, citations, and policy statements.

Note: For more information on Unified Compliance Framework (UCF), see https://www.unifiedcompliance.com/.

Compliance admins can filter the downloaded content, select the documents to use, and import only the content they want into tables for authority documents, citations, and policy statements. When UCF publishes quarterly updates, GRC determines which data in your system needs to be updated and displays side-by-side comparisons of the changes to make the process easier.

Authority documents in the UCF content are organized and mapped to their proper citations, which in turn are mapped to a common set of controls.

Warning: All data imported from UCF Authority Documents is read-only and must be protected. Do not customize the authority documents, citations, or policy statements on any UCF fields transformed into GRC tables.

The terminology between UCF and the GRC applications differ slightly. The differences are mapped in the following table.

Table 1. Terminology differences
UCFServiceNow
Authority DocumentAuthority Document
CitationCitation
ControlPolicy Statement
Control InstanceControl

UCF authority documents

Each Authority Document is preconfigured to map to its appropriate citations. When you import a UCF Authority Document the following are also included:

  • All Citations that reference the Authority Document
  • All common Controls that satisfy one or many Citations
  • The relationships between Controls, Citations, and Authority Document

UCF Citations

Citations are included as part of the UCF download. Each citation is mapped to an authority document. When you select an authority document to import, the citations are already included.

UCF Policy Statements

Policy statements are included as part of the UCF download. Each policy statement is mapped to an authority document. When you select an authority document to import, the policy statements are already included. UCF uses the term Controls to refer to Policy Statements. When you import UCF controls they are imported into the Policy Statement table.

Products > Business Management > Governance, Risk and Compliance; Versions > Helsinki