
ServiceNow
Access
Task Management
Mycroft reads ServiceNow change requests, approvals and incident records as evidence for change management and incident response.
Change requests carry approval history and incidents carry priority and SLA measurement. Mycroft tests that the approver was distinct from the requester and that approval preceded the implementation window.
How Mycroft connects to ServiceNow
- How it connects
- You authorize Mycroft against your ServiceNow instance.
- What Mycroft can access
- Read-only user and record data from the tables in scope.
Which controls ServiceNow evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from ServiceNow to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from ServiceNow |
|---|---|---|---|
| SOC 2 | CC8.1 | Changes are authorized, approved and tested before implementation. | Change request records with type, risk assessment, approval history including CAB decisions, planned implementation window and closure code. |
| SOC 2 | CC7.3 | Security events are evaluated to determine whether they constitute incidents. | Incident records with priority and impact classification, and the elapsed time from creation to triage. |
| SOC 2 | CC7.4 | Incidents are contained, remediated and closed. | Incident assignment history, resolution notes, resolution timestamp and SLA attainment against your response targets. |
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Role and group membership showing who holds approval authority and administrative rights in the instance. |
| ISO 27001 | A.8.32 | Changes are controlled through a formal change management process. | Change request lifecycle records demonstrating that the approver was distinct from the requester and that approval preceded implementation. |
| ISO 27001 | A.5.24 | Incident management responsibilities and procedures are established. | Incident category and assignment group configuration, with the routing history for each incident. |
| ISO 27001 | A.5.26 | Incidents are responded to in line with documented procedures. | Response and resolution timestamps per incident, measured against the SLA definitions configured in the instance. |
| HIPAA | §164.308(a)(6) | Security incident procedures identify, respond to and document incidents. | Security-categorised incident records with response actions and outcomes documented for each. |
What Mycroft collects automatically
Gathered from ServiceNow on a schedule, dated and stored against the controls above.
- Change requests with risk classification, approval history and implementation windows
- CAB approval records showing approver identity and decision timestamp
- Incident records with priority, impact, assignment history and resolution timestamps
- SLA attainment data measured against configured response targets
- Problem records linking recurring incidents to root cause
- Role and group membership showing approval authority and admin rights
Manual work this removes
The tasks that disappear from someone's quarter once ServiceNow is connected.
- Running ad-hoc reports each audit to extract change and incident samples
- Demonstrating manually that requester and approver were different people
- Compiling SLA attainment figures for the incident response control
- Assembling the list of who holds approval authority from group membership
ServiceNow and Mycroft: frequently asked questions
What ServiceNow access does Mycroft need?
How does ServiceNow evidence separation of duties in change management?
Can Mycroft use ServiceNow for incident response evidence?
Does this work with our customised ServiceNow instance?
We turn the compliance nightmare into a dream
Talk to us


