ServiceNow logo

ServiceNow

Access
Task Management

Mycroft reads ServiceNow change requests, approvals and incident records as evidence for change management and incident response.

Change requests carry approval history and incidents carry priority and SLA measurement. Mycroft tests that the approver was distinct from the requester and that approval preceded the implementation window.

How Mycroft connects to ServiceNow

How it connects
You authorize Mycroft against your ServiceNow instance.
What Mycroft can access
Read-only user and record data from the tables in scope.

Which controls ServiceNow evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from ServiceNow to satisfy it. Collection runs on a schedule and every result is timestamped.

ServiceNow compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from ServiceNow
SOC 2CC8.1Changes are authorized, approved and tested before implementation.Change request records with type, risk assessment, approval history including CAB decisions, planned implementation window and closure code.
SOC 2CC7.3Security events are evaluated to determine whether they constitute incidents.Incident records with priority and impact classification, and the elapsed time from creation to triage.
SOC 2CC7.4Incidents are contained, remediated and closed.Incident assignment history, resolution notes, resolution timestamp and SLA attainment against your response targets.
SOC 2CC6.1Logical access controls restrict access to information assets.Role and group membership showing who holds approval authority and administrative rights in the instance.
ISO 27001A.8.32Changes are controlled through a formal change management process.Change request lifecycle records demonstrating that the approver was distinct from the requester and that approval preceded implementation.
ISO 27001A.5.24Incident management responsibilities and procedures are established.Incident category and assignment group configuration, with the routing history for each incident.
ISO 27001A.5.26Incidents are responded to in line with documented procedures.Response and resolution timestamps per incident, measured against the SLA definitions configured in the instance.
HIPAA§164.308(a)(6)Security incident procedures identify, respond to and document incidents.Security-categorised incident records with response actions and outcomes documented for each.

What Mycroft collects automatically

Gathered from ServiceNow on a schedule, dated and stored against the controls above.

  • Change requests with risk classification, approval history and implementation windows
  • CAB approval records showing approver identity and decision timestamp
  • Incident records with priority, impact, assignment history and resolution timestamps
  • SLA attainment data measured against configured response targets
  • Problem records linking recurring incidents to root cause
  • Role and group membership showing approval authority and admin rights

Manual work this removes

The tasks that disappear from someone's quarter once ServiceNow is connected.

  • Running ad-hoc reports each audit to extract change and incident samples
  • Demonstrating manually that requester and approver were different people
  • Compiling SLA attainment figures for the incident response control
  • Assembling the list of who holds approval authority from group membership

ServiceNow and Mycroft: frequently asked questions

Read-only user and record information from the tables in scope. The exact table scope depends on the instance.
From the records themselves. Each change request carries a requester and an approval history with the approver's identity and decision time. Mycroft tests that the approver was distinct from the requester and that approval preceded the implementation window. Those are the two things an auditor checks under SOC 2 CC8.1 and ISO 27001 A.8.32.
Yes. Incident priority, assignment history, resolution notes and timestamps evidence SOC 2 CC7.3 and CC7.4, ISO 27001 A.5.24 through A.5.26, and HIPAA §164.308(a)(6). Where SLAs are configured in the instance, attainment is read directly rather than recalculated.
Generally yes. The integration is configured against the tables and fields your instance uses, so a ServiceNow administrator is normally involved in connecting it. Custom change types and incident categories are mapped during onboarding so the evidence reflects your process rather than a default one.

We turn the compliance nightmare into a dream

Talk to us