TechByte - What's new in Quebec - Security Operations
welcome to the security operations december 2020 store release video featuring quebec release capabilities in this video we'll be discussing some of the new innovations for both security incident response and vulnerability response and first let's start with security incident response now customers use remote detonation and sandboxes like crowdstrike falcon sandbox to determine the behavior of suspicious files but this can be a manual and laborious process we've added some enhancements to automatically submit observables from security incidents to crowdstrike falcon sandbox now this does require an additional license from crowdstrike but it saves security analysts a ton of time and effort next let's talk about our mssp platform integration with secureworks now many mana service security providers try saying that five times fast or mssps experience the challenge of syncing secure works comments with security incident response reports or work notes making it more difficult to map incident tickets and event fields the new integration with secureworks eliminates these challenges and allows mssps to ingest incidents from secure works and automate the process in security incident response next let's talk about how security teams are struggling to understand their adversary's intent when dealing with security incidents and may incorrectly prioritize these incidents without this information in this release we've added support for the mitre attack framework attack stands for adversarial tactics techniques and common knowledge a knowledge base of cyber attack tactics and techniques used as a foundation for the development of specific threat models and methodologies this new capability maps incidents to the miter attack framework to provide advanced context on attacks and help reduce the overall attack surface shifting our focus to vulnerability response let's start with how customers and stakeholders often spend significant time identifying assets and their corresponding owner and how this can be particularly stressful if vulnerabilities are critical with vulnerability assignment recommendations we apply machine learning to an organization's unique unstructured vulnerability and asset data to drive ownership predictions the feature learns from ongoing assignment selections thus improving recommendations as the organization's assignment process matures this capability also reduces time to identify owners in large environments let's take a minute to look at this capability in action so let's start the demonstration by looking at this top vulnerability group we can see that the assignment group has already been set the system chose the unix support group and it's going to do that based on a variety of different variables that the customer can configure so things like who the asset owner is for example is one piece if it's a soft piece of uh software it's an application uh that they're using it can be the application owner etc and if i'm not happy with the group that it's automatically been assigned i can just click this light bulb and it will show me the other group recommendations and as well the average confidence score so it's learning so the system is actually going to be learning how to better make these assignment recommendations and then give you confidence scores uh for the other groups that could be assigned to these vulnerability groups so that's a quick look at vulnerability assignment recommendation that's coming in the december 2020 store release given the growing interest for vulnerability response tenable and servicenow are offering an additional option for integrating tenable's data feeds into servicenow vulnerability response the new application vulnerability response for tenable developed and supported by servicenow was built using servicenow's best practices and validated by tenable to meet complex customer requirements the app provides our joint customers with a new option to establish and manage their i t security workflows while ensuring they still have insights they need to execute on a risk-based approach for vulnerability management and finally let's discuss an exciting new innovation for vulnerability response application vulnerability management ensures application vulnerabilities are prioritized alongside infrastructure and configuration vulnerabilities reflecting the rise in breaches traced to application vulnerabilities customers will gain improved collaboration between the security and development organizations for faster remediation and lastly it integrates with veracode to scan for dast or dynamic application security testing results to determine the riskiness of a vulnerability enabling vulnerability teams to centralize all of the data for full visibility into vulnerability exposure and then orchestrate the remediation workflow let's take a look at application vulnerability management in action so to start we can see that there are some new dashboards that are available for application vulnerability management this first one the tab is going to show the security posture for application vulnerabilities it's going to show things like the application vulnerability items unassigned items the distribution of criticality for the vulnerability vulnerable items uh application vulnerable items by age etc uh we can also see the remediation trends in the organization so as a vulnerability manager i'm going to want to be able to see uh for example the mean time to remediate an application vulnerable item so how long is it taking me to actually remediate these application vulnerabilities when they're discovered and then finally the scoreboard so how are the applications doing uh how are the business units doing in resolving their applications so that's a a look at the a quick look at the uh the dashboards now let's take a look at the data that's imported from the application vulnerability scanner so in this case it's veracode and we're going to take a look at one of the application vulnerabilities and we can see there's a lot of similar information that we see on the infrastructure vulnerable items so those vulnerable items that we're pulling in from places like tenable and whatnot so it's gonna assign it a risk score a remediation target uh what the actual vulnerability is as well as the actual application release the release module the location of the specific application as well as additional information like uh what what is a brief summary of what's going on and a link back to the actual vera code application vulnerability it'll also automatically do an assignment for this application vulnerability so in this case it's the team angels so that development team is going to be notified of the application vulnerability that was discovered on the uh the xero online banking application and it will get tell them this is a critical application vulnerability that needs to be resolved so that's a brief look at application vulnerability management that's coming in the december 2020 store release that was a quick look at the december store release for security operations if you'd like to learn more please visit us at www.servicenow.com security operations thank you
https://www.youtube.com/watch?v=zV9Gu4ESlqk