logo

NJP

Continuously Monitor Your Entire Attack Surface

Import · Jun 02, 2021 · video

the ability to continuously monitor risk across the entire attack surface in an organization has long been the dream in this video we'll show you exactly how servicenow is making that dream a reality now this presentation may contain forward-looking statements that reflect the current beliefs of servicenow and are based on current information available these forward-looking statements should not be relied upon in making purchasing decisions risk management can be a tricky process first risk managers need to understand the areas of risk and determining that can be a very laborious and manual process they also need to know when critical controls fail and they need to know that now and finally remediating risk requires more than just the risk management team it requires cooperation from security i.t hr and other groups within the organization in this demonstration we'll take a look at how continuous controls monitoring works using the example of vulnerability response we'll start this video as the risk manager persona now in the morning the risk manager is going to come in and look at the risk overview dashboard this dashboard allows them to have a wealth of information that allows them to do their jobs most effectively things like risks by category so they can see the different risks that are laid out for them in this dashboard they can also get information around the impact and likelihood of the different risks in the organization we even have at the top the different risks by category so i can see that there's a new high risk this was two yesterday it's gone up to three so if i click into this i can see that there is a new risk against my online payment services clicking into that i can see that it is a loss of confidentiality it's been triggered by one of my continuous controls now it gives me information about the owner the profile that's being used as well as things like the calculated score that was calculated based on both the inherent and residual risk now scrolling down i can see information about the indicator we can see that this indicator shows that it is around a vulnerability that is impacting the confidentiality for a critical service we can see that it's being collected daily and that the last result passed is false meaning that a new vulnerability was discovered on this particular system so we can see that there's the collection frequency and we can see that the last time it was collected it triggered a false reading and it automatically generated an issue this means that i need to inform the vulnerability manager that a new vulnerability on a critical service was discovered let's switch over to that persona next moving over to the vulnerability manager when they come in in the morning they'll often look at the vulnerability management dashboard which allows them to have a lot of the information they need in order to do their jobs most effectively things like the number of vulnerable items and the trend lines for that the number of vulnerable configuration items so obviously these are going to be different because they can have multiple vulnerabilities across the different configuration items in their organization they can also see the number of vulnerability groups that are currently being handled by the organization and then you can see the things like vulnerable items by risk rating vulnerable items by age etc now what we want to do is look at the vulnerability group for the specific vulnerability that's targeting the asset in question so we can see that the vulnerability group has a lot of the information that we need in order to effectively manage the vulnerabilities on the particular systems in question so to review a vulnerability group is a collection of vulnerable items which are vulnerabilities that are found on configuration items within the organization now it's automatically been assigned a risk rating as well as a risk score and a remediation target date which we have missed so you can see that it shows that the target's been missed it shows the assignment group and it's also got a short description as well as a longer description and it shows the vulnerability that is affecting these particular vulnerable items we can see that there are three vulnerable items out of the total number of 30 that have been detected that are still unpatched so 90 of them have been patched which is good we could actually see the specifics around that down here but what i want to point to are the preferred solutions so the preferred solution is automatically going to be downloaded by servicenow vulnerability response in order to associate the patch information with the vulnerability in question we can see information about the specific vulnerability but importantly it gives you details around the solution as well as a link to actually download the patch so you can then deploy that through your patch management solution now in order to do that we're going to go ahead and create a change request so we've created the change request and it shows that it's going to apply to all vulnerable items in this group if i want to split these out let's say i have a large number of vulnerable items and i want to split those between two different teams or more i can do that through the applies to i can change this to an emergency change request since this is affecting a a critical system i'm going to change this to an emergency change request and i'm going to set the plan end date to 24 hours since there's only three systems that we need to apply the patch to this should give the patch deployment team enough time to test and then deploy those patches out now you'll note that we're going to have the information automatically pulled through in the change request around the vulnerability in question as well as the deployment plan to be able to go ahead and send that patch out so download it where to download it and then how to deploy it up to those systems once the patch has been applied it will change the change request to we'll change that to schedule so we're going to schedule that change request we'll say we're going to implement the patches to the systems and we'll note that it's now in a review state we'll go ahead and close that and when we close the change request note that it automatically updates the vulnerability group to show that it is now resolved so all of the patches have now been applied to the systems that had been missed the first time around let's switch back to the risk management dashboard and see what that looks like now that the patches have been applied to the systems in question we can see that the high risk has gone back down to two which means that we are in good shape in this video you saw how continuous risk monitoring allows you to identify areas of risk in the organization and then calculate the business impact for those risks then you can continuously monitor and alert when controls fail and finally you're able to surface that data for risk management and executive staff in real time you also saw how we were able to manage the vulnerabilities through the life cycle from discovery all the way through to remediation using servicenow vulnerability response if you'd like to learn more about these products please visit us at www.servicenow.com thank you

View original source

https://www.youtube.com/watch?v=wxpDjYdLp1g