4/1 Ask the Experts: Explore Cybersecurity Accelerator Enhancements with ServiceNow and Credio
all right okay well um shall we go ahead and get started i think so we have a lot to cover today we've got a jam-packed hour um my name is teresa long the director of product marketing here at servicenow for the risk products and i'm very very happy to be joined by lal narayana sami for servicenow who is the director of product management and by i just messed up your last name who is the founder of credio um so let me just kick it off and then i will turn it over to lol and raj so they can really get into the details but before we do that i wanted to let you know that we are so excited that we have just released some new applications on the servicenow store one of which is updates to our cis accelerators and iso accelerators which we're going to talk about today we have a whole series of these quebec broadcasts that we're doing where we're demoing the new functionality so you all can see it the first one we actually did last week and that was around business continuity today we're going to be looking at our cyber security accelerators and i'm not going to get too much into this because lol and raj is going to tell you a lot more about this week please come back and join us we're going to be talking about regulatory change management we've added some really great features to that the ability to subscribe to rss feeds to be able to view impact the policy and risk statements to be able to view regulatory events in a series so we're putting things together and making it easier for you all and then tracking issues from within risk regulatory change management so that's really excited about that and then finally the last of our series is going to be happening on tax day in the u.s here which is our audit and policy and compliance so we're going to be talking about our advanced audit capabilities and as you know we had previously in our store release integrated with our project portfolio management application to add resources and to add um the uh costs this time now we've added timesheets to that so hoping you'll be able to manage your engagements more easily from within advanced audit and then some new scheduling advancements for our policy acknowledgements so those are the series that we've got of our ask the experts we hope that you mark your calendars for those and without any further ado i am going to turn it over to lol who is going to introduce you to some of the new features in our cyber security accelerator in more detail well why don't you go ahead and grab the screen and um take it away thank you teresa uh good morning and good evening all for joining us from different parts of the world my name is lal narayana swami i'm a director of product management at servicenow service knows risk business unit and joining me today is raj raghavan the founder and ceo of credio and both of us would like to take you through our recently launched accelerators for cis controls and what we are calling technology controls but the first series of uh regulations or best practices we cover and that is the iso 2702 so uh i will be providing an overview of accelerators and raj will actually take you through uh the the some tips techniques and suggestions on how best to take advantage of these accelerators and then we'll do some q a so with that i'm going to uh give you a bit of a preview about the accelerators as teresa mentioned uh we launched two accelerators one uh is called cyber security controls accelerator which is for the cis controls from the center for internet security and then the second one we launched uh is called the technology controls monitoring accelerator so the first phase of accelerator was released in october and we released a second phase very recently in march through the store and we also have an update coming in in june that will provide an operational status dashboard that helps you operate to pretty much implement and adopt these accelerators so with that i'm going to give you a quick overview of what these accelerators are in case customers are new to servicenow grc uh you can think of them as a servicenow pre-configured to address specific use cases so we have accelerators for socks nest risk management framework missed cyber security framework and of course we just launched the cis and the technology controls one so the idea is to provide whatever uh you need to operationalize on on a specific use case this would include things like content workflows in the case of cis we provided a policy the control objectives we also provide the indicator templates uh there are some reports and dashboards things like that other activators might have more predefined workflows like the ones that i've listed above for uh nist so so the idea is this is not meant to be a complete turnkey solution uh what we would like to do with these accelerators is to provide you a head start and on which you can you can build on and extend and add things as you need uh customers who have either the irm professional or irm enterprise packages are entitled to these accelerators so with that i'm going to uh jump ahead and talk a little bit about why we uh focused on why we decided to focus on cis and uh and an iso 2702 so these two frameworks are some of the most fundamental security frameworks and best practices and use it's always been on the list of most asked features from our customers and partners um so the cis is best and it's been uh variously known as cis top 20 sans top 20 it's it's been around for some time it's primarily helps organizations to arrive at a optimum security posture by observing uh specific controls in various areas and we will talk about what those areas are in a bit the iso 2702 also has a pretty storied history it basically defines what you need to implement what is called as an information security management system so together with iso 2701 and 2702 you can define and implement an isms so 2702 provides the security controls required to uh to adopt and implement an isms in your organization so the interesting thing about these two frameworks is since they're foundational they intersect with various other frameworks like cobit and various other requirements from various regulations as well like pci the privacy regulations like ccpa so if you are complying adopting and complying with cis or iso 2702 the chances are that you're meeting regulations uh i mean requirements and other regulations and best practices as well so that's one reason why we decided to support these two frameworks so increasingly uh cis is also being relied upon as a basic security framework for information security so many states federal agencies are requiring organizations that do business with the government or even the departments themselves within agencies and departments to adopt cis uh so you you're seeing more and more use of cis and iso of course is has been adopted worldwide okay so now uh what are our primary objectives with these accelerators so one is uh we want uh you to have a credible path to adopt these security best practices and actually bring about measurable improvements in your security posture the second aspect and and we'll touch upon it and raj will also cover this in his talk is how do you adopt these controls there are 195 controls in cis about 150 odd and iso 2702 so what is there a logic behind it right so we would like you to uh enable you to select and apply controls in line with your maturity and your organizational preparedness and progressively grow uh your uh your security maturity then last but not least we want to ensure that you fully leverage the power of servicenow grc all our itx technologies what we're calling is itx this includes everything from ip service management operations management security operations uh devops and and so on it business management and so on so the the idea is uh to use these different technologies to adopt these frameworks automate the controls and continue continuously validate and monitor compliance uh i'd like to talk a little bit about obviously these two frameworks have been around and uh and one of the things that i've come across in my experience and i've also heard from customers is is the challenges in adopting these frameworks and these vary across organizations and what we have attempted to do with these accelerators is to address specific challenges or impediments that have held back organizations from adopting them so the first one is organizations uh always are challenged in trying to understand what are the controls that matter to me right so this could be in line with maturity it could be in line with their resources the structure of their organization and things of that nature so what we have done at least on the cis side is to provide directional guidance in the form of implementation groups so this is a cis concept which we have operationalized in the accelerator where cis provides guidance on given an organization's maturity what are the controls that they should address first and then as they grow their maturity adopt others so our accelerator helps you in selecting and applying uh those controls the the second one is figuring out how to automate the controls so you may have a plethora of technologies um it could be from service now it could be from other external players some of them could be service partners uh so figuring out how to automate uh the technical control so there we have something called as an operational status dashboard which basically tells you what are the technologies you have in place and what you need further uh to automate them and we also tell you which of those controls have indicator templates defined and which of them have been activated and they're ready to use so you you get a lot of insight into your readiness and and as you as you progress it also tells you uh how you're doing as well uh validating controls at scale and providing data to internal external auditors this has been always a challenge because you have as i mentioned about 190 controls in cis not all of them are technical controls a good number of them are process oriented for which we have manual manual indicator templates but at least for the ones that are technical controls and for which we have mapped specific technologies the ability to have uh basic scripted and manual indicator templates uh which you can deploy and uh and automate uh validate compliance with scale and generate the evidence and the data required to measure your progress show it your internal and external auditors uh continuous monetary monitoring of control so you've implemented controls you're measuring compliance you've somehow reached some kind of a steady state and you want to ensure that you're continuously complying to those controls so how do you do that so this is where our basic and scripted indicator templates that we have provided to many of these uh iso cis controls help and the need to comply with multiple regulations and mandates right so organizations use usually if they're publicly traded have to comply with stocks if they have except credit cards with pci and so on so in addition they also asked the aspire to adopt some of these best practices so what should i focus on uh how do i meet these multiple uh requirements so that's why what we have done is we've taken these cis controls mapped them to various technologies provided indicator templates and we've also linked these indicator templates to associated ids in the unified compliance framework so thereby when you automate a control and validate validate compliance to it because of the linkage that ucf provides to a wide range of regulations and best practices you're able to assess ones and comply with many so we've tried to address a broad range of challenges that customers typically encounter when they adopt or when they attempt to adopt these frameworks so our accelerator has tried to address some of those key pains and uh and and bring about a proactive way for customers to adopt and see value from these uh accelerators all right so there's a quick overview on the accelerator both accelerators uh so the tech controls accelerator and the cis controls accelerator so in cis we have about 191 controls totally and they what we provide uh automated indicators for 55 of them and for iso that are iso 2702 there are 114 controls and we've automated 52 of them there are 52 automated indicators and one of the key things we have done and thereby addressing one of the panes of how to automate controls is we've we've studied these controls in detail and this is where we partnered with rod's firm uh we we looked at each control and mapped it to specific technologies from servicenow so for instance 55 of the controls are automated through uh city per seconds if you have vulnerability response configuration compliance and any of those incident response so you're able to automate 55 of those controls 18 controls are automated through it operations management products 16 come from our own risk management products 11 from it asset management 3 from devops and so on so anything that deals with system inventorying uh uh like hardware inventories software inventories so everything that you see under basic one like inventory and control hardware assets inventory and controller software assets vulnerability management secure configurations many of these controls are automated through various technologies uh from servicenow so if you go to the store download the app and activate it in our product immediately you'll see the authority document the citations control objectives and various other things associated with cis for iso because of licensing issues we're able to provide only the indicator templates which have been mapped to specific iso controls all right and this is my this is the operational status dashboard i was telling you about which will be uh coming out in june so what this does it lists the various controls and they're classified by the domain and implementation group so you can see the domain falls in multiple areas of cis some of them are basic some of them are foundational some of them are organizational and you can see the implementation groups so there are three implementation groups ig-1 ig-2 and ig-3 ig-1 is your most essential security controls that that you need to implement which serve as a foundation and then you add on the other implementation groups so for instance ig2 will also include ig-1 and ig-3 will include ig-1 and ig-2 thereby indicating a sort of a progressive sort of approach in improving your security posture raj will be discussing this more uh the practical applications of it so i will not discuss that uh further uh this is the part where things get very interesting so we are able to look at your servicenow instance uh and figure out what products that from servicenow that you have might will be useful in uh automating some of these controls so we list all the con technologies uh that you can potentially use to automate various controls so in this case the first one you see is called cis control 1.1 utilize an active discovery tool and here the product that you will need is configuration management which is cmdb cnbc discovery essentially so you notice the next field whether the technology is activated or not and we sense that and if you've deployed it and it's in use we we indicate that and then if you applied uh uh this uh control and and uh i mean if you if you decided to adopt this control objective rather and then you've decided to deploy controls uh then we show that as well if you have controls if you don't that shows up as false then the last bit of information is whether you have an indicator template type defined so that you can readily start monitoring validating and monitoring this control so in this case cis control 1.1 has a basic indicator defined already and the data for that comes from the table cmdb discovery so if you're starting out this is a great place to begin your uh begin your effort to see what are the various controls that you need to comply with look at your own preparedness uh resource levels maturity and decide on what level what implementation group that you want to adopt get a sense of what are the technologies that you need and from that what are the technologies that you have from servicenow because of the information contained here in and then decide on whether you want to start deploying or generating the controls for the various cis control objectives and then as you notice the availability of indicators then you can start indicator templates you can start generating indicators and start it start to perform your continuous monitoring so as long as data is available in these tables we instantly pick it up and use that for validation purposes so wherever there are we have not been able to define uh a basic or a scripted indicator we have provided manual indicator templates so you have fully automated coverage for for all these cis controls and many of the iso controls that we've mapped our technologies to so uh yeah this is just an example uh i i mentioned uh that that pretty much expands on what i said so you have here a control for asset inventory so you would require the cmdb as the technology for that that's available and we have an indicator template and that information is pulled from the table based configuration item so that's how you can take advantage of this operational status dashboard and here are some examples of a basic indicator that comes packaged this one is around maintaining detailed asset inventory and this is the satisfies control cis control 1.4 and that refers to the hardware cmdbci hardware table and this is an example of a scripted indicator uh where in this particular case it's an iso control that requires that you separate your development testing and operational environments this could be a great security control or a dell cyclops control so here we are referring to multiple tables so we've actually supplied a scripted indicator and uh the last slide i want to leave you with is the uh the asset ones comply with many point i made earlier where you can see you you see various uh cis controls and the types of indicators that that we've defined for them some of them are basic some of them are manual and so on and if you look at the basic ones you see the column are called related ucf ids so we've taken these indicator templates and mapped them to various related ucf ids so in the case of the example that i've highlighted the maintain asset inventory information indicator template can be used to satisfy multiple ucf controls and these ids in turn when it mapped to various regulations and best practices so not only are you monitoring compliance to cis control 1.5 but using the ucf relationship you're able to actually satisfy compliance requirements for various regulations and authority documents another thing that we've also done is to look at the commonality the intersection between cis and iso and we've identified those common controls and we've automated many of them as well so that i hope gives you a sense of what's in these accelerators i'm going to transition over to uh to raj now and raj will take you through uh the process of adopting these uh indicators and actually and and realizing value from them so raj over to you i'm gonna bring up your uh presentation thanks lal and thanks teresa and lisa um servicenow for giving us an opportunity um i think i want to spend a few minutes i think lal uh presented you know what the capabilities of the accelerators are and the thinking behind and uh we want to take i'd like to spend the next few minutes you know from our practitioner perspective if we were to adopt it have a customer adopted um you know how will they actually go about doing it and i think there are some basics we can drive in terms of you know you'll see some overlap because we want to take the same concept of these frameworks and really see how it can be practically um you know implemented so lal if you want to go to uh next few slides yeah the next one um yeah thanks again my name is raj raghavan um i am the founder of criteo we are a um advisory firm we focus on um you know cloud security compliance and in a minute we will talk uh we were recently um inaugurated for uh iso 2700 one for with a focus on pci hyphen shock and also uh we are on our journey to become a fedramp 3po and we just started our cmnc journey what does all that mean is we are very much in in the business of compliance but we also want to be able to focus on putting compliance controls from a security perspective from a data protection perspective so we take the approach of trying to put these guard rails these swim lanes in in in the changing landscape so if we go to the next slide um thanks so what we're going to talk today is really how can we leverage uh you know how can you as a enterprise leverage servicenow grc accelerator uh in your um environment today um what is why see iso iso but i'll take a different perspective why these two frameworks are interesting uh how do you reduce your security risk which is ultimately all our you know anything we want we adopt we invest and we want to implement we want to be able to you know reduce the security risk and certain things to watch for as you're implementing it next so today the changing landscape is shifting the paradigm shift that's coming up in security and it's based on why the business is going and everybody the covet has kind of accelerated the need to migrate to a public cloud remote workforce uh the whole concept of agile development the need to have daily updates you know um in your in your cloud environment maybe for an app then also how you're pushing down security over time you know things have people want to operationalize there's a lot of there's a lack of skill sets that's known but also there's a lack the span of control is also reducing if i was a security leader within an organization with the advent of cloud the advent of new teams like devops uh where you know they have more admin rights more day-to-day control uh the cloud has a shared responsibility metrics you now have to rely on other people who are maybe a dotted line or are your stakeholders but they need to provide information so you have visibility into the security posture so the idea is how do you give them guidelines say hey i want this now these are no longer in your four walls they're now in public clouds you know globally they're on the you know uh they are now the threats have increased the landscape has changed um so how do you do that how do you have visibility to the security posture there's this concept of cloud security posture that's come you know this there's a lot of conversation this number of companies that are talking about cloud security posture management but that's you know not new it's been there it's just that it used to be in your you know environment and now it's gone outside but but in some cases it's also hybrid i have we have customers who say they're taking a journey of closing their data centers and going to the public cloud but that's a multi-year journey you have in between a hybrid some of them will stay hybrid some of them will use multi-cloud so the concept is how do you ensure that you have the same data protection controls are on all these and how do you get the same visibility to make sure that you're compliant or you're secure change frequency we talked and of course increased regulations well talked about but this is increasing privacy again privacy is interesting because you have a legal angle but if you look at gdp or cpu you have a data protection angle it's about how you're protecting the pii data how you are able to tell you know if someone wants to say i need you need to inform us if you have lost our you know personal information that's preached it's almost a disclosure so you have to have a date of security protection also there's an angle to it so and of course you know with the recent attacks but that has happened with solar winds and others there are also going to be more regulations coming up so interesting thing is your increased regulations which means you're more burden for you know evidence collection because you have to give more you now have to depend on people who have very you who are your you know almost your first line or eyes in in terms of whether where the controls implemented and of course you have the hybrid clouds so these are the challenges now what's the opportunity for us so i think it goes back these uh you know iso cis controls have been around for a long time but i think what we need now is to use those controls to almost give like a checklist a a guidance saying thou shalt do this now you may not be have a security background but if you gave them in a language they understand as part of the day-to-day hopefully they'll perform that function which will then come back to you and you know we provide you that information you need to get a visibility to the uh security posture so it can so they need and of course if you use industry benchmarks it helps a lot lot talks so much about mapping they need to come you know you have if you collect evidence on one control it maps to another control so it's very interesting that you the industry benchmarks also help and lately we have seen so many customers um asking that hey i want to be iso compliant i want to be ci i want to use ci's hardened image i want to be csa you know i want to go and apply for the css in a certificate so it's very interesting now the fedramp and the cmmc they all are coming where the government says you have to follow these so it's a lot of benchmarks and regulations that are kind of overlapping so it's interesting the control concept um and of course the security visibility security posture and the concept of continuous compliance and i think we should talk a little as we move along so now the next slide thank you thank you so we want to get started the accelerator right we did this it's on paper right we don't need a tool but let's start where we are which is you know we know what our obligations are we know what are legal regulatory compliance as an organization as an enterprise to our stakeholders to our shareholders to the government then we have got you know once you have those you want to be able to optimally comply to them so you may want to use some frameworks or benchmarks that you can now see how i can these because all of them are controlled based right so if you are able to use how can i map or comply to these controls and how i can get you know compliant to these these regulations important thing of course fundamentally know your assets which is now which servicenow does a great job with which is you know i've seen a lot of people coming and saying you know we can do all this reporting for you but the fundamentally is do you have the assets do you have the resources that you need to actually run these controls on if you're able to do that because that's what you know but you need to know what you have that's the first step if you do obviously everything else is easy know your risk tolerance um what's your pass pl threshold uh in all these large show the accelerator you can set your threshold you can say i am kimberly clark for me it's a different uh threshold rating than i'm a bank or i'm a hospital or i'm a government agency so thresholds of pass fail 80 could be failed for one 60 could be passed for one you know so how do you do this you know how do you set those based on your risk tolerance risk appetite uh then they of course the success comes in all of us when you apply grc we ensure that these frameworks really align the business and ultimate goal is to gain visibility into security posture i'll next slide so we took this concept of a control right okay so a asset needs to be protected that's fundamental 101 the control helps you protect the asset it tells you what to do run the control run vulnerability management or have ensure there's no unauthorized software um you know ensure you have a good you know multi-factor authentication for example for privileged access you have those assets and you have some controls protecting those assets and these controls can comes from the benchmarks then you have compliance to ensure that those you want like these indicators that ensure that those controls relevant controls on those assets are actually uh you know they're passing or if they're not you know what is the issue so that you can go back and try to fix them and they give you this visibility of compliance indicators do that ultimately of course everybody wants to you know provide these evidence to auditors an external third party who are an internal audit who is an independent third party want to ensure that you have actually you know you're protecting the data or protecting that asset so it's concept of controls that we have taken and try to expand it even in the accelerator next slide yeah thanks thank you um so in this case uh i'm just going to keep spend only a few seconds on this because i think we have we have heard from lal about and others and people talk about what's the is it's been around for some time it's getting more visibility now more prominence now a lot of people are talking uh that's why you know it's a lot of uh you know uh frameworks are coming up saying we need to use cis why because it's very prescriptive like if you read it tell it tells you in very clear simple english what you need to do um it is widely adopted there's no doubt there's tons of any many tools that you see in the market will say we comply to these top 20 controls in this way so it's a very very widely adopted tool um it comes it comes with people who actually thought through security from that perspective it's not someone who wrote a legal uh um you know law but it's more from what actually can practically affect that correct you from an attack and uh it is referenced in number of frameworks so there are these concepts of basic foundationalization and we'll talk about it in a minute but the idea is also you've got three things you've got basic fundamental organizational but you also have three groups which is cs tells you hey you have these three if you're small you have you know vary on the maturity of less resources um you have you haven't matured your security you're starting off inclination group will give you something then you can go to i so you kind of go through they give you more of a maturity model as well as they tell they'll also tell you how to classify their controls and there's relevance to both and we'll talk that in the next couple of slides um next slide and this is i just wanted to put this out there um for uh you know everyone saying this is sans has done a great job as to why you know putting using cis enables you so if you have a pci um you know let's say you want a pci says do you have a secure coding policy right cis has exactly the same thing of course iso has two but com getting evidence for that automatically you can say yep you know it may not be the same format but at least you said yep i have in cis i do have a secure coding policy or i have these you know i've complied to this uh control the pci has a similar control you can use the same evidence so it kind of helps you that way you know make it more efficient next slide so the cis as we said is interesting because it also takes a security perspective and in the in there's been studies on this uh using the attack which is you know the adverse adversarial tactic techniques and common knowledge which is the mid race you know um model they have used many techniques to say let's use these techniques and attack assets that have these cis controls and they've taken the top five threads you know and they've seen that ig one which is the smallest or the initial group of 43 controls is able to protect you give you protection from much of these attacks if you look at these you know ig one protects you for web hacking almost 153 types of techniques have been protected just apply implementing 43 controls in for inside privilege all of them are so you even if you start off with this smallest group of controls to implement you're getting a large roi getting a lot of protection out of it so it's very interesting and of course as you go up when you hit ig3 you probably hit 85 these are you know people who have tried it they have tested it and they've you know they've actually come out and said this is what when you put these controls this is the amount of level of protection you get so it's very very um descriptive it has some you know it gives you what the results could be and you can of course test it we have done it on our own some of these strikes we have tried to also we have people in our organization who have said okay let's try these let's put up some of these controls and and we have seen very good uh results in terms of providing providing those uh data protection controls uh next slide law so now this is the framework allah talked about uh the accelerator the cyber security controls accelerator for cis what we took is we said you know obviously not all controls you can automate um there are many of the controls that are you know human you know you need a human intervention be a policy or base security awareness training but then there are certain controls that need to be uh you know uh tested frequently maybe on a daily basis maybe on a weekly basis every time you have a jenkins built going up to the cloud you may want to test a certain control because that there is a changes but it changes every 24 hours so what we did is we took the concept of basic controls basic controls are technical controls hardware assets software asset management vulnerability scanning um you know i um access management we took those and we said hey how much of that can be automated you know how much of those control because those are controls which are also operationalized which means there are people in security operations devops and other groups who are performing these and they can perform these so if you're able to the indicator templates now that lal mentioned you actually 57 percent cover the basic ones which are the ones that are frequently changed which are the ones that are away from your organization which are the ones that you need to protect your assets so 57 percent now 18 percent of foundational and 33 organizational now these are that require you know there are some evidence for even those you can actually pull but they're not completely automated so what they are is they provide you some evidence but you need another um you know human intervention to come in and say yep i got this i need to verify this with a policy and then i provide evidence to the auditor or i prevent provide evidence of control compliance so you have complete fully automated ones then that you can operationalize and and you can extend now the people for example if you have mssp doing uh some kind of monitoring you can have them do some tasks and extend that from say continuous monitoring to continuous compliance so you now have the ability to get to the concept of convenience compliance over time just with those basic controls it's also said industries uh studies have said um that you know if you do the first five controls you're almost getting production from 85 percent of cyber attacks so we took all those and said you know what let's automate as much as that so that's the concept of how the accelerators have kind of overlaid on you know how the controls have worked with some next slide now so it's an example now the reason i'll give you the example in here but i wanted to put here as to how the thinking behind this right and and you can now there are sort of uh you know automated controls in the calculators but they are foundational if you want to take another control and automate it you can do the same if that data is in those tables and service now in those various bus and modules and if you are able to say write a script or able to pull the data you can still do and the starting step is what does the control say it's in this case it says unauthorized software what module is the data or what this bu has that data within the now platform if you're able to get if we're able to identify it then we know what the passing condition should be it means that you need to you know ensure that you're able to validate or get an alert when there's a on a set of assets that there is a unsupported software if you're able to say i'm able to get that and pass this threshold you can put a pass fail and then provide evidence so the concept is take the same take a control break it down into take the anatomy and break it down and say what is the requirement where is the data in within servicenow or within the uh within the module what data fields it has and then how can i pull that out so i think that constant some cases you may not pull everything you may pull some and then maybe get it from an external source you can so the idea is if you're able to take that's how the two examples i gave the second one of course is you know very of the secops tool where not just vulnerability access but you're actually running it with the latest updated tools so that it automatically scans all the systems that's a requirement now some of these are also probably uh or i know some of these are part of other you know regulations so when you run these the same data maybe the same evidence won't be but the same data can be used to comply or provide control compliance for those regulations and some of these of course you want to run frequently especially in cis so it also these indicators help you do that very efficiently next now uh iso uh lal mentioned so it's a little bit tricky um so what we did is uh within iso we took those technology controls and we said the same thing and the ones in the green are the ones where there are some automated controls as much as you can i know some either with manual i'm sorry if it's scripted or basic try to take some of the controls and said where the data is how can it be automated and iso is also interesting because it's a global where different auditors want to see it in a different you know in different evidence and different formats or they how they view your organization and how they want to audit against iso so you tried our best in this case um to provide or that the indicators where it can provide you that evidence but most of them again are are from those technology controls and some other controls that we have already seen before in the cis and how we have tried to ensure that we can reuse them in the same iso from the same data from the table next slide now so an example here is established secure code policy uh you know it's in uh you can do a pass fail as you see the policy you're able to use the grc module to find it and so again what the intent of the iso accelerator or the technology control accelerator is how how much evidence collection time i can reduce how i can make it easy for you know for these evidence to be produced because you know unlike cis maybe you do iso some of these isos maybe not as frequently maybe once a year or once in six months but it still adds you know a lot of evidence collection burden because people are multiple artists through the year so the idea is what can be what controls or what automation can we do to improve uh evidence collection just like now the maturity model um we spoke about you know the the controls and the journey towards it so you start off by saying you know start with something that's not in place you perform ideas go to continuous uh improvement that's the that's where you want to be but it takes time and these accelerators can can help you get through that journey may not be completely you know you may not reach continuous improvement uh it's a it's a it's you know it's a journey that goes over time but at least you can start and if you get the accelerator you can start with some um you know you can start defining some controls defining some processes and measure it and over time reach that but just to show you the maturity model you know the extra text can't help you with the mutual so i'll take the last two slides and i'm going to talk about you know in a few minutes so i'll just talk about what the controller's accelerator scan cannot do first is these are technology accelerators although they create contextual visibility they cannot solve which is we said they can't solve all your problems these are to make these are foundations for you to build upon so the better aligned you have the you know the more bus the more modules you have the more data comes in with the more data comes in the now ecosystem the more visibility you'll get we talked about you know they need to augment human efforts with um automation i've never seen a tool i've you know seen many tools that say oh push a button and you get the evidence never happens so you need some there is a human factor to this and it's a good thing actually uh then you have you know you do have some accelerators can provide you but you do need to have the governance and policy enforcement and finally uh you start where you are ig one ig three basics based on where you are in your maturity model this gives you the ability to start so it's a very interesting concept because you can you can start it at zero and try to go to ten but it gives you the prescriptive steps to get there finally it is a marathon and we all know this and uh doesn't start and end in you know 60 seconds this takes time last slide now so i want to this is a little busy slide but i figured i'll just put everything a lot of said and i we try to give you share some of our perspectives which is leverage your investment you have data you have a number of you can add more feeds you can you know you can bring in more data use that use that to be able to gain visibility ultimately to your security posture across these environments across the landscape obviously we want to reduce risk the flexibility in customers is key what does that mean it means that you have taken the now platform and you have customized to your business your enterprise your risk your requirements so we want to be able to make sure these accelerators fit into those so that it is relevant to you it's it gives you what you need to know to make your decision operational com operationalize compliance again give there are people who can do this validation for you and how can you get the results and you're able to monitor that continuous monitoring that's a great concept right which so much about kanban and continuous monitoring how can you know make that into something called continuous compliance so that you're really you don't have to have a audit season to go look at controls you can kind of get them and it kind of becomes part of your daily you know review assist once uh lal mentioned a lot about how the idea of using ucf leveraging the ucf ids now the last thing is when you want to implement this i i suggest work with a partner work with someone who now can look at your platform implementation set your threshold ratings maybe sometimes you may threshold rating high and over time tweak it so that you are able to see uh because sometimes you want to be positive right i'm not saying you should reduce the risk but positive things help if you always say no no no it's a friction we say yep this is okay but next time can you improve so it's kind of it's it's a nice game for people to encourage them to you know adopt these controls data types you can import you know you have to design if you want more you can actually add additional fields you can say i use this tool but your you have only feeds from this tool well you can actually write a script or you can write you can use the api to get it because you get the same data into those tables you can run the accelerator and finally you know you want to be able to ensure that the evidence meets your requirements um you know there's new reports coming out is operational reports there's operational dashboards but ultimately the tool has evidence and you can also write um custom reports you you can take that data to put it in a way that in a format that you can then provide to your auditor it's pretty you know it's customizable so ultimately we want to save time um you know with the audit and evidence collection so with that i appreciate your time thank you lal and others for giving us opportunity to you know share our perspective um you know everyone has their own views of thing and we feel like having worked in the field having seen large enterprises to small enterprises out of these we wanted to share some of our perspective as to why these controls are important how you can use servicenow to automate it or at least start the journey to automation and enable you know better visibility to your security partner thank you thank you raj and uh um really appreciate it raj and law we don't have any questions right now unless lisa we have over there anything over on ya on the uh youtube um nope i think you've heard so far we're good yeah i think you covered a lot i think you guys covered a lot probably answered everyone's questions but we do want to leave people with though is you know reach out to learn more at the servicenow.com risk url you can also learn more from the credio website and all the applications and things we've got out on our store um join our community there's a lot of information out there and you can chat with raj you can chat with law we'll have this recording up in the community you can feel free to ask questions make sure you monitor what's going on they'll make sure you're appraised of anything new that's happening and then we have other ask the experts out on youtube that we would like to invite you to view and learn from so with that i would like
https://www.youtube.com/watch?v=3bhOOefpbP8