logo

NJP

Respond Smarter to Vulnerabilities

Import · Mar 30, 2021 · video

welcome to the response smarter to vulnerabilities with servicenow vulnerability response in this demonstration we'll look at three benefits of vulnerability response first how you can leverage visibility and reporting to drive efficiency in your security organization second how you can automate vulnerability assignment and response to reduce response times and finally how you can use servicenow vulnerability response to drive cooperation and communication between the security and i t teams let's take a look at the demonstration for this demonstration we'll begin with carla jackson a vulnerability manager carla has three things that are always on her mind number one what's the state of vulnerabilities in her organization number two when exploits start making the news how does she quickly determine what her exposure is and then create a plan to address it and number three how does she make sure her interactions and communications with i t the folks responsible for remediating vulnerabilities are seamless as possible to help address the first issue knowing the state of vulnerabilities within her organization carla starts each day with this dashboard here she can get a real-time view of the state of vulnerabilities including the number of vulnerabilities by risk rating over time the mean time to remediate vulnerable items and more carla can also drill down and look at individual groups like the endpoint security team to see how they're doing this allows carla to keep track of not only the overall state of vulnerabilities but also see how individual teams are handling their assigned tasks speaking of endpoint security earlier today carla read about a new exploit that targets microsoft office to determine her exposure to the vulnerability carla's second concern she'll use the software exposure assessment a tool that's part of servicenow vulnerability response that leverages information from servicenow's software asset management to begin the assessment carla will need at least two pieces of information the software's publisher and the product if needed she can even drill down and look at specific versions or editions but in this case we'll look for all versions of microsoft office and all right it looks like she has quite a few instances of microsoft office in the environment so let's create some vulnerable items vulnerable items match one configuration item with one vulnerability so for each discovered configuration item that this vulnerability applies to she'll automatically create a vulnerable item what's really cool about this process is that let's say there's a zero day exploit that's just hit the wild something so new that it hasn't been added to the national vulnerability database yet carla can still create vulnerable items for the vulnerable assets by clicking new vulnerability in this case though she'll use an existing one simply type the id and it searches the national vulnerability database entries for the matching id we'll select the matching cve and then click create vulnerable items now we have four tabs that we can look at first is the exposed discovery models these are the instances of microsoft office and carla's environment next is the vulnerable entry this is the vulnerability that we want to remediate before it's exploited then we have the newly created vulnerable items and finally we've taken all 750 of these vulnerable items and created a single group that can be worked you'll notice that it's even been automatically assigned to the endpoint security team let's switch personas now and take on the role of one of the endpoint security it workers named becky this is the dashboard becky sees when she logs in in the morning it gives her a view of the work that needs to be done as well as tells her how she and her team are doing with remediating vulnerabilities in the environment scrolling down we can see the new vulnerability group that was just created by carla at the top of the list so let's click into it right away we see a few bits of information including the risk score and risk rating these scores are automatically created by risk calculators that are fully customizable it also has a short description of the vulnerability in question which is quite handy we can also see that the group has automatically been assigned to endpoint security which makes sense since microsoft office is typically found on endpoints the first thing becky is going to do is take this large number of vulnerable items and split them into more manageable chunks of work using the split group functionality here becky can split the group using a variety of possible conditions but for the purposes of this demonstration let's use configuration item contains and then we'll say precision t5500 group gives us a preview of how many vulnerable items will be added to this new vulnerability group which we can preview but for now let's just create the new vulnerability group becky now has a brand new vulnerability group to work she'll assign the new work group to herself becky also wants to make sure that she follows the proper process for patching systems to do so becky will create a new change request we're going to apply this change request to all active vulnerable items in this group but if we wanted to split the work even further we could do so by filtering for specific vulnerable items we can also add the configuration items to the change request and since this exploit is critical we're going to make this change type an emergency change i'll also set the priority to critical and make the plan a end date a few days from now this should give her plenty of time to roll the patch out to the affected systems after testing it speaking of the patch within the change request we can see a wealth of information that's been added including information about the vulnerability justification for the change request and an implementation plan that was automatically added this saves becky a ton of time researching the correct patch because it's already been provided for her through vulnerability solution management another feature within vulnerability response this helps address carla's third concern seamless interaction between security and ite becky creates the change request with all the information she needs to get started now for the purposes of this demonstration we're going to simulate the process of applying the patch to the affected configuration items and close the change request once the work is completed finally now that the patch has been successfully applied to the 86 previously vulnerable configuration items we can scroll down and look at the vulnerability group and you'll notice this state has automatically been set to resolved again this shows the close-knit communication between the work it does and the reporting back to the security teams carla can rest easy knowing that the correct patch was applied and her organization is no longer a potential target for attackers in this demonstration you saw how carla was able to leverage visibility and reporting to drive efficiency between both the security organization and the it organization she was also able to automate vulnerability assignment and assign things to the endpoint security teams so becky could quickly respond to them and finally both becky and carla were able to use servicenow to drive cooperation and communication between both of their teams the security and the it team for more information on vulnerability response please check out the solution page at servicenow.com thank you

View original source

https://www.youtube.com/watch?v=WWz_bLVa8IA