logo

NJP

Vulnerability Response End to End Demonstration

Import · Mar 26, 2021 · video

hello and welcome in this demonstration we'll show how you can reimagine your vulnerability response with servicenow today we'll be looking at how servicenow helps it and security teams work together to eliminate dangerous vulnerabilities far more efficiently and effectively than ever before we'll start with the big picture and then dive into the key elements of the solution with servicenow it's typical to see a 40 to 60 percent reduction in time to remediate business critical vulnerabilities when converting from more manual processes like email and spreadsheets when results like these are achieved our customers can use dashboards like these to report on their progress the vulnerability response application provides a single system of action and engagement collecting information from scanning solutions threat intelligence providers solution databases and internal remediation activities out-of-the-box dashboards like this one help us track our kpis and break down the information as desired this information can be rolled up against any existing cmdb data if desired for example we can see here what business services are at risk and how they're trending we could look at this from a service owner perspective or we could focus on exceptions and remediations users can also create their own reports and dashboards our customers appreciate the ability to build dashboards for their teams and leadership this iso dashboard is a great example of what customers can rapidly build using our gui based report engine and drag and drop dashboards one of the advantages that servicenow has is the ability to bring together data from many groups to provide holistic insights across the board on this overview tab for instance we have information from teams across risk policy compliance configuration management vulnerability response and security incident response dashboard tabs can be created to organize the data in this example the tabs provide extra detail for different groups but they can be rearranged and styled however any individual user prefers so you can see that we're getting everything in one place but you may be asking yourself how did we get here well it all starts with integrations there are out-of-the-box integrations with vulnerability scanners such as tenable security center and io qualis rapid7 crowdstrike and tripwire as well as vulnerability threat intelligence solutions for enrichment such as recorded future eye defense shodan and exploitdb finally we also integrate with supporting archives like the national vulnerability database and the microsoft security response center for additional details on the vulnerabilities that are brought into the customer platform once installed these applications can be configured in your servicenow instance some simply require api keys such as showdan while others have more options like setting a schedule or adding filters to the data we want the documentation linked from those integrations on the store can probably answer any questions the customer has servicenow also stores a library of cve entries from the nvd alongside third-party vulnerability definitions and reference information and this gets presented with your scanner results all of this data is referenced in scanner findings in the vulnerable item table now please note we're not creating an incident or a task for these findings the vulnerable item table is a separate space for vulnerabilities vulnerable items are then enriched with any available info from the cmdb threat intel context and solution information now having a cmdb is not a requirement and vulnerability response can load host information into the cmdb if desired it can be a great way to supplement the cmdb and keep it up to date however when the cmdb is populated by servicenow discovery with business service mapping according to our best practice common services data model the cmdb can be used to automate vulnerability triage and risk scoring threat intelligence integrations like showdown help us understand what's happening with this vulnerability in the wild is there an exploit kit for it is it being exploited often solution management and the microsoft security response center integration helps provide remediation instructions to teams whether it is applying a patch or something like a setting or configuration change finally servicenow can act as a calculator of calculators pulling in information from all sources and providing a high level 1 to 100 score of cumulative risk simple gui based calculators can be used or if desired precise logic can be supplied in javascript any changes in the gui version are automatically previewed against data sets below scan findings can also be assigned to groups or individuals based on rules this happens automatically based on any established assignment rules the results can be overwritten manually if needed vulnerability groups can also be created by hand this is useful when there's a high profile vulnerability that needs special attention and tracking say for instance wannacry there were a number of cves that needed to be quickly addressed in this way we could check in on them this newly created vulnerability group groups together all of the existing vulnerable items with the cve ids we specified we can assign this to a group in it and start an investigation if an exception is needed because the owners can't patch in time we can document that here we can define the reason for the exception and when it should expire here this exception will be remembered and we won't have to do this every time a scan is run now in order to deploy a patch that remediates a vulnerability change control must be followed and vulnerability groups are directly integrated with change management change requests can be created easily and accurately from here using this preview functionality information about the vulnerable assets and how to fix the vulnerability is passed into the change request if available and able to be changed by the person raising this request finally this integration is bi-directional so when the change has been implemented the vulnerability group and its vulnerable items will be automatically marked as resolved and await confirmation from the next scan now at this point we've covered the end-to-end life cycle in the vulnerability response application from creating a finding through an integration with the vulnerability scanner to remediating a vulnerability using a change request today we've seen how servicenow is helping with vulnerability management by automating workflow processes improving prioritization with integrated threat analysis and business impact triage enhancing the collaboration between security and i.t and providing big picture analytics necessary to track and improve kpis for more information on how servicenow helps our customers manage vulnerability response visit servicenow.com

View original source

https://www.youtube.com/watch?v=xhcpN1prJeU