logo

NJP

Configuration Compliance Dashboards and Setup

Import · Mar 23, 2021 · video

security risk and compliance leaders are challenged with protecting the confidentiality integrity and availability of business services and confidential information but as businesses grow and attackers become more sophisticated legacy approaches with a high degree of manual effort will no longer be enough to keep up in this demonstration we'll look at how servicenow configuration compliance can be used to secure your environment faster misconfigurations can leave vulnerabilities wide open to malicious actors and while third-party secure configuration assessment tools can be used to automatically run configuration tests the results they produce can number in the tens of millions security teams need servicenow to work at scale automated triage service aware risk scoring and quick integration with change management can help teams to secure configurations faster at any scale let's take a look let's start by looking at the configuration compliance dashboard now this is the dashboard that an administrator would use to be able to get a quick view of what's going on in their organization with regards to compliance you can see that there's a lot of widgets here that have useful information such as the test results for compliance and you can drill down and see details on each of these you can see the number of policies the tests the test results and the hosts now this is a test environment just so you understand why there are so few hosts in this demonstration video uh you can see things like the failed results by technology and you can see the different technology breakdowns uh by risk rating etc if we scroll down we can even see things like the failed test results by category so you can see individual categories where the test results have failed the open test results and the test results groups so a lot of information around the testing the test types etc now we've recently added a remediation tab so we're able to track remediation as well for configuration compliance and you can see things like you know the status of remediation targets where they're at whether it's in flight approaching target or midst target and again you can drill down and see information about each one of these things everything in here is clickable so you can look at the open test result groups by remediation target status the test results by risk reading and remediation target status so if you wanted to see there are 58 critical that are in flight you can click on this and get details around each one of those individual test results and then the closed test results how are we doing against meeting the targets that we're setting for uh the the test results and fixing the issues that we need to fix with regards to compliance so that's a quick look at the dashboards that are available and this is all again customizable and clickable so you can drill down this is all built on the now platform which gives you a lot of capabilities with regards to reporting let's now shift and look at how we configure configuration compliance to actually help get work done so what we want to do is look at a few key areas the first being assignment rules assignment rules are going to use specific conditions and then assign the test results to specific groups let's take an exam look an example of that so here we see i have a assignment rule uh called application servers we can see that it's active and if i want to set a description i can do that this is where we actually get into the meat of assignment rules we have a condition so in this particular case the assignment is uh if the configuration item starts with and then the condition being win dash zero so those are the application servers in my environment so if the configuration item starts with that then we're going to automatically assign this to the group application development so that automatically will take the test results that come in from our scanner and then assign those test results out to application development if the configuration item is winder zero and as you saw we had a plethora of other ones out there as well and these are fully customizable so if i wanted to uh drill down even further and say you know if it's the configuration item starts with this and the criticality is that then assign it to this particular group so that's a quick look at assignment rules that's one of the areas that we help automate getting work done quicker with configuration compliance now the next thing that we want to do is look at remediation target rules so we saw that we were able to look at remediation target status we also want to be able to set those targets so let's take a look at an example here in this example we have a critical risk rating rule so this is going to be the target for remediating critical items so we can see the condition is if the risk rating is critical we want this target to be 15 days and we're going to notify folks in seven days so take that and combine it with the uh assignment rules and we now are able to fully automate not only who gets to sign the work but they are also going to explicitly know on the test results how long they have to remediate it and they'll even get a notification uh for that we can even specify who the notifications go to so we can make sure that you know the management for a particular group is notified if the remediation has not been completed yet we also have information about the remediation test results status so we can drill down and look at information about each one of these particular test results and see who it was assigned to and to make sure that we you know bug them and make sure that they get it done in a timely fashion finally let's look at test criticality maps now this allows us to take the source criticality so this is the value for uh from qualis urgent and then we map those to our target values on servicenow configuration compliance and that was a quick look at the setup as well as the reporting abilities for servicenow configuration compliance if you'd like to learn more about servicenow configuration compliance please visit us at www.servicenow.com thank you

View original source

https://www.youtube.com/watch?v=IUvEXD1a7W4