logo

NJP

Continuous Authorization and Monitoring Overview

Import · Mar 05, 2021 · video

good morning ladies and gentlemen so we typically start off with dashboards and with our continuous authorization monitoring and our risk there's many dashboards out of the box instead of walking everyone through the details of dashboards i tend to prefer to talk about the greater value the dashboards bring because we've assembled a lot of capabilities here as you can see these dashboards really are kind of a miniature framework of themselves and they're extremely flexible it's very easy to bring data from across the entire platform and visualize it together operational data cyber data rmf etc and we designed this to empower the business community so that they can own and operate this without necessarily having to have the help of it and development so this is our continuous authorization monitoring application and this is really where we're defining the authorization boundary as you can see we give you the opportunity to find specific roles we have some out of the box but of course to create new roles and new fields truly is as easy as hitting that button and typing in the name of the field i want if you have a specific role that needs to be in there it's a it's a cake to add then we define the boundary itself now a big uh source of feedback we got from our customers was that they currently find their networks and their boundaries for rmf purposes really based on artifacts based on word documents they would teams have teams of people go out and and probe around and say this is what the network looks like and they would write it down using words into a word document and they said that you know pretty often that word document would be obsolete by the time they finished building all this out and they wanted a dynamic perspective of what their boundary looked like so here we're leveraging our same db and what we're doing is we're defining filters against the cmdb and saying hey our boundary consists of these types of things within our enterprise as you can see you can have multiple filters and these filters can have multiple conditions in them as well so i said hey if our network discovery processes of our it operations folks out there they're out there discovering things moving things around and updating the cmdb as a security team as an rmf team let's leverage that real-time visibility and if anything pops up with this ip address range we know that that's part of our boundary another example i did a little bit a little bit more simply i said if something uh if something pops up within this data center as a whole if the location of that it asset is this location it's part of our boundary and these are showing off our ability to relate data and understand these relationships of i.t assets we then rationalize those filters down and say hey these are the 45 it systems that we we caught from those including any systems that we manually tailored in so this is how we're giving you the ability to understand what's in your boundary from a real-time perspective that theme of visibility is so key when it comes to your assets and we're taking advantage of that capability in the in the servicenow platform so here's here's a package we've actually started off this one has already gone through the prepare stage and so we've already done our privacy threshold analysis one of our answers triggered the need for an impact assessment that impact assessment was sent out to the correct individual automatically and the results to that assessment are displayed right here right so again removing platform creating instant traceability within categorization we've defined our information types out of the box we're giving you approximately 100 different information types but you can create your own ids as necessary and these information types each carry their own impact rating we can tailor that impact per information type so we can tailor at a very very precise level here and i can override one of the impacts these combined with the the the pia create our system impact and i can override that as well with the justification and of course we can wrap a whole series of approvals and and processes behind this and then ultimately i arrive at my system impact level then it's time to select our controls we can apply control overlays and you can create your own control overlays the system applies the baseline controls straight out of 853 and 837 and we can start tailoring these controls i can take a control and say yep i need to implement that one or i can say that this one will not be implemented in which case it moves over here and i can very quickly and easily see which ones are not being implemented i can choose to inherit controls from other systems in which case i get full visibility of that control i'm inheriting so i'm not inheriting controls with discomfort when that system exists as another boundary within servicenow we can give you the full insight into their compliance their test results their issues their monitoring that you would have of your own so that you can inherit with comfort as the system in the packet moves up into the implement stage now we've kind of rationalized all of those controls and that tailoring down into the actual controls that need to be applied and this is where the system owner would start actually implementing we can test the status of the implementation with attestations and ask the system owner are these controls in place are you ready for an assessment when it moves into the assessment phase we leverage our audit engagement module this is an audit engagement and this is where we are defining that that punch list of work that needs to be done to effectively assess all the controls whether that controls a technical test or an interview or a review so as you can see there's a lot of metadata around here with resource allocation and resource planning and how to actually manage the overall engagement we have some test plans where we're going in we're teaching that control assessor how to test a particular control now these test plans don't always exist right um and for a lot of the the routine technologies the assessors are really the experts in how to assess these things but we're finding that when customers are dealing with new technologies operational tech iot or or just new systems to their environments um that being able to provide that very prescriptive guidance to the control assessors allows them to not only you know do those those tests more effectively but faster with less confusion around how to go about it now in this case all i did was i brought in nist's own test information from 853 it's not particularly detailed it really just says well you can test you can observe you can review this control uh but the data is in there to show you how it works we take the entities that were that we're testing against in this case the boundary that control library and then we rationalize all of this down into the actual test for the skas so we're giving them that punch list now the benefit to them of course is they get some new new order uh uh you know from from chaos brings order to their environment but you and your staff get visibility into the actual progress of these right how much of this work has been completed when do we expect this to be done are we making progress and what's our current status so as they go through and they test these controls they're updating the platform real time and we can see the results of those those tests so we can say hey we already have a few problems here that are being generated and so that brings it all again with that very low level fidelity but brings it all up into the the high level visibility and finally we move into the authorization stages which really is at that point it's a review and an adjudication stage and then into into monitor now when you authorize of course you can do that more traditional time-based authorization that the world wants to evolve off of or you can authorize on an ongoing basis and you know one of the really key aspects of this is going back to that platform as opposed to reviewing based off of are the facts which may very well be obsolete by the time they reach neo's desk you can review based on real world data so you can see here that i'm looking at this boundary and i'm seeing all of the controls right i have access to the test results and the compliance data right here i have my poems i know what vulnerabilities are on the system right now even if those vulnerabilities were found during the last two weeks while my team was building documentation we can bring in software asset information any sort of information from across the servicenow platform or that we can bring into the platform we can bring together here to give you that true visibility into what's going on with this system and then since at this point we've really kind of transformed the entire rmf process we've brought it out of that very kinetic manual world is common operating platform we can actually do things like generate the ssp for you automatically because we have all of the knowledge in the platform now and we can generate other types of artifacts as well and we can even build out api integrations if you say hey i need to take this information and shove it up into this uh this this upward reporting system over here we can generate the artifacts automatically and then automatically upload them into other systems as necessary so that's the high level walkthrough of how we've taken the servicenow platform taken our integrated risk management and we've brought it together specifically for rms you

View original source

https://www.youtube.com/watch?v=LTftGSWzjcs