logo

NJP

How To - Security Incident Response

Import · Mar 05, 2022 · video

hello everyone thank you for joining us on today's webinar how to clinic security operation for security response uh my name is mohammed nasir and i'm going to be leading this webinar i'm just going to give it a quick couple of minutes just waiting for everyone to uh pulling into the meeting and uh we kick in in a couple of minutes thank you hey hello everyone okay so hello everyone my name again is mohamed nasir i am a solution consultant who is specializing on the security operations offering at servicenow and today i'm going to be covering the how to clinic security operation for securities response a webinar thank you all for joining us today before i get started just uh a quick reminder this is a privilege and confidential information this is also covered by the safe harbor notice for forward-looking statement so this presentation contains forward-looking statements that are based on our management beliefs and assumption and on information currently available to management we intend for such forward forward-looking statement to be covered by the safe harbor provisions for forward-looking statement contained in the u.s private secretary litigation reform act of 1995. so what i'll be covering today uh number one i'll be covering how to get started with your security response implementation moving on to the key concept and skills for using security answer response and finally the best practices and additional resources where you can find more information about security incident response the specific agenda for today's webinar is going to be around automating security into response security instant response goals moving on to how security inside response really works after that we're going to be discussing the security incident response implementation and best practices moving on to the security incident lab which is going to be substituted for uh demo to for today and finally we're going to end with the next steps where you're potentially going to be finding more information on how to get more details about security incident response now let's kick it in with the automating security into the response best practices for security incident response so what are the current challenges facing security teams so the first challenge is the inability to prioritize incidents quickly and the second one is the manual and delayed response processes so what exactly do we mean by that 76 percent of all of the security incidents that we receive or common organization received uh most of the time don't have specific context so we're just being alerted with something that we don't actually understand what it means which could potentially be a great danger because by the time we're filling on filling out all of these blank spaces we could potentially be in a greater danger um the second one is that we have few resources so 82 percent of employees employers report lack of cyber security skills cyber security is a field that is continuously growing uh there's definitely a bigger need for it since we moved to all of the working from home things and all of the expansion of our digital transformation hence why these skills are always in demand hence why we don't have enough resources as we would like uh the other part of this is the manual process that we currently rely on so 56 percent of organizations say that things slip through the cracks because emails and sweatshirts are used to manage response processes so one of the things that we commonly face especially working in the security world is that we are commonly using things that are kind of outdated when we're talking security so whether that was a spreadsheet where we uh basically just have a repository of all of the different vulnerabilities or of all of the different security incidents that we're currently working with uh we're communicating through emails which can mean that we are potentially waiting for someone to get back to us for the next steps all of that creates just a lack of a time that we are basically wasting uh the silos is already there because 60 62 of which organization were unaware their organization were available to a data breach so silas that is naturally created between i.t and security teams is also one of the reasons that we could potentially be in danger so the security team finds a vulnerability or a security incident it communicates through the manual process to the iq team asking them to perform a specific action to remediate against that specific security incident or availability so hence why we are seeing the silos because again we're relying on all of these manual processes so the threat lag landscape so 73 days is the average time to contain a bridge so we find a breach we know that exists it takes a 73 days to actually get to that specific beach there's a 3.92 million uh average total cost of a base so um we've always constantly hear on this on the news there's a new breach out there um a reputational damage that could potentially mean loss of uh value and either maybe a policy violation that also means that we are up into fines things of that nature would cost a lot a lot of money on the long term so doing that or putting that investment into your cyber security is definitely better than spending that money trying to recover from a loss that is caused because of a threat or a wage there's a 667 increase on phishing emails in march through april 2020 this is the time we actually moved into working from home uh where a lot of hackers had seized this opportunity to create fake emails where they pretend to be um who or they pretend to have more information about the covet virus or the vaccines etc so hence why we are seeing a crazy increase in that specific amount of time uh there's also 78 percent of cyber espionage incidents including fishing so fishing is actually one of the most common security instances that we commonly see because it's often uh wrapped as something that we don't uh think is an actual threat there's also a six trillion dollar uh increasing global cost for cyber crimes by 2021. so what can we do to actually uh help mitigate all of these numbers us this can be done through security orchestration automation and response or soaring so why so exactly because we want to be able to prioritize the different threats that we are receiving in our environment uh we can also use that to reduce the manual task scale the capacity of our own employees uh we also use that into connecting security entity and cancelling the silos that is uh created and into in result who are able to accelerate or accelerate the response or the response tasks that are associated um whether that means that the security teams need to do something or the itunes needs to do another thing so how important is automation and collaboration between security and item teams there is a 2.5 million dollars average cost of wage saving by companies with fully deployed automated security solutions and it's really important because it drives cyber resilience and operational efficiency so what is the specific goals of security incident response so we want to know when threats change and new threats occurs so we want to be able to continuously monitor our environment so security incident across your enterprise at scale we're going to be providing you with visibility into your threat exporter we we're going to help you identify security changes in real time and accurately assess business impact to best prioritize the incident and response workflow we also want to know which incidents are critical so quickly prioritize incidents so business context and incident severity insight accelerate prioritization so we want to focus on the incidents that matters most with prioritizing by business criticality uh improve the decision making and align the right data now having a source solution means that we are also going to be able to stay ahead of the bad guys what i mean by that is that security incident response and miter attack one of the integrations that we have on the servicenow platform is the ability to integrate with miter attack which could help us into the investigation process of specific security incidents or vulnerabilities that can look a bit deceiving because of how small they are when in fact they are part of a bigger tactic that can potentially be a greater danger so being always aware of what a specific attack means or what a specific vulnerability means or the specific steps that a hacker might take into actually gaining access to your environment by utilizing the information mitre attack is critically important in this case comprehensive incident record is going to give us a single pane of class where we're going to be basically looking at all of the information that is available to us on the security incident so as you can see on the screen right now and this is also something that you're going to be seeing once we move to the demo portion is that we are able to see more information about the specific security incident um the work notes that is within the different teams so either the ic team or the security team both of them are communicating on the same page so canceling all of the need for emails and slacks teams etc we can see who are the affected users on all of these different security incidents whether there are similar security incident or not on top of that we are utilizing the playbook which gives us basically a step-by-step approach into how we should be handling a specific security incident from start all the way until it's actually contained we also want to be able to respond faster with collaboration across the team so as i mentioned previously uh having a single pane of glass is definitely going to help us into accelerating the resolution uh through either the um single pane where we are communicating with each other or also utilizing the magic of servicenow which is within our workflows where we can basically automate a bunch of different steps that usually are done manually we can do that through automating the incident assignment uh we can view the real time incident status and track determination process and all of that is through the centralized data application so we've seen how why security incident response is important and how servicenow is going to be basically uh working toward achieving all of the prioritization and centralization of your efforts but how securities and response actually works and where does it fit into your enterprise so the first thing is where does security operation fit into an enterprise uh as we are all aware there are a bunch of different services that we currently use for our uh cyber security efforts some of these devices or services are done for detection some are just simple cms some are vulnerability scanner and configuration scanners and all of this information are going to be uh ingested into the servicenow platform along with any user submitted one whether that was for user reported fish or anything of that nature after they are ingested into service now we're going to be utilizing the cmdb if it exists or if it's in a mature place where we're going to take all of the information match it across our cis and see how critical they are to our operation based on that we're going to be determining the priority of these different alerts that we've adjusted after ingesting them and categorizing them so if it's a phishing attempt then the workflow for phishing is automatically going to kick in if it's availability then the vulnerability workflow is automatically going to kick in which can mean that if there are any specific tasks that we would like to be automated like for example currently the host until we're done with the investigation or uh deleting the email if it contains a specific um hash file that we know that is a malware then we can automatically take care of that through the automation part within the workflow we can also utilize the information of threat intelligence and exploit and solution intel to help us in our investigation process so again i mentioned the example of the hash file how did we determine if that specific hash file is in fact malicious that can be done through the threat intelligence integration that we have with services like cloud stride or uh virustotal where you can automatically scan the hash file or the ip uh to give you the findings on it the exploit and solution intel can help us into uh determining what is the appropriate solution based on maybe a vendor fix or something of that nature machine learning is where we kind of are going to be utilizing information like ticket assignments or incident assignments so if we receive a specific incident that is existing maybe in san diego then the machine learning part is going to take that incident and assign it to an individual who is located in san diego over assigning it to someone who is located on the east coast because just of the time difference so this is something where we can utilize machine learning to help us assigning the different incidents the orchestration part is basically where we are able to uh initiate a two method communication between the servicenow platform and any of the different services that can perform actions on our configuration items so in the example of isolating the host or currently it then we can leverage the orchestration tools to do all of that now this slide actually looks a bit uh different and uh might help you understand the concept a little bit more the reason for that is that it gives you an example of all of the different devices and services that can be integrated with servicenow so the detection we can integrate with palo alto titanium semantic invulnerability and configuration we can integrate with tenable quality rapid7 threat intelligence virustotal cat strike orchestration count strike mcafee palo alto explosion and switch and until microsoft so again this is just an example of all of the different integrations that is um can be done with servicenow or on the servicenow uh security incident response solution for a full list of all of the different integration uh you can visit story.servicenow.com uh to see if the device or service that you're using has a pre-built integration i'm going to be covering how we can see what sort of integration is available to us all of that on the next slide so again this is just an example so how it works automated security response for a cloud so as i mentioned one of the ways or the most important thing that we need to focus on is integrating your security product or mssp so we rely on the third-party integration into the platform whether that was from splunk radar logarithm etc we're basically i'm going to be getting information that is going to be categorized as a threat after that we automatically prioritize the security incident based on the information in our cmdb or based on our own implementation rules uh we utilize threat intelligence into also determining the criticality of the or the business impact of these different threat alerts after that we determine the appropriate response action whether that was through the different playbooks that we have built ourselves or integrated from different services we assign the different tasks to the appropriate individuals and from that we are going to be able to remediate the threat faster and throughout this entire process the review and post concern response are automatically available to us these can also be leveraged into creating future playbooks or just creating lesson learned exercise or something like that just to give you a quick visualization of the manual security incident response process before implementing servicenow so as you can see we have a bunch of different automated steps that are working hand-in-hand with the manual steps we can see how the manual ones are actually stretching out the response time from hours to days to weeks and this is just because we are waiting for a response from a specific individual or we have to go ahead and perform a specific task manually hence why we are seeing that structured time now how would that look after implementing something like servicenow we can see how most of the manual steps are actually now automated so we are able to cut down the response time from all of these weeks or days into just a matter of minutes and hours depending on the maintenance window and whether we can actually perform an action or not again if you have any questions please feel free to utilize the q a part and i'm going to be answering that towards the end of this webinar now security internet response implementation and best practices security internet response accelerator look for your integration so the first step into getting your security into response up and running within your home environment is through installing the appropriate integration for the security devices that lay in your organization environment so the installation to each security device might be a bit different so getting these devices prioritized is considered best practice so what i mean by that is that we need to understand what we currently have or what are the different devices and services that we currently have first step would to go to this would be to go to the service a now store which is store.servicenow.com to check to see if that integration is already pre-built uh as you know servicenow has a great connection with most of the security vendors out there hence we have a lot of already pre-built integration available in our store now in some rare cases you might not find this integration so one of the routes that you can take is that you can custom build that integration so if the device or service that you currently have has an open api then you can definitely leverage that into building that custom integration or you can leverage a pre-built partner build integration so some open source uh devices or services don't have an integration built for them you don't wanna actually take the burden of building that integration yourself then you can leverage one of the partners that have implemented servicenow in the past where they have built that integration to just take the information that they've pro in the past and implement it in your environment and having a partner or finding the suitable partner is definitely something that we strongly recommend which is something i'm also going to be covering towards the end of today's webinar so the next part of the security as a response accelerator would be to understand your current architecture so in order to automate a process we need to understand how that process currently is going so this steps allows us to build the desired workflow and the appropriate run books and playbooks that are going to be leveraged with security insured response so what are the things that we should consider in this case number one is the prioritization of your organization services and assets so we need to know what is the important asset to you and what is the uh services that are considered critical to your operation so these are automatically going to get the prioritization if they receive a security alert or something on them then you need to understand the organization's current policies and sla so we always want to be aware if there is a policy that we might not be in compliance with by not performing a specific action on it or if there is an sla that might be preached if we don't uh resolve an incident in the appropriate time so having that in mind when we are building our waveflow is definitely going to be uh beneficial uh number three is workflows and playbooks that come out of the box with any of the servers now set up licenses so some of the playbooks that um come out of the box and service now like the malware or the phishing attempt these can be uh ready to run straight out of the box so you can just take them uh integrate them into an environment modify the tasks that come out of the box to fit your own needs and then you are ready to run with them now lastly would be understanding your assets so understanding your assets allows you to prioritize your effort and your task assignment within servicenow you can achieve this by three or four ways number one leveraging your pre-populated cmdb so if you have a scene to be into place this is great this means that you already are aware of what need to be prioritized when and what is critical to your operations and this is how we get to determine the prioritization of the different threats that we receive on your different ci's we can also leverage third-party asset applications like microsoft uh ssm so sccm which can help us into again prioritizing the cis that you have within your environment now if we don't have a team domain into place and we are not leveraging a third party but we are interested in building one then we can leverage the servicenow discovery so this is an um a point that you can bring up with your sales team uh which can takes you to the iton team to talk to you about discovery which is a method the service now uses into building or pre-populating your cmdb and lastly relying on the manual prioritization so as i mentioned in the presentation we can rely on specific rules that we put into place like saying for example if the finance department gets an alert this gets high priority than the cafeteria or if the ciso receive an alert on this computer or a threat on the computer this gets higher priority than just a normal employee so all of that can also be fed into the um at the platform to put into mind when we are prioritizing the different uh threats and alerts that we're receiving we can also use a combination of the information on the cmdb and these specific implementation rules when we are determining the practicality or the risk within these different security instruments now i'm going to be pausing here for a quick second to move into the uh instance to actually perform a quick demo on what security response really means and how that would look like again if you have any questions please feel free to utilize the q a hey so over here we are looking at the sister dashboard where we're basically going to be able to see an overview of the security posture within our organization so from here we get to see um what is the vulnerability response what is the average time to respond to vulnerability security into response what is the average time it takes us to respond to different security incidents i've also incorporated the approval request and this is where we basically get to determine uh if the system needs to attend to any specific request or approve them reject them send them to review etc we have different tabs over here which helps us dig deeper into different areas so for example if you want to dig into incident handling uh then we can see how many security incident backlog growth we currently have how many priority one versus priority two incidents we are currently working with we can see the security inside response what is the average time it takes us to respond to different security incidents to get the latest information we can just quickly refresh the uh graph uh we can also interact with this graph so for example if i want to filter out the information or add it back in i just click on it and hovering on the graph will promote me to actually click onto any of these different areas to dig a little bit deeper and get more information about so for example in the containment part and you can just click on it which shows me down to the minute what is our current performance when it comes to the containment i can turn on the labels which kind of gives me a better uh view into that so it looks like we actually improved by one minute between here and the current time if we want to create maybe a target or an initiative for the future we can just quickly do that from here where i can go ahead and say i want to create a target that is going to cut down the time to 2000 minutes by maybe july or whichever month i already get to determine now if i go back into my um slide i can actually check the target to make sure that i am working or working toward achieving the specific target that i have created over here on top of that i'm able to perform or compare my performance between a specific period of time so if i want to compare this quarter versus last quarter or this year versus last year i can quickly do that right from here we also want to give the system the ability to make decisions on the spot so i've incorporated the incident tree map over here where we are able to look into the different security incidents that we have received to understand in which department they rely or are in so it looks like from this view i can say that most of the security engines that i currently have are an it service versus the peoplesoft hrms or the peoplesoft crm so in this case i can just hire more individuals to work on the it service or move some of the individual in less square department like this app role into it service just to make sure that none of my teams are being overworked now the rest of the tabs over here are going to be digging into different information or different integration within the platform so the system hardening is specific for vulnerability response business risk and policy control are going to be something that is related to the integration with integrated risk management another solution that we offer here at costs and return of investment is just a way for us to actually see the automation process that we have done on the platform and how many hours we've saved versus the labor value that we've saved so this is something that is definitely beneficial to for assessor to understand the financial value of having something like servicenow implemented on their platform now moving on another dashboard that i wanted to cover would be the security operation efficiency and this is kind of tailored to someone who is more in a managed position to kind of understand uh what is the performance level of their team so how many security incidents are there per analyst i'm currently working with how many cloud security incident per analyst i can see the detection and response effectiveness for the different security incidents that i currently have so how many false positives for score how many false positive security incidents what is the duration that they exist on my environment the critical false positive true positive security incident etc and you can see this sorry the incident risk score analysis and the security incident stage analysis so again this is something kind of tailored for someone who is in the manager position to kind of get more idea on their team performance now moving on to another dashboard and this dashboard is going to be tailored to someone who is actively working on uh resolving these different security incidents so as an analyst i can go ahead and see that the total number of security incidents i currently have with within my environment is 927 so this is a big number this is something that is definitely going to overwhelm me so how can i get to know which out of these 927 i should be working on first to do that i can utilize the different um filters that i have over here so i can focus on the ones that have a critical priority so i can see how i immediately cut down the 927 to 503 furthermore i can focus on the critical business impact to cut down that number to 450 so with just quick filters i was able to cut down the number of securities that they should be focusing on by more than 50 percent now out of all of these 450 security incidents what is the security incident closure by the different priorities what is the security incident by their attack category so out of those 450 i have x amount that is policy violation versus denial of service versus phishing so this puts me in a place and the analyst to go back into management and tell them by the way most of the security incidents that we're receiving of a critical priority and critical business impact are due to policy violation so maybe that puts us in a place where we need to train our employees more or maybe enforce a better policy uh to make sure that everyone is adhering to it another thing that we can utilize is the visualization of the location of the different security incidents that we're getting so i can actually look at this map and see how many security incidents are coming from where so within the united states i have different offices some of them are in california some of them are in new york some of them are in north carolina if i want to focus on one of them in my case i'm actually located in san diego so i'm going to be accessing this list which shows me how many incidents that i currently have that have a business impact that is critical a priority that is critical that is located in san diego this list view can be modified if i want to add in any information like if i want to see who is the affected user in this case or if i want to remove what is the short description for the security incident all of that is immediately going to be updated on this list view i can do things like creating different reports for bar chart or pie chart of additional score if i have more than one in this case i only have one um i can also export this uh graph that i created into any of the dashboards that i have access to now let's click on this uh security sentence to see how the security incident record looks like so over here on top we can see the different states that the incident had gone through so uh in servicenow out of the box we follow a nest stateful so the draft analysis contained where the cage recovery review closed is all out of the box and if your operation actually utilizes a different approach like the nest open or if you have your own specific states that you would like to modify all of this can be automatic can be configured uh once you are actually implementing the solution scrolling down into the incident record we can see its number who requested it the configuration item it's in location subcategory we can see the risk score and the business impact and the priority how did we determine this we actually did this through the cmdb so if we open the dependency view map we can tell that the security incident happened in the computer product kayak so based on what are the other services that can be impacted if something goes wrong how critical these are to our operation uh we can have the environment automatically associate direct score and a priority for it in this case the risk score and the priority that's where determined is 60 and the critical does impact any critical priority scrolling down we can see we can see a short description on the incident itself we can see the incident details reported over here if there are any related records in itsm for example like an incident a change request or a problem all of these are going to be available to me here post incident reviews again this is where we're going to be basically sending out assessments that exp or um check to see who had worked on this incident what are the tasks that they have done we can ask them specific questions that can help us into remediating this sort of incident in the future uh we can utilize this to build a playbook in the future or we can improve the current playbook that we used to resolve the security incident cloud your information this is where we keep track of when it was closed what is the closed code uh if there are any notes associated with that this is where we can utilize the miter attack to see if this is part of a bigger technique that we're not aware of or we should be aware of uh over here we have a bunch of different related links and related lists like for example if we want to see the indication of compromise we can just quickly click on the that link and if the information is available it's going to be available to us in the related tabs we can associate this with a miter attack technique if we uh based on our investigation determined that this is in fact part of a bigger uh technique we can say that maybe this is an impact and a describe just an exa as an example and then that would be reflected on the miter attack map which i'm going to be covering toward the end of the presentation so again this is just a quick view into the incident record this is a incident that has already been closed so let's move on and actually work on a security incident from the scratch until the clock to do that i'm going to be utilizing the security incident workbench so the security incident workbench allows me to see all of the securities in this case that are assigned to my team if i want to change that and just look at all of the open incidents i can just do that with the click of a button and from here i can get more information about the different security incidents by simply clicking on the peak view so as you can see i can get more information about the security incident and if i choose to work on it i can just open the incident in a new tab so over here i have two tabs for two different security incidents um if i click on more i'm basically just going to be presented with more information about the security incident like exa for example who requested it the affected user the category itself it's phishing so as soon as we uh received this specific alert and the source for that was through an email so the user received an email the click on report fish and the workflow for fishing kick in which automatically pulled in the playbook for fishing which gives us the appropriate steps that should be taken to remediate the specific securities scrolling down we can see how many similar security incidents we have the work notes so again canceling out the silos i can communicate with the iq teams or the security teams right from here i can see who are the affected users if there are any configuration items that i should be aware of or that are affected and before i even work on the security incident i can see that the integration with threat crowd and virustotal had already been taken advantage of and we can we have seen how the ip address the domain if there are any hash attachments have already been automatically scanned and we can see the findings for them so it looks like this is in fact a phishing attempt and all of the information associated with it is malicious so let's go ahead and actually work on mediating it so the first task would be to analyze it how can we do this it's to acknowledge the user submission and ask if they have interacted with the email now if i am a newly hire and i don't know how to do that specifically i can scroll down into the knowledge base article which shows me what exactly i need to be doing down to how i should be reporting it back so it looks very simple all i need to do is send out an email now i don't need to leave this um page to do that all i can all i have to do really is click on compose email i'll utilize the acknowledge for phishing template i can see how the email is pre-populated for me i can add in the recipient i change the title if i choose to do so and send out that email now while i'm waiting for the response which can either be received back through a simple yes or no uh this could also be sent out in a slack message where they can simply click on yes or no uh based on their response it would be reported back on my uh platform and based on the response whether it was a yes or no the workflow can take different actions so if they came back to me who are saying no they haven't interacted with the email then i can quickly close this as a false positive versus if they came back to me saying that they have in fact interacted with the email then in this case i am promoted to go ahead and isolate the host on how they have interacted with this email just to make sure that if there is a worm or a virus it does not contain contaminate the rest of our environment now while i'm waiting for the response one thing i can do is i can search the email and observables for all of the email servers that i'm currently uh working in so i can just look for the subject so the subject was um forward security alert i can just go ahead here say i want to look for all of the emails that have the subject within my email servers and i'm going to search uh just within a couple of seconds i the search results come back to me saying that they could not find anything now in another case i can say that i'm just going to search and delete because i don't want any other employees to actually interact with this email now if the search had came back to me saying that there are more than one affected users i can go ahead and see how the affected users are going to be automatically updated here which means that the business impact and the priority are also going to be automatically changed so in this case since we have only one user who received this email the business impact is high and the priority is low if the user stands into 5 or 15 or all of the organization then the priority is going to become critical and the business impact is also going to be critical because all of them environment is potentially affected with the specific phishing attempts to give you a better example of the search result i'm actually going to look at a specific use case which is the cdc again covering what we were seeing on these slides how there has been a surge in the fishing items between march and april 2020 so we created the cdc health alert again just to show you how fishing can be done in this case if i go into the investigation and search the email and observables for the emails that have this title which in this case cdc health alert i'm going to be actually seeing more information so it looks like five individuals have received this email and one of them have actually clicked on the email so there is a potential for an exposure in this case from robert to remediate against that i can go ahead and check the configuration items associated and isolate that host choose how i'm going to be isolating it through the universal demo generator in your case that could be the specific orchestration tool that you're utilizing to isolate the host click on that and that action is automatically going to take place without me having to leave this or anything like that enter the timeline is a way for us to keep track of all of the different tasks or all of the different um actions that have been taken through the playback and once we actually are done with the security incident then the assessment tab is going to appear where all of the individuals who had active tasks into remediating this security incident are going to be promoted with specific questions that you put into place just to make sure that what they have done did actually make sense and helped into the remediating process now before i move back into the presentation i'm just gonna quickly go over the miter attack map just to show you a visualization of how that would look like okay so this is the micro attack heat map for enterprise attack we can see how many um different attacks have been recognized on miter we can actually see our performance too so the detection coverage type the green ones looks like we have an excellent coverage and we can see how the red one means that we don't have any coverage on that and we can see also the mitigation coverage type and how good or bad that was within our environment um if you have any questions regarding any of the areas that i covered within today's demonstration please feel free to drop your question in the q a now i'm going to be pausing for a quick second to go back into the presentation to insta-date webinar with the last action items and how we can follow up on all of the information that i've covered in today's presentation so what are the next steps that we need to be aware number one security answer response what is our maturity module so within servicenow we have had four different our maturity modules that we can classify our customers within so we have zero where everything is being done manual versus three where most of the different um response tasks are orchestrated for remediation process so once we receive um a specific uh interested customer and we basically categorize them between these different numbers uh most of the time they rely somewhere between zero and two so within service now we can take the call walk run approach to kind of take you from wherever you currently are until we can reach a more mature state so this is how we uh basically make sure that the solution fits your own specific needs and how servicenow can provide more value into your own organization now over here this is where we can basically find different resources that can help us understand more about security internet response um number one would be the doc site so servicenow has the best documentation out there for all of their different solutions so you can visit the docs to actually get more information about security answer response setup and security answer response in general if you're interested in being part of our training for the security answer response we have two different trainings for securities response the security response fundamentals and the security into response certified implementation specialist this can be accessed on the now learning side so you can get more information about that on there for support you can visit the security response community which has a bunch of different individuals who are um using uh security into response now or individuals who work for servicenow who are familiar with security and response who can help answer your question we have the high support where you can submit different tickets if you already have the solution and you have questions or something that is not working uh the best way that it should be uh we also have now create with basic which basically walks you through the best approach into implementing the solutions if you choose to go through the self-implementation route or if you choose to leverage a partner we also have the partner finder where you can look at the different partners that exist within your areas or within your own specific um business and see which out of these partners would be a better fit for your own needs and lastly if you just want to get more information we have our youtube channel which basically has a bunch of different information about how to get started with security into response what are the latest releases updates and etc now thank you all for being part of today's security incident response the how to clinic webinar i hope this had provided more value to you if you're interested in learning more about the security entity response please feel free to get in touch with your sales team or visit our website where we can basically walk you through a generalized demo or when when when the need is there we can also walk you through a specific uh use case-based demo to make sure that servicenow security answer response is the solution for you i hope you've gotten some value out of today's webinar and we look forward to seeing you on future ones um i'm going to be hanging on for a couple more minutes just to make sure that i ha i don't have any questions in the q a part um if you don't have any questions thank you so much again and have a great rest of your day okay thank you all for being part of today's webinar we look forward to seeing your future ones have a greatest everyday

View original source

https://www.youtube.com/watch?v=6eggnP1LnFs