How To - Vulnerability Response
hello everyone welcome to the how to clinic for security operations vulnerability response i'm going to be kicking in the webinar in five minutes just waiting for all of the attendees to come in thank you so much for joining us hello everyone welcome to our uh webinar for today uh i'm just going to wait just a couple more minutes waiting for all of the attendees come in so um just sit tight we're gonna start shortly thank you so much for joining hey everyone thank you so much for joining us today um welcome to this how-to clinic for security operations vulnerability response my name is mohamed nasir and i am a senior digital solution consultant who is specializing in the security operations offering gluten service now thank you so much for joining us uh before we get started this is just a privilege and financial information safe harbor notice for forward-looking statements so this presentation contains forward-looking statement that are based on our management belief and assumptions and information currently available to management so we intend for this such forward-looking statement to be covered by the safe harbor provision forward-looking statement conditioned in the us privileged security litigation reform act 1995. what we will be covering in today's session is how to get started with vulnerability response implementation key concepts and skills for using vulnerability response best practices and additional resources uh here's our agenda for today's session we're going to start of management of brain abilities vulnerability response goals moving to how vulnerability response works uh then we're going to discuss the credibility response implementation best practices moving on to the inability response lab which is going to be substituted with a demo portion for today and finally next steps which are we usually follow up where to get more information about vulnerability response community forums etc uh throughout the entire course of the presentation or the demo if you have any questions please feel free to drop them in the chat and i'll respond to them when we get to the q and a section or if i notice them before then so starting off let's start with management of runnability's best practice for vulnerability response why is vulnerability response important and why do we focus on vulnerability when it comes to cyber security so most problems are solvable but yet they are undressed as you can see in my screen here 39 of breach victims knew that they were vulnerable before they were reached and 60 percent of breach victims said that they were breached due to a vulnerability for which a patch was available so um a lot of victims are actually aware that they are vulnerable in some areas it's just that they haven't gotten to it because of poor practices manuals processes and all of that which usually prevents them from taking the appropriate action at the right time another issue that we usually find the stretch budget for its operation security project security budget increase so um a lot of the time when we are discussing uh cyber security with management um and all of that they usually bring up uh budget as a major concern um one thing that we usually neglect is that the money that we usually put into security operations is potentially going to save us from much more that we might have to uh pay whether that was for reputational damage or for uh just patching the vulnerability or the security that uh threat that we've been exposed to so um according to this slide we can see that the projected security budget is gonna increase uh and it's just gonna keep on increasing until we reach the limit that is potentially going to put us all in financial risk and danger so how is today's processes affecting us as you can see today's interaction between i.t and security usually they exist in silos even though they both work under the same environment and both are really addressing the same devices and operation so uh most of the time the security team find something like a vulnerability or a threater alert send it out to it for them to patch it or for them to work on that threat assessment etc um you they usually are communicating whether through emails through phones uh through docs or spreadsheets or through actual mode of mouth which creates a lot of stylus between these departments and creates a lot of manual steps um and later on we're going to actually see a presentation on how that looks visually when we are waiting to hear back from i.t or it is waiting to hear back from security without really a single pane of glass that connects them both so um this is one of the major areas that we are going to focus on today and how we can basically cancel the silos and have both of the team work in harmony so what is the vulnerability response goal now variability response is basically going to help us in three major areas the first area is going to be visibility so we're going to be able to identify which system we're affected with the specific vulnerability or threat prioritization so out of all of the systems that have been basically uh identified as a vulnerable system or uh affected system we can prioritize which one out of all of these events we or these ci's we should be working on first and er indication so we're gonna be able to remediate acid and automate the workflow that goes on uh when we are working on patching a specific vulnerability so servicenow vulnerability response can help you in the visibility by basically offering you a single page of glass a centralized visibility of the vulnerabilities data business context and risk so we're going to actually understand why we are giving the priority to that specific asset or this specific vulnerability uh prioritization carrying on into that so we're gonna increase the productivity and reduce backlog attacking uh critical uh work first so we're gonna be able to focus our attention on what really matters rather than being scattered all over the different vulnerabilities some of them would be false positive some of them would not have a high criticality or high business impact so we're going to put that on the side and focus on what actually matters when it comes to these different ci's and variabilities repeatable processes automate workflows and ensure faster remediation so we are cutting out the manual process that we often see again the silos that is created and we are basically helping making the patch process so much faster and this is critically important when we're discussing things like zero day uh vulnerabilities like the log4j uh vulnerabilities that we all had to suffer through um in the past couple of months so we are going to be able to see how we can leverage servicenow vulnerability response to help us in all of these different areas we're also going to be able to build a cyber resilience with servicenow so servicenow does not only offer security operations it has a bunch of different offerings it operation management which usually helps us in building and maintaining the cmdb that's also going to be leveraged into prioritizing the different events that we're receiving uh in vulnerability response uh we have i.t service management where we can coordinate things like uh change request problem management etc which also helps us in their mediation process for the different variabilities so we can see how all of these different solutions that are built on the core in our platform are gonna work hand in hand to make our life so much easier when it comes to handling brain abilities and different threats another offering that servicenow has when it comes to vulnerabilities application specific vulnerability response so this is one of the latest releases that i believe we released back in paris we're currently in our own release where we are able to integrate with their code scan to das dynamic application security testing result uh we can centrally track and prioritize all application vulnerabilities based risk improve collaboration between security and development team for faster remediation and flexibility adapt security policies based on results and promote promote safe development practices so we this also allows us to gain an actionable insight into the application vulnerabilities so we are again utilizing the third party uh integration with service like very code uh using readability response to identify where the vulnerabilities are which are the affected applications the software releases that have a vulnerability and utilizing that cmdb um that i have mentioned previously would also help us in analyzing the risk that is associated with these application vulnerabilities uh help us in putting an assignment group and rules policies uh that potentially can be impacted so help us in the assignment process when it comes to these applications specific vulnerability depending on the skill level or maybe the operating system that the individual would need to be familiar with to work on these applications and we can also work on the exceptions and dependencies uh process with application variability response this is just a visualization of how to identify an asset software in this configuration which is another offering that is within renewability response some licenses so we can also leverage the information that we're getting from the different uh vulnerability scanners and to actually checking our policies to make sure uh that we are um in compliance with the specific frameworks that we would like to be in compliance with so for example if we need to be compliant with iso pci etc then we can measure that when it comes to the different configuration of the devices and application that we have and see whether that's going to affect our compliance status accelerate remediation end to end so uh again we're focusing on visibility prioritization and patching uh stop using spreadsheets so we're going to cancel all of the manual process hopefully avoid patch disruptions so we're going to focus on the appropriate time to apply these specific patches integrate data into one platform so rather than having all of your um analyst engineers uh swirl trailing between all of the different integrations that you have within your environment uh servicenow again is going to provide you with a single plane of class where you can uh view and uh take appropriate actions on all of these different uh devices automate and report again through our workflow magic we're going to be able to automate most of the manual process and allow us to have a much faster remediation time now how does vulnerability we've already seen how or why is vulnerability response important now we're going to focus on how vulnerability response works and how the servicenow platform security operation really integrates with your environment now this is a slide that i usually like to start with where i'm basically just describing the general idea of how servicenow um vulnerability response or securities response really works and fit into an enterprise so as you can see we have a bunch of different devices that we usually have within our environment some of them are detection software some of them are cms some of them are vulnerability and configuration uh all of these events are going to be flowing into the servicenow platform along with any user reported ones whether that was phishing or a specific physical um threat or anything of that nature um after that we're going to be utilizing the cmdb if we happen to have one into making a prioritization of the difference in vulnerabilities that we've received um apologies on that there you go so um after that again we get we're gonna be leveraging the cmdb into helping us ready for these different events and alerts that we've received now if we don't happen to have a cmdb then we can leverage our own implementation rules so for example we can say that if a vulnerability exists in one of the specific uh critically important departments in our environment and that brings it to a higher criticality or we can do things like if it exists on a successful computer then this is definitely a major variability or a major security incident so we can also promote that or we can use a combination of the information that is within the configuration management database and those implementation rules and to help us set the appropriate priorities for these events and alerts uh depending on the kind of event and alert servicenow is going to automatically assign the appropriate workflow uh which again depending on the um kind of alert or vulnerability uh that can take several actions so whether that was putting the device on current team until we actually perform an investigation or if it was delegating the appropriate tasks to the different teams then we're also gonna be uh utilizing the workflows for all of that uh it connection is deeply integrated with all of that again this platform is working on cancelling the silos so it's important to have it and security continuously connected um analytics and threat intelligence information is going to be utilized to help us with the investigation for these different events and alerts just to make sure that we are actually gaining um enough information to make the appropriate decision uh machine learning is something that is embedded into the servicenow platform so one of the things that the platform is going to be capable of is that if it receives a variability and it doesn't have the appropriate rules for it to be automatically assigned to the appropriate individual uh someone is going to go in and manually assign it now the next time we receive the same vulnerability uh servicenow is going to keep track of the last time where that vulnerability has been assigned and automatically assign it to the same individual without having to go in again manually so this is the machine learning portion of the platform uh exploit and solution intel is gonna basically help us into uh understanding what is the best approach when it comes to the different vulnerabilities on threats and how we can properly handle them the environment is also capable of orchestrating uh different actions so if we again meet currently in an item uh search and delete the emails that are suspected of having a phishing attempt etc uh we can orchestrate all of that on the devices without having to go in manually and do them so with a simple click of a button we can take care of that orchestration now in the next slide this might actually paint a better picture with some of the different logos that translate into these different devices so for detection we have a bunch of different integration with uh some uh with a lot that more than uh the logos that you're seeing on the screen these are just a simple example uh for the full list of integration please feel free to visit store.servicenow.com which enables you to see a full list of the different integration that is possible with security operations so again for vulnerability and configuration we have tenable qualities rapid 7 rare code threat intelligence miter attack virus total crowdstrike exploit and solution intel showdown red hat microsoft and for orchestration we can also orchestrate that with palo alto um microsoft active directory uh et cetera so how it works um first step is integrating your vulnerability scanner we rely heavily on the integration with third parties so we it's important that we make sure that these integration are set properly and this is something i'm going to be actually discussing when it comes to the vulnerability response implementation best practices after that we help prioritizing these events again based on the information that we have in the cmdb or utilizing information that we have in our environment we had set ourselves so based on this canon risk score based on the business impact business criticality that we set ourselves uh based on information that is available on um publicly available lists like the national availability database from nest or the common weakness enumeration list so this information can also be utilized in helping us make the appropriate prioritization after that servicenow takes a unique approach where it groups the vulnerabilities together rather than just create random vulnerability for all of these different ci so if we have two vulnerabilities for example within uh windows and one vulnerabilities within mac then it's gonna create two different groups making it easier for us to later on assign it to the appropriate team which takes us to step four so we're gonna take the appropriate skills that we have within our environment and automatically assign it to them so we can specify that the windows team gets windows vulnerabilities the mac team gets magnum abilities of course there is uh much more uh possibilities rather than just operating system but this is just a simple example now after we uh receive the vulnerability and we prioritize it and we assign it to the appropriate groups then we can automatically either create a change request on exception request so if we don't have a solution and we need to just wait for an exception or wait for the vendor to release a fix or if we are um we have a solution and we are just waiting for the appropriate maintenance window then we need to submit some sort of an exception to just say that the record for the vulnerability is not going to just be open we're rather just waiting on the appropriate time or we're waiting for the appropriate patch so we can actually manage all of these exceptions on the platform itself uh just making sure that no vulnerability is just left open where it could potentially be patched just because or sorry exploited just because we have neglected it for too long now if we are ready to work on the vulnerability we can coordinate the change requests that are usually needed for the ability to be patched or for maybe a device to be current etc all of that on the same platform now after we hopefully successfully patch the vulnerability uh then we're gonna wait for a confirmation from the vulnerability scanner that had first identified it so servicenow falls in item format what that that what does that mean is that we rely on the entity that had created the record for the record to be closed so if it was created by a human we would need the human to go in and confirm that the um ticket or the record has been patched successfully and then we close it in this case since it was created through the integration with availability scanner then we're going to wait for the vulnerability scanner to go back into the environment perform another scan confirm that the vulnerability that it has discovered has been patched successfully based on that information the record is going to be closed on terms now uh reports dashboards and kpi analytics are automatically generated helping us keep track of all of our efforts making sure that we are actually performing to the standards that we have created or set i mentioned that i'm going to be going over some of the visualization of the manual vulnerability response process that we often see in organization as you can see there is a mixture of automated versus manual steps and we can see how the remediation effort is usually stretched from hours to days to weeks and that is just because we are relying on a bunch of different manual steps that are embedded within the automated ones so it just makes it harder for us to make the remediation process faster so how would that look after implementing something like servicenow we can see how most of the manual processes have translated into workflows uh which translates them into automated processes so we can see that there is just a very minimal amount of manual process where it's absolutely needed uh so we can see how the remediation time is cut down from this period of days or hours into just a couple of minutes max an hour depending on the availability of a patch or depending on the possibility to perform the patch on that time now um i'm gonna go ahead and discuss how we can um what is what are the vulnerability response implementation best practices um but before i do that just i'm just going to take a quick break to close the window because i feel like the traffic is too loud so just a quick second think about that everyone vulnerability response accelerator uh number one is to look for your integration so the first step into getting your vulnerability response up and running within your home environment is through installing the appropriate integrations uh for the security devices that lay in your organization environment so as i mentioned previously we rely heavily on the information that is we are receiving from this third party integration so before we actually jump and say let's get rentability response we need to make sure that we have the appropriate devices that can be integrated with the platform so there are different approaches on how we can do this or if there is an integration that does not exist how we can handle that so the first step would would be visiting the store.servicenow.com to check if a rebuilt integration is already available um and there are basically a bunch of different integration that have been built hand in hand with a bunch of or the major uh security offerings so tenable qualities all of those have prevailed integration that we can already just leverage um if the integration does not exist or if we're using some sort of a new um service that servicenow still hasn't built integration for then we can custom build that integration if they have an open api then we can just simply um do that or we can leverage a pre-built partner built integration so one of the things that we advocate for when it comes to vulnerability or security into the response is that we want to leverage the appropriate partner because it makes the implementation so much so much easier some of these partners have already built integrations for devices that they commonly see that does not have an integration with servicenow or if you have your own maybe homebuilt device or a service then you can leverage that partner into helping you build that custom integration um the second accelerator i would say is understanding your current architecture so in order to manage vulnerabilities properly we need to understand how that process currently going and how we can actually improve on so things to consider here is we want to know how the prioritization of your organization services and assets so if we don't have a theme to be into place we need to know what are the critical business uh devices or applications that we have and how important these are to us and what are the services or servers they set on and that also would be considered when we are receiving information about them into the prioritization we can also we have to understand if there are any slas or policies that we might reach uh by not responding to a specific vulnerability or a threat in time so this is something that we also need to keep in mind when we are implementing uh vulnerability response the third one would be organization ability to send patches across multiple devices so some organization utilizes services like microsoft as ccm um if that is a possibility then we need to keep that into consideration as well just to make sure that we are um set for success uh number four would be available vulnerability groups and their assignment rules so if we already have the appropriate teams be built and we are just doing everything manually that all can be translated into the platform um we can just say that the group that we've already been leveraging for this kind of vulnerability is going to get all of these vulnerabilities that we have specific criteria for we can translate that into our workflow so rather than doing all of that manually it's automatically done now if we don't have that process built now then we can set before the implementation and actually discuss which team should be getting which vulnerability it just makes it so much easier when it comes to delegating the different tasks to the appropriate groups this is just a visualization of what i mean when it comes to the understanding of current architecture of the organization vulnerability efforts so we we need to understand what earth is the data we are receiving how we're going to prioritize and prioritize them whether that was through the cmdb the cvss data or the exploit data i want to say one of the last vulnerability response accelerator is to understand your assets so understanding your assets allows you to prioritize your efforts and your task assignments within servicenow you can achieve this by three different things leveraging your pre-populated cmdb so if you have a cmdb that's great if not then we can work on that while we're doing that we can leverage something like a third-party asset application like microsoft sccm or a servicenow itom discovery which is number three so leveraging servicenow discovery if we don't have like a third-party integration and we have itom discovery then we can leverage that into building the same dvd or rely on our manual prioritization rules uh if we don't have a cmdb if we don't have a party asset application or if we don't want to leverage servicenow discovery we just want to build our own implementation rules that are going to help us into the prioritization of the different events and alerts that we're receiving then this is something that we definitely can do or the best approach would really be a combination of all of the following so if we have a cmdb but we sometimes want to put specific rules for specific alerts or specific departments then we can do a combination of all of the different offerings within this slide now hopefully i've gotten you excited to see how vulnerability response really works in action so um i'm just going to pose here for a quick second to pull up my instance and actually demonstrate the vulnerability response solution again please if you have any questions or any things please put them in the chat window and i'll be happy to respond to them in the q a section or before that okay so hopefully everyone can see in my screen okay um starting off the demonstration i'm gonna be um just pointing you um to something is that i'm going to be conducting the entire uh demo from a single persona this persona has the access rights to all of the different tables with informability response so think of it like an admin uh hence why they are able to see all of this data now once the implementation is hopefully done on your end this might look a little bit different depending on the access rights that the individual using the platform has so starting off i'd like to go with um with this sister dashboard because it basically gives us an overview of the security posture within an organization so as you can see the ciso is able to see the vulnerability response what is the azure time it takes us to respond to different vulnerabilities uh same thing when it comes to security answer response which is another offering within security operations uh just i wanted to point that real quick uh we can integrate with the configuration compliance so again based on the different policies that we have we want to make sure that we are in a compliant state how does that translate when it comes to our security department that information is available to us with just a click on this graph we can see the security specific policies and how compliant we are with them the risk overview of the different threats and vulnerabilities that we have and how they translate into different categories so operation financial i.t reputation etc uh there are any approval requests that the uh ciso need to attend to i like to incorporate this so just in case to give them a quick access to that they can just simply click on here see if there's a policy they need to approve or something if that needs to now here on top you're going to notice that we have a bunch of different tabs now these tabs are basically dedicated to help the cso actually dig deeper into different areas or different offerings within security operations so incident handling would be to dig in deeper into security into the response but that's not today's topic so i'm just going to move on to the next one system hardening which helps us dig deeper into the different vulnerabilities and vulnerability response in general so you've already seen the vulnerable response what is the average time it takes us to respond to different vulnerabilities uh just to make sure that they are getting the latest information without having to get in touch with the appropriate department etc they can just click on refresh and they are guaranteed to be able to view the latest information uh they can interact with these different graphs so for example here i only have the vulnerability like the mean time to remediate but if i want to filter that out i can just simply click it on it and it disappears or i can click on it and it appears again over here these dots basically represent the forecast performance so based on or utilizing performance analytics we are able to forecast our performance into the future so based on how we were doing things how we are currently doing things this is our foreseeable future forecast we can actually also click on the graph which takes us into a more or manual details of the information that we were seeing so it looks like the average time for response right now is sitting sometime on 13 day if i as a system want to create a target to have my employees uh be done with the vulnerabilities or be able to patch them within six days i can create that target here associated with the appropriate start date review date which helps me just set a specific objective and help me also measure uh working toward achieving that objective so if you see on the screen right now i teared on the trend line which helps me see how my performances currently is just to make sure that i'm actually working toward achieving the six day objective that i have created i'm also able to create or turn on the labels just to see down to the minutes where we were when it comes to the mean time to respond in the previous time going back into the um dashboard we are able to see the most vulnerable ci's by the different class so from this view the cso is immediately notified that the most vulnerable asset they have is when the server and total of 2794 vulnerability versus the application vulnerabilities or the iphone vulnerabilities so this puts us in a place where we know where we where we should be really focusing our attention when it comes to patching vulnerabilities or if it's giving us an information of maybe a specific application that is very vulnerable and we might have just a conversation of potentially replacing that with a much more secure application or hiring more individuals to help us patch the vulnerabilities that are associated with that application uh we can also see the most prophetic vulnerability ids so these all of these different ideas are imported from things like the national variability database or the common weakness animation list so it helps us to know how many vulnerabilities of each kind we have within our environment configuration compliance again helps us make sure that the different application devices services are configured properly uh to help make sure that we are in a compliant state when it comes to the different um authority documents that we need to be compliant in now the rest of these tabs are basically going to be dedicated for things that are related to grc or irm so business risk is something that we can create if we have the rm license also in servicenow just to make sure that we have the appropriate risk calculations policy and control this is where we can see the different compliance percentage trends for the appropriate um policies within security we can see the compliant versus non-compliant entities and the citation by authority documents so as i mentioned pci um eu 26679 um iso et cetera we can actually combat we can just click on them see the appropriate citations that we need to be compliant and and see the different controls that either put us in a compliance state or non-combined state and basically help us make or reach a more compliant state so this is just a quick overview of the system dashboard just how sso would be able to see an overview of their security posture now jumping on something more dedicated for vulnerability response this is the vulnerability management pa dashboard which allows us to see information like how many total vulnerabilities do we have within our environment versus the total number of rentable items vulnerable configuration item vulnerability by their age vulnerabilities item by the risk grading uh we can filter that out based on the assignment group based on whether the availability exploit exists or not based on the exploit attack vector etc if we have different departments or different operating system then we can also view this dashboard based on that so we can have a filter for mac a filter for windows a filter for unix etc we are also able to check what are the most vulnerable services that we have along with information and who owns these services this all this information again is imported from the cmdb we can see the vulnerable ci's so again measuring or mirroring what we were seeing on the system dashboard we know that most of our variable uh vulnerabilities exist and when the servers and computers so just a view into that from an analyst view or a manager view this is a tab that helps us measure the exceptions so we can actually see how many expanding different requests we had this week or are about to expire uh help us into prioritizing our work this is the deferred variable items by the different reasons so how many because there was an available fix or how many was because we have a mitigation control in place or because this has been accepted etc uh we can also track our remediation efforts so we can see the vulnerability groups by the risk and risk rating and state we can see the vulnerability group by address creating and numeration target status critical vulnerability groups by assignment group etc now i did mention um how we have basically a bunch of different integrations with uh things like the national availability database or the common weakness information list so this is just a quick view into how that looks like so over here we have the list for the national vulnerability database and period so we can see um that information clicking on it we can see how many vulnerable items of the specific vulnerability we have in our environment what is the exploit the solution the weakness etc now moving on i'm going to be going to the vulnerability management workspace to show you how we basically can create watch topics for specific vulnerabilities which again helps us into uh dedicating the uh tasks to the appropriate teams and just help us monitor specific vulnerabilities with specific criteria so as you can see here within the vulnerability management workspace i'm able to see all of the different watch topics that i have created so we have vulnerabilities with external facing assets or vulnerabilities with exploits available or log for shell vulnerabilities that we have within our environment if we want to create a new remediation effort we can simply just click on create remediation effort associated with the name and description specify the criteria that we are looking for and then the watch topic is automatically going to be generated so this one that just gives you a better overview of the vulnerabilities that are critical overdue vulnerabilities so this is the overview how many vulnerable ci's we have we can actually see a distribution on that by their ci class the internet facing the eyes that we have how many distinct vulnerabilities we have that are critical of radio variability and what are the appropriate vits or vulnerability uh verbal items so after we create these watch topics we can also create the assignment groups for them so um we are basically saying that as soon as we receive something of this nature then automatically assign it to the group when the server or endpoint security etc so this is the view a manager would typically have for the watch topics how would that look like on an analyst view over here we can see the errors view into what are the different tasks that have been assigned to them specifically or to their group so as am right now i'm able to see that there are 64 assignment remediation tasks that have been assigned to the groups that i'm in and nine preferred solutions that have automatically been uh created or associated with the vulnerabilities that we have so if we click on availability here at random we're able to see their mediation process timeline so it looks like we are 88.89 done remediating the specific vulnerability more information about the vulnerability over here and this has been imported from the integration with the national vulnerability database or the common weakness information list we can actually also see this detail over here so if we just want to look for him at it from a different view we can see how many vulnerable items are associated with the specific vulnerability how many affected ci's we have along with the information like the location description class when it was last updated all of this information is imported from the cmdb if there are any change requests that have been created this is where we can actually measure that or look at them track them etc if i want to change the assignment from my team member over here kevin to me i can just simply click on assign the remediation task to myself uh based on my investigation if there is this specific task is not an actual vulnerability or if i want to mark it just as false positive because my investigation had concluded that i can just go ahead and click on mark as false positive and the record is going to be indicated as such we can create a change or associate it with an existing change by simply just clicking on here um if there are a bunch of different tasks within this task that i would like to distribute among another team member or another team in general i can just split the task from here if i need to request an exception based on the fact that there are different reasons like the risk is accepted we are awaiting a maintenance window the fix is unavailable other we can just quickly do that with a simple click of a button and based on the reason that we indicate uh we can have the workflow take different actions so if we simply are going to say the risk is accepted the in workflow can go back and look at the risk rating and the criticality of the vulnerability that we are accepting at risk and maybe we can say that if it's below 50 then automatically accept or if it's above 60 then require a specific approval so all of that can be configured into the workflow the basic depending on the course of action that we take and if we actually had patched the vulnerability we can just simply click on resolve and close the vulnerability record which in uh going to later on be translated into the environment asking us whether we want to close the vulnerability record for now and wait for the confirmation from the vulnerability scan or leave it open and wait for the vulnerability scan to perform another scan and find that that vulnerability has been passed successfully and then go back into the environment and close that the vulnerability so it's just a matter of preference at that point now this was just a quick overview of how vulnerability response really looks like on the servicenow instance for a full-on demonstration that really goes into the details of everything that i have covered so far uh please feel free to reach to your sales associate or uh reach out to servicenow in general and we would be happy to set a conversation time where we can actually sit and discuss the different details uh within or on the platform itself now going back to the slides so going back into the slides uh what are the next steps that we can take from here uh the vulnerability response maturity module so we want to understand where do we sit on the maturity module of rentability response in order for us to actually be able to move to the next step so are we currently sitting at all manual processes or manual operations where we are at the zero or we have some automated prioritization but we're still not uh into the enterprises trending uh state so that would put us at a one or if we're sitting somewhere between a one and a two so 1.5 which is mostly common within organization so servicenow vulnerability response is really going to be able to take you step by step from a level 0 all the way to a level 3 and just continuously improve on your efforts when it comes to the vulnerability remediation lastly over here uh these are a bunch of different um resources that you can utilize for your investigation when it comes to vulnerability response so we have the doc site for security insurance response and vulnerability response where you can actually go ahead and dig deeper into the information uh all of the details with our environment we have a great documentation for all of our products so you can definitely leverage that into getting more information about vulnerability response uh if you are interested in our training so we have a bunch of different trainings dedicated for security operations on now learning so you can go through the security operation fundamentals which basically walks you through sick ops in general uh you can choose to go through the vulnerability sponsor to find implementation specialist course which allows you to uh really sit on a three-day journey uh into understanding how vulnerability response should be implemented within an environment and what are the best practices from there [Music] you can also uh visit the vr community which allows you to see more information or discuss specific topics with experts and variability response or other individuals who have vulnerability response within their subscription uh you can also visit the high support if you currently have variability response and you need the support in a specific area now create allows you to see the appropriate or this is just a template that servicenow has for implementing its different offerings so this is something i strongly recommend uh if you're ready to communicate with a partner to see how the implementation journey would look for your own environment then we definitely suggest the partner finder to find an appropriate partner that is certified and vulnerability response to walk you through all of the implementation process finally if you need to just see general videos on what is vulnerability response and how renewability response works you can definitely check vulnerability response for beginners on youtube and that basically concludes our how to clinic for vulnerability response i really hope that you've gotten some value out of this presentation uh if you have any questions or any comments please feel free to reach to me directly my email is m.naser at servicenow.com or if you'd like to you can speak to the servicenow team uh to uh basically schedule an up deep dive deep dive demonstration on the vulnerability response solution and how that would work for your own specific environment again i thank you for your time today i'm just gonna uh check if i have any questions in the chat and if there aren't any i'm just going to go ahead and in the webinar so thank you so much like i'm not getting any questions on the chat so again thank you so much for being part of today's webinar we definitely look forward on seeing you on future webinar webinars hosted by servicenow have a great rest of your day
https://www.youtube.com/watch?v=B3nOw-FtEKA