logo

NJP

Elevate Your Security Posture with Configuration Compliance and Continuous Monitoring

Import · May 06, 2021 · video

security risk and compliance leaders are challenged with protecting the confidentiality integrity and availability of business services and confidential information but as businesses grow and attackers become more sophisticated legacy approaches with a high degree of manual effort will no longer be able to keep up in this demo we'll show how configuration compliance can automatically connect security configuration information with compliance controls now misconfigurations can leave vulnerabilities wide open to malicious actors but they also have policy compliance implications third-party secure configuration assessment scanning tools can be used to automatically run configuration tests but the results can also be symptomatic of compliance control failures security teams need servicenow to work at scale automated triage service aware risk scoring and integration with policy and compliance management and servicenow can help teams stay compliant at any scale today we'll show how configuration compliance and policy and compliance management can be used together to achieve continuous control monitoring throughout the customer environment to start security manager carla jackson logs into their servicenow instance to view the overview dashboard here they can see the status of security configuration scan test results across all relevant dimensions policies tests hosts individual test results now these dashboards represent real live data they can be used to explore the environments and draw conclusions about security and compliance priorities now carla wants to see whether the organization is compliant with the cis benchmarks for windows server 2012 r2 and if not what configuration changes are most critical to bring them into compliance so carla will open a policy to show compliance across the whole environment in configuration compliance policies are collections of configuration tests that measure compliance against standards from authoritative sources like cis benchmarks we can see our compliance remediation percentage rolled up to each policy and all of its constituent configuration tests from here we can see that there are critical failing tests for password configurations that should be addressed with priority in order to secure the environment and increase compliance with the cis benchmarks now that we've identified our top priority we need to know who's responsible for these failed tests and how long have they lingered in the environment in the remediation tab of this dashboard we can see an overview of test results whose remediation is in progress this is where a vulnerability analyst or security manager can see whether the team's responsible for fixing misconfigurations are working on time we'll drill into this live data to see which critical test failures are overdue according to their remediation target let's see who's responsible for the password configurations here the security manager can view test results that have already been automatically assigned scored and given remediation targets all by rules that can be easily configured within the servicenow platform exploring real data directly from the dashboard can help the security manager to quickly identify the status of work on these items and report overall trends to executive stakeholders with confidence in our case we can readily recommend increased attention on password configuration compliance and we can involve the sock tier 4 team to assist now that our security manager has identified the top priorities for configuration compliance let's look at the same data from the perspective of a compliance manager configuration compliance policies are different from policies in an integrated risk management environment like policy and compliance management but configuration policies like cis benchmarks can help to demonstrate compliance with control standards like ucf hipaa pci and iso continuous control monitoring enables you to monitor compliance with regulatory standards like pci automatically by looking at security data the underlying configuration tests in configuration compliance can be mapped to control objectives in integrated risk management so that test results automatically flow through to controls now the compliance manager is responsible for controls for a set of windows servers they log into their servicenow instance to see the overall compliance score for the assets they own and investigate any failing controls in our case this compliance manager owns three window servers and we can see that there are six failing controls on those servers the compliance manager can open the controls for one of the servers and see that there are multiple failed password configuration controls that are affecting those servers compliance the platform knows this automatically from the configuration tests that are associated with these controls on this server now the compliance manager can act to prioritize these fixes by working with it remediation owners if the configuration test failure is not remediated then this issue will automatically appear in the next audit of this asset so now let's see how this test failure gets fixed in servicenow the it remediation owner logs into their servicenow instance to see what's assigned to them and work on their open test result groups test result groups allow for many test results with similar remediation paths to be grouped together and worked on all at once test result groups can increase the efficiency of customer remediation teams and help fix configuration issues faster at scale it just makes configuration tests easier to work with in our case the remediation owner needs to look for high priority password configurations that are ready to be patched we'll find the password history configuration that was causing our failed control earlier from here the remediation owner can easily create a change request to fix the failed test for all affected configuration items now if we were unable to fix this configuration we could also request an exception but in our case we're ready to bring these servers back into compliance as soon as possible so we'll create a change request the change request is automatically populated with details from the configuration test and the associated configuration items we can create a normal standard or emergency change and even take advantage of your pre-configured standard change templates thanks to the auto population we're ready to submit this change and let it be taken through your change management process once this change is implemented the next secure configuration scan should confirm that the test passes and our policy and compliance control will automatically be marked as compliant through continuous control monitoring today we've seen how servicenow configuration compliance and policy and compliance management can be used together to achieve true continuous control monitoring allowing you to view high-level compliance score roll-ups and fully automate reporting at the compliance control and configuration test level to keep your policy compliance scores up-to-date

View original source

https://www.youtube.com/watch?v=YLiqHAwy0MM