logo

NJP

How best to approach resilience strategy

Import · Apr 20, 2021 · video

[Music] our security vision for servicenow is to become the trusted sas provider what this means to us is for our customers to trust us with their most sensitive data to ensure that we build a secure platform and products to set and meet the highest standards and requirements especially given our financial services and public sector customers but to also foster a trust and security-minded culture internally in a way where continuously improving our security is part of our company dna how far we are along on this journey well that's our vision and our marching orders but it is very much a journey not a destination so that said it is important that we quantify our progress but also with agility so that we can react to changes in industry to unplanned events such as a pandemic and keep a strong pulse on security technology and innovations our first step in executing this vision is to align our security objectives with that of our company and our customers the second step is planning execution and transformation one of the core principles that we mercilessly follow is to endeavor to make security easier to make it simpler to make it by default and if we can to make it invisible bolted on security is never as good as built-in we do this by automation to stop spending too much time and stuff that we don't need to spend our time on so that our talent can be freed up to work on ever more impactful things for the business we're a strong believer in leveraging the core competencies of any business to enable success so what i mean by that if you have a furniture retail business that is focused on just-in-time delivery and asset management they're probably going to have a pretty strong cmdb if you're a security threat intel company you know just what sort of data exists out there on the dark net that could put your business at risk and you make this information into a product offering for your customers to enable their success as well for us at servicenow we work for it we build custom workflows to automate work but we also build workflow product portfolios that we leverage internally as stepping stones to accelerate our work which in turn we offer to our customers and this is a key component of our security strategy we often talk about our security products but those that are integral for our security program of our ability security incident response grc and vendor risk automation upon automation to make security easier for ourselves and for our customers to quickly share some examples of how we use our own products across the servicenow portfolio well we have item which allows us to have a current cmdb of all assets within the servicenow cloud which allows us to know exactly in which data centers a customer's data resides we use ppm to increase our program and project visibility with real-time dashboards and reporting before we did this we had hundreds of security projects that stayed in the green status stage quarter after quarter ppm helped us drive clarity on what we were trying to achieve and when we will execute on it security incident response it provides us with a single security incident source providing a holistic view of a current security incident landscape across our company and our customers and it does this by providing us with a consistent method for global incident response collaboration across our follow the sun teams and of course with associated kpis which we report straight up to the board vulnerability allows us automated assignment of volumes so when new vulnerabilities are added they are evaluated against a list of assignment rules to ensure that they're going to the correct team for remediation this also helps us for risk ratings so rather than simply relying on a scan vendors predetermined vulnerability severity we can prioritize volumes based on 100 point scale specific to our infrastructure to include concerns such as exploitability asset value and function and again all with dashboards to visualize status the final example that i'd like to share with grc we use grc to track security policies risks and controls it also maintains our risk registry which drives overall prioritization within our security program and is based upon a common control framework for consolidated regulatory and legal compliance requirements each year at servicenow like many of you we find ourselves required to achieve more and more certifications often the of which are geo-specific so for example mtcs for singapore iraq protected for australia many eu requirements and so on this would not be possible without the built-in workflow engine of grc mapped against nist so as more of our lives become digitized cyber attack surfaces will inevitably grow it's going to become more important than ever to embrace security as a mandatory concern for businesses to be successful the products i mentioned they do help us at servicenow in a great way but they are not the only parts of our security program how we partner with our vendors and customers how we integrate new technologies and manipulate data or essential components of our security program we need to become better at this in the future as an industry if security is to have any chance to keep up with the rapid pace of technology innovation and transformation now if i had a magic wand speaking hypothetically i would take all these technology providers and consumers alike and flip a small bit in their brain so that part of their brain is always thinking about cyber risk this would be at both the personal and professional level not only to protect your work but also the privacy and security of yourself and your families now given that i do not have a magic wand we need to keep doing whatever we can to continue to make the security basics easier for everyone you

View original source

https://www.youtube.com/watch?v=QDP4XJDMTM0