logo

NJP

Wiz Integration with ServiceNow Vulnerability Response

Import · Mar 01, 2022 · video

risks in the cloud are more complex than ever and span across interconnected issues and resources but vulnerability management teams still need to remediate them as quickly and effectively as possible to do so they need to be able to see across their cloud environment to identify vulnerabilities understand which are the highest priority based on correlated risk factors and compensating controls they have in place and ensure that the highest priority vulnerabilities are routed to the right teams for speedy remediation as seamlessly as possible with the latest integration between wiz and servicenow vulnerability management teams are able to do exactly that wiz takes an agentless approach to scan your entire cloud environment including in-depth scanning for virtual machines containers and serverless functions wiz then analyzes everything for a variety of risk factors such as vulnerabilities malware effective exposure excessive permissions exposed secrets and more armed with this information security teams can focus on remediating the highest priority vulnerabilities first what's important here is context when it comes to prioritization the severity rating of a vulnerability is not enough say a vulnerability detected on a virtual machine has a cvss score of 8.9 that seems high but how risky is this vulnerability to your organization to determine that we need to understand the context around the vulnerability on which asset was it found what role does that asset play in your environment if the asset has an exposed secret that can lead to sensitive data then the business impact of the vulnerability is higher if the asset itself is exposed to the internet then it's more likely that this vulnerability could be exploited context like this is crucial to understanding which vulnerabilities matter the most to your business and for prioritizing your remediation and that's what wiz and servicenow offer security teams once you've prioritized your vulnerabilities the next step is to remediate them wiz and servicenow customers can now integrate with vulnerability detection with servicenow vulnerability response let's take a look at this in action with a brief demonstration once we've requested the wiz integration from store.servicenow.com and installed it in our instance we're given access to the wiz integration dashboard this is where the vulnerability manager and administrator can keep track of the performance of the wiz integration itself we can see information like the status of the integration runs over the past 30 days as well as information about the number of configuration items that were imported new vulnerable items that were created etc now vulnerable items or vis are a single vulnerability paired with a single configuration item thus it's possible for one configuration item to show up in multiple vulnerable items and vice versa in order to simplify work vulnerability managers can group vis into work tasks called vulnerability groups based on specifications they choose like grouping all vulnerabilities discovered on a single configuration item together we'll take a look at how that's done a bit later we can also keep track of the performance and throughput of the integration runs as well as see details about each run that happened that's all well and good but what does the data actually look like let's take a look at the vulnerability manager workspace this is a workspace designed specifically for vulnerability managers like us to monitor vulnerabilities in the organization and assign work to the appropriate teams we can create custom watch topics such as the one that i called vulnerabilities on cloud assets this captures data from all the vulnerable items that were detected by whiz now we can view the active vulnerable items over time the votable items in remediation efforts and we can even see the active remediation efforts that are associated with this particular watch topic we can also view the number of distinct configuration items as well as the distinct vulnerabilities we can even view the individual vulnerable items that are associated with this particular watch topic we can easily assign vulnerabilities out to the appropriate it teams for remediation by creating a new remediation effort we can generate remediation tasks the vulnerability groups mentioned earlier using assignment groups assignment groups and configuration item assignment groups and vulnerability or we can generate them after the fact by choosing none let's take a look at one of the vulnerable items that was created and there's a few key things to note we can see the state of the vulnerable item the risk rating it was assigned by servicenow vulnerability response as well as the remediation target date we can see the reason why it was given that remediation target based on the target rule that was created by the vulnerability manager we can even see which group this vulnerable item has been assigned to a wealth of information is provided by wiz about the configuration item itself such as the name the category in this case virtual machine the asset tag as well as whether or not it's internet facing it also provides information about the associated vulnerability that's been discovered on this configuration item we can also see the number of times this particular vulnerability has been discovered on this specific configuration item finally if we as the vulnerability manager want to take direct action we have some options available to us from this screen we can mark this as a false positive if it is such we can choose to resolve it directly or if we need to request an exception for example extending the remediation target date we can do so here that was a quick look at the integration between whiz and servicenow vulnerability response if you'd like to learn more please visit us at www.servicenow and www.wiz.io thank you

View original source

https://www.youtube.com/watch?v=gN_-o2O57Pg