Technology Workflow - San Diego Release - Vulnerability Response (VR)
hello everyone welcome to the now platform san diego release feature my name is mohamed nasir and i'm a senior digital solution consultant specializing in security operations and today i'm going to be covering what's coming new in vulnerability response so for vulnerability response there are three major upgrades that are coming on within the san diego release number one or the first upgrade would be the new workspace for it and vulnerability managers which is an upgrade that's going to be available to all of the licenses within uh security operations that has vulnerability response so there are three major highlights within the uh these new workspaces number one is the workspace for it remediation owners highlighting id centric task uh number two workspace for security to create remediation efforts and number three boost collaboration between security and i.t on modern user experience of this is what the vulnerability manager workspace would look like so we can see how the vulnerability manager would have the ability to create different watch topics that highlight specific vulnerabilities or they can create watch topics that are basically going to be acting as if they want to look at into a specific ci to see if that ci has any vulnerabilities associated with it now what we can also do is that we also have the ability to assign these different vulnerabilities to the appropriate individuals that have the ability to go in and actually patch them so uh just looking at an example here the critical overdue variabilities we can see how many vulnerable ci's we currently have uh the distinct vulnerabilities that are overdue and critical and the uh number of vulnerable items that we have we can also see the different assignment groups that had automatically been assigned once we have uh recognized these vulnerabilities or integrated them from the third party scanners now if you move into the it remediation workspace so uh someone within these different variability groups would have access to this workspace where they basically are going to be able to see the different assigned remediation tasks that they need to take care of to patch the vulnerabilities that are assigned to their groups or they can get an access into the preferred solutions within their different uh vulnerabilities that they need to be working on the second feature would be the tenable io integration for configuration compliance which would be available to the professional or enterprise licensed within vulnerability response so within that we are getting three major highlights import assets from tenable io to the service now cmdb view configuration test test results policies and authoritative sources and prioritize test failures using the risk score calculator and finally integrate with itsm change management for remediation now if we look at the platform itself once we actually go into the setup assessed we are going to be able to configure different vulnerability scanners one of those is going to be the integration for tenable i o as you can see it's very quite simple to integrate with lio all we really need to provide is the account name the instance url the access key and the secret key following the different steps that the setup assist is going to walk us through would enable a successful integration with the tenable i o into our servicenow instance and the final feature that i want to highlight for today is going to be the integration for pen testing and cloud vulnerabilities uh within that we're getting two major highlights the first one is application owners can request a penetration test the results of which can be imported and managed in vulnerability response and number two import cloud variability data from west then prioritize assign and monitor remediation effort using vulnerability response now in our service now instance we can go into the application navigator and look for penetration test findings from that we can access all of the different application variable items that have been discovered through different penetration tests this allows us to see the assessment request number the vulnerabilities that have been discovered through that assessment and we can also see the technical details the impact and the step to reproduce thank you all for taking the time to be with us today for checking out what is coming new san diego release uh within vulnerability response specifically uh if you're interested we have other videos for the other servicenow solutions thank you again for spending the time with me today
https://www.youtube.com/watch?v=G9NXjlvzPI0