logo

NJP

Continuous Risk Monitoring for Vulnerabilities

Import · Jun 02, 2022 · video

hey everyone today's session will cover continuous control monitoring and specifically how to use secops vulnerability management to incorporate key risk indicators key control indicators as part of your integra integrated risk management program so we'll start in integrated risk management which is all the applications you see on the screen here and combine this with secops vulnerability response process and really demonstrate how this information can be used as an early warning signal or a predictive indicator to determine if controls are not operating effectively or if a risk score will increase or decrease we're essentially synchronizing two different solutions to derive advanced insight advanced analytics that we would not otherwise have visibility into so the process consists of four steps we're first going to look at a risk dashboard and analyze some uh some heat map kind of dashboards and reports we'll then go into the course finding vulnerabilities and vulnerable items and we'll uh patch those vulnerabilities and then revert back to the risk dashboards and show how that affects the um the risk scores and the corresponding heat maps so let's get into it if we start with the risk workspace this is essentially the the landing page the home screen for risk managers so we have a number of trends for rest controls risk events key risk indicators this feeds into different dashboards showing our quantitative loss figure heat map analytics which plot those risks onto different quadrants and one thing that's nice here is the dashboard shows a lot of information in my demo instance there's quite a few risks controls what you can actually do is filter by business unit or filter by entity so we can apply a dynamic filter that says only show us the risk metrics for e-commerce so we're going to hone in on that specific business unit and once we apply the entity filter it just whittles down these metrics to show us only the risks controls only information related to the the e-commerce entity these dashboards are all interactive so if i click on the top right-hand quadrant you can see here's the four risks for e-commerce that are most critical to that business unit one of those being loss of availability and then you can click on the risk and see basically all the risk information including which step of the process we're at any previous risk assessments so this was our latest assessment score any open mitigation tasks and then really the focus of today's session is around indicators so we have this indicator that's looking at the vulnerabilities impacting the available availability of our e-commerce system and you can see that the latest indicator is failed and because of that the systems automatically created a new issue which is the result of that indicator failing now if we go into this indicator this is just the kind of the results from our latest scan so it's indicates a failed indicator what i actually want to do is go into the template and this is where all the magic happens so within the indicator template we've defined what table we're looking at so we're looking at the all business services the vulnerabilities associated with our our business services which the one that failed was for e-commerce and then we define what results in or you know what determines that an indicator has failed and we do that by setting all these conditions um and just kind of the you know the short version of all these filters is basically we want to pick out vulnerabilities from tens of thousands of vulnerability records which ones are still open so which ones haven't been closed or fixed which ones don't have a mitigating control in place that addresses the vulnerability which ones are exceed this criticality threshold so they're flagged as mostly or somewhat critical some teams can do this also by cvss score so cvss for exceeding a certain threshold and out of those which ones are overdue for over 14 days so basically highly critical vulnerabilities that haven't been patched for 14 days once it exceeds that threshold that's going to cause this indicator to failure so let's go let's go ahead and switch gears to the vulnerability response side and show how that information will impact our risk problem we'll start with the big picture and then we'll dive into the key elements of the solution what you see on the screen here is an overview of the vulnerability management dashboard and we use dashboards like this one to show the remediation task structure but also to report on the progress you can see here the number of vulnerabilities we have in the environment how they affected the various configuration items and other key business metrics and kpis but because of vulnerability response application provides a single system of action and engagement we're able to collect information from scanning solutions that actually provide business service context for reporting and triage so out of the box again dashboards like this one help track your metrics and kpis and we'll break down the information as desired based on your organization's business services the information you see here has been rolled up against an existing cmdb so you can see the business services that are at risk and how they're trending so we'll take a look at the the e-commerce business line here and get some more details around the vulnerabilities associated with that so as you can see here we we see a trending graph but we also see the number of vulnerable items that that are associated with the e-commerce business service and if we just dive into one of these i'll just pick this one right here we can quickly gain even more information about this particular vulnerable item and what's associated with it but the first thing i want you to notice is that vulnerable items are tied to configuration items second we have the ability to auto assign this item not only to an assignment group but even a person that is going to be uh held accountable for those remediation steps and we do that through automatic assignment rules as as well as other automated tasks that are involved with the the process of remediating these vulnerabilities and then third we're using various risk calculators to assist in determining what that risk rating is and what the various risk scores may be with this vulnerability and then finally notice that we're applying a remediation target uh to this uh process very similar to what you see for an sla like for it incident management but in vulnerability management we look at this from a date-based perspective according to the timing of the remediating vulnerabilities that affect critical business services the next thing we want to take a look at is the remediation steps because we're leveraging solution management we're actually tying into organizations like microsoft security center red hat security and they are providing uh what the preferred solution is uh whether it's applying a patch or some other task in order to remediate those vulnerabilities and then as we move down a little bit further and look at our our remediation tasks we can see here that this these efforts help us organize vulnerability data into easily managed chunks so that it teams can quickly and efficiently target and remediate the most critical vulnerabilities within the organization so if we actually open up this particular remediation task again you can see a lot of information again based on what the risk rating is the score who's responsible for this particular effort or tasks as well as the status how are we doing with this particular effort and again we can see all the vulnerability items that are associated with this remediation tasks uh the preferred solution and if there's any change requests associated with the facilitation uh of this particular effort so the next thing i want to do is kind of switch personas here and and impersonate carla jackson she's our analyst that is that is working on this particular uh uh incident and we're going to look at uh the i.t remediation space and so here you can quickly see uh carla's assigned to this particular group you can see the number of remediation tax that are associated with this group all the preferred solutions for the vulnerability items as well as the vulnerable cis so within this group you can see all the efforts associated uh with this um this assignment group if we switch over to what who is assigned to me in this case carla you can see that she's been assigned a remediation task and you can see by diving into this a little bit further you can see a very high level overview of not only the remediation progress bar here but you know again what is the risk rating what's our remediation target give me a short description of what this vulnerability is and and a description of of this particular uh event uh you can see on the right hand pane of those three vulnerable items that we're dealing with for this particular effort but notice here that as you switch over to an analyst view you begin to see the various actions you can take on this particular remediation tasks you can see here that we're able to look at things from a change perspective we can split these tasks out into various assignment groups we can even uh request exceptions so in this particular example if this effort may interfere with critical business efforts or production environment maybe you're waiting on a fix from a vendor you can create a an exception request and invoke a secondary workflow that goes through an approval process if you will in order to mitigate this particular risk for this example we're going to go ahead and resolve this as an example make some notes and we'll resolve that and now you have a remediation that is now in a resolved state waiting for confirmation waiting for someone to go in and close out this particular remediation effort all right so coming back to the risk side once we've mitigated that vulnerability so we've applied the appropriate patch it's accepted by the appropriate approval the corresponding risk will automatically have the risk score decreased so if we go back we still have the e-commerce filter applied if i go in this top right hand quadrant there's only three risks instead of four and then if i search if i click on this middle quadrant you'll see the loss of availability risk has moved into a lower risk quadrant and that's if we drill in here that's because the associated issue has now been closed off this automated factor is applied to the latest risk score which moves it into the appropriate quadrant within our heat map so by virtue of patching that vulnerability automatically reduces the risk score and we can you can see those results here to to wrap up this session essentially what we've done here is shown how risk indicators can measure your vulnerability data in real time how the workflows can really help create synergies between second line of defense risk managers and individuals managing the vulnerability responses so we're effectively creating kind of synergies and efficiencies between the team uh between those two teams how vulnerability response integrates with scanners took a look at that in the phone video those items are getting automatically ingested from your various scanning tools and then how this platform allows for uh kind of more effective collaboration across teams i hope that was apparent in this video any any follow-up questions please do let us know thanks everyone bye

View original source

https://www.youtube.com/watch?v=G4oek4yWQ5k