logo

NJP

ServiceNow Vulnerability Response and the CMDB

Import · Apr 21, 2022 · video

hey so i'm mike plavin i'm a technical product marketing manager for servicenow security operations and i've got leo here with me leo yeah hi everyone so my name is leo cicada i'm with the it's customer outcomes expert services team i lead our delivery team and delivery servicenow security operations products so my team is solely focused on delivering the um the core security operations product line suite yeah and leo we were talking a little while ago about a lot of questions that folks have with regards to uh cmdb and its relationship with vulnerability response and really the value uh that you know the cmdb can offer uh vulnerability response customers and and there's questions around you know how do they need a robust cmdb in order to extract value out of vulnerability response etc i know you've got some thoughts on that so let you talk to that a little bit here yeah absolutely so you know without a doubt of course everyone who has a healthy mature cdb of course they're going to be better off it brings context it brings you know all kinds of different uh attribution there but since since about november of 2021 you know vr has has really made it easy to um provide value for customers who may not have a mature seem to be and there's different ways we can call it mature right whether it be under populated um whether it be populated but it's just not accurate or just highly inaccurate so all kinds of different variations with the introduction of a very specific major feature we have made it a lot easier and a lot less clingy to to have a mature you know rock solid team db so i think um i think things you know um are a lot better now with that particular feature the feature i'm talking about is classification rules so talk a little bit more about that why is it make it uh easier to uh run vulnerability response uh when you don't have as mature a cnb perfect so what i'll do is i've got this powerpoint that i want to share right so let me pull it up that that i have and that way we can talk through it um and i'm going to skip to the meat and potatoes of this thing right um so can and we're going to make sure you can see the uh the slide that is being being presented mike how vr provided across all stages yep exactly so you know classification rules gives you the ability to um to parse the vulnerability scanner data in a couple different ways one is parsnip parsing the third-party entry data the vulnerability definition data so things such as you know if the vulnerability contains keywords like oracle sql java um then assign it to these particular i didn't classify them right you classify me call it web application you can call just just third party application middleware uh browser-based vulnerabilities and then what you would do then is key off your assignment rules off those classification values um for those wondering and for those that that really get into the service now i mean um this this this method of doing that assignment and that logic um it really streamlines the the performance aspect because you're you're really tagging uh so to speak the vulnerability definition which in some instances could be about 150 000 maybe 250 000 records and you do that one time um and then you kind of do incrementals after that versus doing it x number of times the vulnerabilities you may have in your environment so that could be 5 million that could be 10 that could be you know 50 million who who knows right so you're really just paying attacks once and then you're just keying off of that and you're just streamlining that yeah that's huge as a yeah so as of the san diego release which just got released last month we also are able to take the vulnerability scanner host data so whatever whatever data the vulnerability scanner provides about the host that it scans so ip address host name asset tags scanner scanner aesthetics and then um ftdns um then you can start assigning things based on like maybe you've tagged it as an external entity maybe you've tagged it as crown jewel any anything location based anything that's attributed to the host and then it's the same principle right you you run your business logic assignment or scoring or grouping against those classifications and it's just quick quick quick now notice i didn't say anything about well we got to do you know we had to look up the ci to figure out you know is it in the right location you know we're really leveraging the data that's coming out of the scanner so that it allows folks who may not have a you know a fully populated seem to be or an accurate seemed to be to continue working and we can kind of work things in parallel well it's giving them the value that we've talked about with vulnerability response for a long time for like you said those customers that don't have the mature cmdb they're able to use this uh the way that it's intended uh a lot quicker using these uh you know the classification rules and vulnerability attributes so that's great yeah so what is um yeah yeah so let me let me share this uh this other um let's make a little bit easier visual right so what are the major features we can use it cross-reference with the the types of customers and their cmdb kind of stage i call i just say stages right because they're various stages so a mature cmdb can take advantage of vr classification rules scanner tags plot the general platform assignment engine that we all know seem um cmdb attribution and the relationships so like the business services and you know the impacted services and whatever kind of attribute you may have um so that's that's like your ideal situation whereas at greenfield very mature cmdb um you would still benefit from the classification rules even scanner host tags uh the platform assignment agent um and and i have them kind of in order of preference of which one you know you should leverage first so this is just a quick nice visual for customers to see that well i think it makes it also highlights that if you have a mature cmdb you're absolutely going to see additional value out of that you know like you like you had mentioned being able to see the affected services and things like that but it's not a requirement and that i think is something that a lot of people when they have looked at servicenow vulnerability response uh one of the questions that's come up from the solutions consultants and the sales reps is around that well you know they don't really have a cmdb stood up yet what do we do so and that's really what we're you know hoping to address here i think that you've done a great job with these slides of highlighting those points yeah so that's a good segue to the one one important point i wanted to make is you know if you if you're in a situation where you have a green field seem to be or just not it's under-populated um and so you might hear lots of times where vr can help populate and all of that is true we have the ability to create ci in a separate table outside of your core cmdb tables so that a record is created and then you can do all your logic off of that call it a staging table call it call it just a one-off table um and then while while the vr folks and the cmdb folks work through um ci matching or just you know trying to work through their traditional um discovery you know efforts so maybe you have a customer that is going through a discovery implementation and um you know that that doesn't affect us because we plug into that intake uh method uh we'll try to be non-techie but we plug into that intake method for discovery so that if and when discovery gets up and running and deployed you don't have to go back and change something it's just going to pick up those unclassified pis that are in that stages table classify them correctly and all as well yep that's great yeah and here what i what i did is i did an actual a little bit more detail slide at the four different features so that folks can kind of quickly see you know well how how could you leverage this right so right well i and i think that this is uh this is all great information i think this is uh really helping to clarify again just that while having mature cmdb is is helpful it's not a requirement it's not something that absolutely needs to be uh part of you know the prerequisites for uh deploying vulnerability response any last thoughts on this before we wrap up you know it's um i would say having the platform seem to be folks involved in that vr implementation no matter what the stage of the cmdb is it's always going to be beneficial and helpful and just just understanding that there's always a way to get value and as of november i'll leave you with that as of november um the store released there we have made it a lot easier for you to take advantage of the vulnerability response application regardless of your cmdb stage that's great and i think that's a great uh place to leave it uh that reminder about the november store release leo i really appreciate you doing this uh today and uh we'll talk soon all right thanks mike thank you

View original source

https://www.youtube.com/watch?v=89s6Lrvyn_o