Cyber Resilience using CSDM 4 05 2022
okay so thank you uh everyone for joining the april fifth session you might be asking why um or noticing that i am not john spierko and you're correct my name is martin chaparria so i am part of the enterprise architecture team i'll be leading this off we've got a couple of guest uh speakers as well so just um as we start all of our work group meetings kind of a summary of what this work group is intended and how we started so we've been meeting as a group since june of 2018. um we're just over 550 members now different companies throughout spread out different industries different organizations and it's really just one one vision right to come together to be a leader in digital transformation thought leadership and so we share stories which are artifacts um best practice so if it is your first time welcome to the group and thank you for joining us we would like to you know say hello to our new members so if you would let's use the chat function um please go through let us know who you are um where you're from what company and um you know give us an opportunity to to say hello and start building the network here now with that um i do want to just set the stage for what we're going to cover today and it's um as many of our conversations go it's you know related back to in some way the common service data model in servicenow so if you're not familiar with what the common service data model is um it is a um an architectural model of how components of the servicenow platform are going to interact and intersect with each other and if you look at it it really is servicenow's kind of unique differentiation within the market because it it's able to tie capabilities together truly a single data model so look at things like even from just foundation or you know companies our business units our departments our users tying those back to products and services um to even things like contracts and spend um and then ultimately to some type of business capability business services and how it's provided consumed maintained throughout its life cycle so adhering to the cstm allows you know our customers to really take advantage of um this type of data model you know to help you quickly deploy avoid unnecessary technical debt and and really just be that enabler to help you along your journey so in today's session we're going to talk about how you can leverage the common service data model the csvm to build resilience uh into all aspects of the business kind of use um this data model as the foundation for resilience and ensure that risk is going to be addressed throughout throughout the enterprise so with that um we have two speakers that are going to participate with us today we have aaron that is from our business unit of for risk and resiliency and servicenow and then on dress who um is a cyber resilience offer officer for center health do you like guys like to say hello [Music] you got it i just wanted to make sure that you could hear me but uh hello everybody go ahead aaron hey so this is sarah callaway is a mentioned i'm uh you know principal at the risk and resilience uh business unit and uh you know long long story short i was a founder of a company called fairchild resiliency that was acquired by servicenow back in 2019 and ironically andres and i have been uh you know professional friends uh well before that and so it's it's really an honor uh you know andres to present with you and um you know i see andres as a thought leader in this space and is has really done some pretty creative um has addressed some some challenges with really creative approaches on the servicenow platform so excited to be part of this thank you um the feeling is mutual um since the times when maestro um was uh part of the uh ecosystem for business continuity um you know i've been always an admirer of your implementation so i welcome the invitation and thank you so much for the intro excellent well i won't take any more time away what what i want to do today is um andres we'll let you go through and kind of talk to us about you know your vision and how you're you're building out a framework and a data model that to really run this resilient business on top of servicenow and then we'll um go to aaron to discuss a little bit of future capabilities uh within the product and then from there if anyone in the audience if you've got questions please let's use the chat and we'll also make sure to reserve some time at the end to address those andreas i'll turn it over to you here absolutely and so i presented my slide deck then yes perfect let me get that going and be able to share my screen then and you let me know when you can see it can you see my screen looks like it's coming up so just to let you know we have a big storm here in louisiana it never varies um i lost power a couple times so i have uh another session going on my laptop in case we we drop off uh where i'm connected with a verizon uh mifi but can you see my screen yes it is yeah um [Music] i have been in business continuity and disaster recovery for quite some time and i find this um saying uh from our president uh 34th president dwight eisenhower where he pretty much states that plans are worthless but planning is absolutely everything he was saying this as he was being commissioned to put the plans together after the pearl harbor invasion so it was significant that he would even recognize the fact that plants are worthless and if we start with one thing a disaster is something that is totally unexpected a lot of times it's unknown and so it's a very unlikely that a disaster is going to go to plan so the key here is that we need to be able to remain adaptive and be able to be ready so it's about readiness a lot of people ask me what resilience is all about i can tell you that the definitions of resilience are as varied as the definitions of applications you ask someone what an application is and they will give you the definition of a business application or an application service or a software but you know the application for us in the csdm is that discovered application um that is in the environment as an application right so the definitions that we're trying to put together for resilience um hopefully today after the presentation will have a more clarity as to what we mean but you know we already went through number one plans are nothing planning is everything number two uh if we're gonna go through some principles here um don't do it unless it produces tangible value and uh value is um you know very important uh to what we do in the platform and so i recommend that if you are doing something that doesn't produce any value then you need to stop doing into that i'll give you an example they call me and say hey we need to sit down and do the planning for a test for a dr test and after we do all this planning and we put all this documentation together we need to go ahead and do a dry run for the vr test and i asked him what value does that bring to the table when you have a disaster it's going to be totally unannounced right you need to stop rearranging the chairs in the titanic and be able to jump straight into creating value identifying who are your pain point partners to be able to uh leverage them uh into the solution that goes also to the you should only play like you practice right you should never do a dr test unless it's the same way that you're going to recover uh and to that end you want to make sure that um you don't put any fake controls in preparation you should be able to walk to your network operation center and say hey today we're having a dr test here's the scenario and then go sit on the other side and wait for systems to start failing over we are to only build solutions that are sustainable when we talk about disaster recovery when we talk about business continuity a lot of the reasons that this solutions are not sustainable is because we're not stitching them into the organization the organization has life cycles that they follow for strategic alignment making sure that they're competitive they are operational life cycles that organizations follow and so we want to always make sure that whatever we do we're integrating that into the life cycle of everything specifically in i.t i.t life cycle change management itsm great partners to be able to develop those sustainable solutions when it comes to disaster recovery and business continuity so that we don't have to go to disaster recovery once a year or do business continuity once a year if we are change aware uh if we are tied to the life cycle then we are able to maintain that integrity in readiness throughout the enterprise service driven resilience and by that what i mean is the fact that we have a service platform it's called servicenow for a reason we do service mapping because the essence of servicenow is the delivery of that quality of service and all we're doing is bringing the sound component to it as to how can we then offer a more sustained approach right so if something fails then we have a failover capability or we can have an active active solution and then it has to do with operational hygiene how can we make what we do better more efficient and is if we do that operational hygiene that is a day-to-day basis it's a cultural shift then we can avoid the disease management components of the surgery that is a disaster recovery component all of this falls apart uh whenever compliance shows up and says hey where is your plan right because they want to see a document so we have to also work with compliance and educate them as to the new methodologies [Music] so i wanted to give you a little bit of um an idea as to what our current situation looks like and uh in our current situation uh today uh at centura health uh we just procured servicenow and the priorities set by the organization are primarily apm and itsm and we all recognize that the cmdb is critical to the success of everything that we do and so we are now establishing a resilience practice a program uh where we no longer want to be able to use word documents and spreadsheets right that are stored in people's drives or team drives we want to be able to have an integrated approach to business continuity and disaster recovery that leverages the power of the csdm in the cmdb in now overall with the ability to orchestrate workflows and be able to leverage the bcm components that aaron is going to talk about we don't want to longer have isolated systems right the reason that erps came to life is because finance hr accounting everybody had their own system and it's the value of the integration of the data to be able to have the referential integrity of the data across the enterprise that can provide us the certainty uh to be able to maintain what we call the real time enterprise right when we make a change that change is visible across all of the elements of i.t and that's what we would like to be able to have in our business continuity management and our disaster recovery we want to be able to align all our metrics all the data that we collect with our cyber security metrics as well for visibility so what this gives us is uh the ability to make decisions on the fly right to be adaptive to change we never know what the disaster is going to look like we're always surprised by them by the sheer nature of their definition we don't have any staff dedicated uh to do this work today so we are forced then to educate the different elements of staff and to bring all of this to the enterprise as part of the equation and it's um it's a new opportunity uh we're gonna have only one chance uh to either make it work or fail at the delivery of this so we have to be very careful as to how we deploy this uh into into the enterprise uh in this next slide um i don't know if you can see it already um but i labeled it building the real-time enterprise let me know if it's coming through not yet i think we're running just a little behind yeah let me uh turn off my camera and see if that helps any um [Music] but in the real time enterprise um what i'm presenting here is the view of uh let me just turn off my camera if i can hopefully get a little bit more bandwidth um can you see it uh not yet but what i'll do is i'll take care of it present presentation from you and uh and you will present it and that's a lot easier then yep yeah connectivity here is uh right now uh i'm going through uh throughout um verizon connectivity so apologize for that but the storm is uh taking our internet connectivity down no problem yeah so um in this um slide uh what i am presenting is uh at the bottom of the pyramid you will see that all the infrastructure software software models and applications are part of the discovery right when we go to discovery in the environment all those elements are going to come into the cmdb and the platform through the mechanism of that discovery it used to be nebula a long seven years ago application services on the other hand is something that we define and where we attach the service maps and then we have business applications and business capabilities our goal um as you can see is being able to deliver the mapping of these capabilities in servicenow for the only purpose of being able to deliver resiliency uh so we need a a cmdb we will have to make changes to our cmdb to incorporate into it uh reference architecture for cyber security and what that means is we're gonna have to bring another set of tables that is going to educate the cmdb as to how our protections are occurring in the cmdb and we recognize that this might be technical debt that we're creating right and this is where aaron is going to expand as to how grc and some of those other elements solve some of these problems but this is the solution that we're about to embark on next slide so this is the very basic uh csdm implementation for the walk i'm showing the colors as to what is discovered and what is conceptual and how it ties back to some of the processes like itsm and some of the other information objects that have been matured over the csdn version 4.0 next slide and this is a very busy slide so i want to walk you from the beginning to the end these are some of the considerations that we are taking some of the steps that will take to be able to enable this capability in in the shortest time frame as possible we have a very aggressive timeline to to achieving this um is uh three months standing up some of the very basic capabilities out of the box with idsm etc so as you see the number one uh i'm showing the business capabilities and one of the things that we intend to do is to buy a library of business capabilities for what is a health care system and they come at multiple levels up to five layers of detail and we're just gonna load them in out of the box and uh we are going to create then the child parent relationships of them and we are going to start at the top of that hierarchy to start defining the application services or the business applications that really provide those capabilities to the enterprise we are not going to go to the bottom uh leaf level uh elements but we're gonna start at the top at the very same top uh we will also conduct a bia a business impact analysis that is going to be done in combination with apm the two priorities that we have are apm and our itsm and by bringing apm and the bia together we're able to collect some of the priorities for application portfolio management in partnership with business continuity where we ask the question at the capability level as to how long can you be down and how much data can you afford to lose notice that this is very different than many of the other approaches where we collect that information and we go put that information on that score against the application we don't intend to do that we intend to inherit from the business capability to the business application to the application service what are the rtos and rpos that we need to satisfy very different approach and the reason we're doing this is because when we go to the business we want to talk to them in business terms we want to be able to ask them what do you need for this capability not what applications do you need but what do you need in terms of uh you know what is the financial risk uh what is the brand risk what is this type of risk how long can you be down and how much data can you afford to lose right what sensitive data do you have etc etc and then we'll calculate the rto and rpo and then we'll spread it out on the application services components and that's what the arrow shows the business applications like any other company there is a list of applications out there and what we're gonna do is you know out of this existing cmdb uh with that list of applications that we have we're just going to load them into business applications that's what the step number two is and immediately we're going to start building the relationships at the enterprise architectural level as to how those map to the business capabilities when it comes to application services we will not copy the business applications into the application services because the business applications are not normalized um because application services we want to be able to take the environments into consideration so we might have an application service that is related to a to a production environment and we might have an application service that is related to a testing environment or an integration environment so we are going to start bringing them in uh one by one and the way that we're gonna do that is we're also aligning with enterprise architecture they're looking at some technologies uh that they're looking at changing over the years and we are selecting those technologies to be the first ones that we're gonna do a disaster recovery test on and with that we're collecting all the information about the disaster recovery test uh that has been done in the past and we're building the models for those application services there we are adding some additional tables to to do this work uh there's an integration table that we're adding uh that is gonna allow us to map any of the um data exchanges that we have with partners and internally a table that we haven't been able to find in the csdm but we went to the work groups and had many conversations out there and a lot of the discussions are about you just need to create your own table because you're going to need to have this information and track it so we are in the process of modeling that on the number three i identify as number 3 one of the main partners in all of this is itsm you know if i am having incidents on monday morning after server patching in the recurring incidents that means that my i have i have i will have those same incidents when i have to fail over uh because that means that the systems are not being validated correctly uh prior to being put into production and so change management and the change activities are going to be responsible of validating a lot of the cmdb records that means that when you're submitting a change we want to make sure that you have the correct information and if it's not there that they can submit a catalog item for that information to be put in place while they have a placeholder and when we are able to go through the process of governance as to this is an uci and this is where it belongs this is the class then we have validated that record and then the change record uh has that as the affected ci moving forward release management can help us uh make sure that we understand that the on-call schedules are clean and complete making sure that the service maps reflect what was actually deployed into the environment and so does for example problem uh identify that when we have a persistent problem that the recovery methodologies that we have for that are adequate right a lot of the recovery methodologies can be shared between what is in a disaster recovery environment as it is in an incident response environment incidents obviously uh if we're calling people in the middle of the night um they're gonna let us know that they're not the right person and they will make sure that the on-call schedules are fixed so incidents should be a partner in that outages should be validating our services right because outages uh affect our service delivery and when we have an outage and we collect the information as to who is affected we should be able to go back to those services and define them better and so goes on and on on the itsm side now going into the discovery side um we have the resilience reference architecture that i mentioned early on that we're going to have to develop we consider this to be technical debt that's why it has an asterisk there um and then we have recovery methodologies that are going to be also defined that are going to be aligned with that reference architecture all the legacy documentation is going to be transformed and converted into elements of the cmdb and csdm to include a lot of the operational procedures right but when we do this we're going to do it in an object-oriented breakdown methodology so that we can identify where the pieces of content need to belong within the csdm and the cmdb lastly in number six i have put the cmdb acl abstraction and and that capability for us uh is to develop technical debt for us to have the management of access into the cmdb away from what would be a privileged admin account in other words we want the cmdb separation of duty to have the ability to define the access of records based on attributes based on fields and based on specific classes as to the read modify or create capabilities but using an abstraction through a table uh where we define this and in that table becomes pretty much our governance structure for all the access to the cmdb obviously we're going to have to create reports dashboards and a lot of other things to be able to clean this environment can you go to the next one i think this is my last one and then uh aaron comes in hey andres there are actually a couple questions of this slide if you want to hang tight for a sec um i think you touch yeah i think you touched upon one section of it so uh brian says what is the strategy for governance over this implementation future csdm decisions yeah so very interesting question so i volunteered to be the owner of the cmdb product and with that i have put in a governance structure uh that is number one uh transparent and all-inclusive and by that what i mean is if the change in the cmdb has the potential of affecting a work stream a functionality or a related element within the data model then you should be consulted as part of this equation and we have created a cmdb council that has full representation uh from enterprise architecture business architecture and some of the service now folks to come to the table and then take all of that into consideration and uh at the end of uh that council is going to vote on a decision that is going to allow us to either reject the proposed change or accept it no and uh one one other question here it says what does calculate rto and rpo mean in the life cycle considerations for resilience when the server's portfolio management application includes the commitment module where both rto and rpo are service commitment types absolutely so we we recognize that the place where rto and rpo should live is in the service offering that is the end state unfortunately for us to achieve the level of maturity if you go to my prior slide i mentioned that we're at the walk state right and so in the walk state what we see ourselves doing in this type of iteration is that we are going to cut some corners but we're doing it very deliberately knowing that apn is a priority for the business we want to be able to ride that opportunity and climb on the train and collect the bia information instead of having to do another bia to collect that information in other words we want to collect once and use many as part of this implementation sounds good um and just one last one is when performing instant interchange management what class of ci do people typically use we use business applications primarily but have a request to use application service with love input absolutely so the the way that we see this is that is a maturation process you know from a ability to be able to have a mature number of application services in place that have service maps uh developed for them uh that is the place where when you have an 80 20 type solution you should start trying to enforce the use of those application services as the affected ci's because what that's going to allow you to do is going to allow you to evaluate the actual risk right in terms of how are you exposing the risk to the capability to the function uh by affecting that service when you go to the business application uh that risk methodology is not uh as granular as you need it from the application service and so but recognizing that service mapping requires for you to have a mature discovery practice and also a mature service mapping practice it takes time and service mapping can be tricky you want to start service mapping at the platform level so that you can start defining your core elements of practice and that is where the reference model that i mentioned before for cyber security comes into play we want to be able to start the core service building blocks uh service mapping those until we get to the application services right which is what you would then expose for a itsm process inclusion in a picker okay one last last thing and then we'll move on uh andres it is just a clarification on that comment says when you say to use application service as the affected cid do you mean not using it as a primary ci uh you can use it as a primary ci uh affected cis but so when you use it as a primary ci and you use it so it's gonna give you the ability to be able to determine what the affected ci is because those are going to sit underneath it and so you don't have to necessarily go load all of those affected ci's into that ticket necessarily right by the virtue that you're pointing to the application service and if that application service has a service map right you then understand what your affected ci's are oh all right thanks andreas we'll continue on and so here i'm just showing uh how resilience for us uh centuria health is defined against what is an idle itsm servicenow implementation and we want to be able to anticipate have situational awareness out of the platform and then be able to withstand sustain any of the service uh impact um recovery for us needs to be very adaptive because we don't know exactly what disaster we're gonna have it can be ransomware it can be anything and then we need to be able to learn from all of this and adapt our practice so it's a very high level view we've chosen uh in a large way the nist engagement and the nest 800 160 is a good place to start with resilience for cyber security i pass it on to you aaron so before we we do that i do have a question that to kind of help bridge the gap here so um looks like you're building out a service portfolio or digital portfolio over time and using csdm to help um guide um to for for growth for adoption how does this then translate into other parts of the uh risk estate such as uh compliance yeah so what we're trying to do is is a what we try generally when we go and deploy service now we try to go to the business and say hey you have to do all of this and instead of doing that we recognize and we're putting cyber security as a business strategic component we recognize the role that cyber security plays in our protection of our enterprise and with that we have decided to put it at the business capability level and so by us taking that step is forcing us to load everything about cyber security into the constructs of service followed by the services that id provides and once we have a pretty good understanding of the flows and the processes and how we come to do this as an i.t organization then we plan to engage the business with the rest of the services that we want to be able to map and follow it's difficult to engage the business we don't know how we're doing this internally as an id shop and when it comes to the risk components i i would turn it on to iron to talk about the grc elements and how that's going to be aligned uh we hope to be able to bring the fair model into play and be able to use some of the vulnerability management components for integration into some of the scores right that are going to allow us to do all of that yep i think that's a great segue aaron let me get your um andres thank you so much for uh setting the stage here you know it's kind of like that that iceberg effect where the way that you're deploying servicenow and and bringing together cyber resiliency you have a lot of the complex interconnectivity happening behind the scenes and then your presentation layer and your uh management reporting that you spoke about will really raise the issues to the top right so all the hard work will pay off as you start through the deployment and adoption of that so that's pretty pretty cool to see all right can you all hear me yep all right so you know one of the things i wanted to get on to i'll go off uh the track here a little bit as we as i'm going to talk through the bcm journey but as part of this bcm journey what we're seeing is um just an overall maturation in programs right it's you know we have the covet effect um you know where people now can spell business continuity management um it's spoken about in many households it definitely isn't mine but uh you know where where people have a good understanding and appreciation for what it means to our businesses what it means to our customers what it means to our families and along with that journey it's really becoming part of the business right it's i i like to say it's it's it's great to have a resiliency program but the in my opinion the ultimate goal is to have a resilient enterprise and the nuance is slight but the effect is huge right and uh andres got into this a lot with his presentation is is is that you we talk about embedding these different tasks into everyday work functions and that's where i'm getting to the biggest piece of this around the orchestration but what we're also seeing is that people are talking about resiliency across different areas of the business that are you know frankly new to me so like we'll have cfos call in or say hey how can i make sure that my my area is resilient um we're seeing more collaboration across the servicenow platform as a whole whether you're looking at cyber you're looking at hr you're certainly looking at this the uh csdm or cmdb for the the data that we all share right that's the you know refined i call that data it's the refined oil it's how can we leverage that um to make uh educated decisions or even to prompt suggestions around what's happening in your organizations and so one of the biggest effects that i'm seeing over the past couple years with the combination of the covet effect um with some of the uh you know global uncertainty that that's going on whether it's a global economy whether it's uh you know unrest is that the business continuity disaster recovery crisis management cyber security folks are all working together right it's almost like you you have to but um beforehand let's go back five or ten years ago cyber security was kind of in its own silo they only played with their own friends because everyone else around them you know couldn't understand what was going on or they thought so now we're seeing more of these um you know mutual respect and collaboration and certainly within uh the servicenow platform the collaboration that we're seeing within secops and and also um business continuity and i t disaster recovery so if we if we walk up and step up these stairs that you see in front of us um i'm not saying that any of these are the right answer for your organization because depending upon your organization um being at stage 0 might be fine for you right it could be fine now from the list of these people on servers now it's probably not fine for you all but if you're looking at a smaller business um that doesn't need this this this automation and can manage your a plan on an excel sheet or even on a piece of paper planning is necessary um to make sure that we're all on the same page but as we step up to okay now it's more of a reactive stage with something went down and how do we get everyone together um and and and support that maybe this is like an excel tool and then when we move up to that the basic and managed this is where we really start bringing together the power of the servicenow platform and it could be and you know andres has done a nice job you know articulating his phased approach right it's how do we win the hearts and minds of the business and while leveraging the existing data and giving people um a process that's a marble right it's a marble as as andres is pulling in um kind of common processes for the health care service we're giving people data as a marble to work from we're giving them a framework as a marble to work from and to grow from and then when you get into these more mature areas of managed and orchestrated a couple of the examples that i like to use that kind of workflows this across the servicenow platform is whether you have a new application that's coming online a new process that's coming online a new location that's coming online it's the combination of what that looks like for your you know from your operations but also you know the question around your data governance is when we bring these things into the system and let's say it's a process well is this process a critical process yes no well how critical is it you know one to five or how are you doing these these bias and what does it mean and then how does that affect your planning and resiliency on it do you should you do a bia on this process even before it's deployed or should it you do a bia on this process six months down the road but it really sets the stage for people within your organizations you're doing a resilient um you know you're doing a resiliency task but it's now become part of ingrained in your organization and martin if you can move me on to the next one and here's a bit around you know this is a bit of the iceberg right this is a lot of the uh how the we're leveraging all all this awesome data and capabilities and functionality within the servicenow platform so the more that we do on platform i believe the more resilient and the more resilient opportunities we have within within organizations and when you look at the right side of the screen it lists a lot of our risk capabilities and functionalities from obviously business continuity how do you evaluate risks how do you mitigate it your dr planning your vendor risk your overall crisis management well we're all working in the same sandbox and within that same sandbox is really powerful um but it also comes together with we need to play together right we need to have a good appreciation for um how the the cmdb and the data in the cmdb is being populated how it's being governed how it's being maintained but the beautiful thing about doing resiliency on platform is that you have more eyeballs on this cmdb data right the more reasons to maintain and to build upon your it inventory assets and your cmdb the better so as people are doing a business impact analysis you know identifying your most critical applications and processes when they're building out their bc or dr plans they're selecting you know information and the data that's in the cmdb so if your business and or your your it people don't see an application or don't see a process it means a couple things it means that it's either not in there they're calling it something that they shouldn't be calling it you know so you have a data normalization normalization issue or it's might be just you know spelled wrong in the system something really silly but then we kick off andrei's you know data governance process and then we have the you know this this process that looks at the information and we update it and make it better it's a continuous process improvement cycle for your data and that's really what excites me is it really elevates your business resiliency uh program into a more strategic opportunity for us to really look at the entire process supply chain across the organization because that's what we need for business resiliency and then can be can be leveraged for many other strategic purposes for the business uh let's see here so mike i see a question here so mike says makes sense just wondering if this can also be worked backwards identify capability ask the business what services they consume to support that capability then use that to identify business services and the applications that provide those application services i like the other approach better as this is a way it is proven difficult but maybe the other way is difficult also um you know mike there it it if it was easy everyone would be doing it but i will say this that the hard work pays off um at the end it's a it is a journey and it's something that's never going to be be perfect um i don't know if it's i don't know if it's easier sorry martin is that some yeah i i can chime in on this as well so yeah i i really think that it depends on the organization and if you look at the csdm that the guidance is either application focused right where we start at the application level because that's the language of the business if you ask what capabilities the business have many times in many organizations it's the name of an app while others are more mature in true capability mapping where they have their capabilities identified and supporting services so if you're if you're an organization um and i see this a lot in tech and in uh managed service um where services are are highly defined because there's revenue attached and um then it may make sense to go with a service down approach which it sounds like that that's what your organization may be doing so i i i don't think that there is a right or wrong it it has to make the most sense for the business i think adhering to the csdm promotes that type of flexibility where you can start where it's going to have the most impact to your business and then still be able to to scale without worrying about how apm and spm and now digital you know are going to intersect with each other yeah martin and you know it's a good point in and i'm not saying that that uh one trend that i'm seeing out there is um standing up a whole you know you know data governance office across the enterprise and you know that would obviously include the cmdb and csdm within servicenow but then also your other types of applications that are out there and you know i typically right now see this at some of the larger enterprises but it certainly is an important theme that you know for for best results should be deployed in some level of uh you know integrity you know to help ensure that we got the right data you have the right data you can do you know wonderful things with it i agree so we do have uh seven minutes left here so i do want to make sure that we just open up for for any other questions from from the group i think we've had a really good discussion and we've had some really great questions coming through and you can come off mute and ask a question i'll get us started here so uh andres i do have a question for you you are in a um highly regulated industry so what you're building today is phenomenal right i i do love the approach how scalable do you think this is to to other industries especially those that are in highly protected markets and industries so we we have come to recognize that cyber security is paramount for our ability to be able to deliver services right life-saving services and as that we have put it at the highest level of a strategic initiative and when we do that and we go ahead and in not only build it out in the csdm and cmdb we're able to also show the value that we provide to the organization that recognition of cyber security being one of the top make it or break it to the delivery of service is something that we all need to internalize and recognize to be able to decide right if it's time for us to share it and contribute right take it out of the corner office that is completely locked down and be able to bring the right visibility right for the enterprise to manage as a strategic function of the enterprise and when we do that then we take the full benefit of servicenow and we can also highlight the contributions of the practice but anybody else should be able to do the same fantastic yeah john just asked a great question um for the group actually for for every uh the audience you know who who is there anyone else out there using cscm for business continuity or even um dr prefer that from that perspective that's one of the benefits of frankly when my company got acquired is that we as a business unit can encourage um you know what the out of the box csdm looks like and we're we're doing that and seeing that and also you know always looking for improvements there too to see what makes sense to have naturally included um within that uh data set yeah i should add to that i like the fact that bcm provides the flexibility right to be able to deliver a lot of this functionality out of the box right so if if you know it's not restrictive in the way that that is implemented it allows you to also be able to scale up with a lot of that functionality yeah and and you have a a few things going for you right you're a cmdb owner you're federating the support which is not just the support it's also the accountability across the business um and then there's also a greenfield implementation right so you have this clean slate that you get to uh you know this bland canvas that you get to paint which many of us don't have yeah and the the part that you don't see is the many bruises that i got at blue cross uh with always kept me in line as to guard rails right and so they were very good at uh providing um a lot of the knowledge that has been shared here comes from the blue cross blue shield team of luciana that have excellent you know principles and in practices right that that have allowed me to now come with a clean slate uh you know with a new vision so yeah anytime to any transformation leaders and they're asking how other organizations you know do this and best practice yeah we can provide some of that but i can write you a much longer book on what not to do so experience uh definitely comes into play well great um i know we've got about a minute left here but if there's no other questions we'll go ahead and end the meeting uh recordings presentations all that will be available um in a follow-up uh we do have a share out there um but but please if you have any questions ideas feedback please send it to us thank you again andres for the time and aaron uh it's a pleasure having you guys on sounds great seeing you guys yeah thank you
https://www.youtube.com/watch?v=N4-OLMRJVvw