Systematically harden the digital attack surface
Transcript
X-TIMESTAMP-MAP=LOCAL:00:00:00.000,MPEGTS:0 [MUSIC PLAYING] Today we'll be looking at how ServiceNow helps IT and security teams work together to systematically harden the digital attack surface. Organizations face vulnerabilities in the tens and hundreds of millions in an ever-expanding attack surface. The recent Log4j vulnerabilities showed us that response teams need to be ready for emergency exposures in high volumes across different attack surfaces. ServiceNow Vulnerability Response helps security and IT teams work with this data at scale, making it easy to find what matters and act on vulnerabilities in bulk, maximizing efficiency. The Vulnerability Manager Workspace allows security teams to visualize their data and watch topics. This makes it easy to track millions of vulnerabilities and visualize exposure. Watch topics show the types of vulnerabilities and assets that are most important to your organization. Security teams can set up sophisticated watch topics that capture specific slices of their data and monitor when to take action, such as the Log4j vulnerabilities shown here. When the response team is ready to act on a slice of vulnerabilities, they can initiate remediation in bulk across a whole watch topic by creating a remediation effort. The work will be automatically divided into remediation tasks and assigned to the appropriate stakeholders in IT remediation groups. Remediation efforts and tasks help us organize vulnerability data into easily managed chunks so that IT teams can quickly and efficiently target and remediate the most critical vulnerabilities that slip through the patching process. From the IT Remediation Workspace, the IT remediation owner can work on fixing these vulnerabilities within their remediation target. If they're ready to fix the vulnerabilities in this remediation task, they can create a change request at the click of a button. Change requests can be created easily and accurately from here using your organization's standard change templates and any customized change approval workflows that have been put in place. Note that information about the vulnerable assets and how to fix the vulnerability is pre-populated into the change request, if available. This integration is bidirectional so when the change has been implemented, the remediation task and its vulnerable items will be marked as resolved and await confirmation from the next scan. In this case, we'll simply resolve these, leaving a note the change implementation is in progress. But how do security teams and IT remediation owners know what to work on first? Using threat intelligence and business context available in the Now Platform, vulnerability response provides true risk-based vulnerability management tailored to your enterprise. ServiceNow can act as a calculator of calculators, pulling in information from all sources and providing a 1 to 100 score of cumulative risk. Simple GUI-based calculators can be used or, if desired, more precise and complex logic can be supplied in JavaScript. For instance, we can change the weight of the input criteria to prioritize vulnerabilities with an available exploit on internet-facing CIs' support of business critical service. We can even incorporate third-party sources into risk score calculations, like the Tenable calculators seen here. To get vulnerabilities to the right owners, scan findings are automatically assigned to groups or individuals based on rules. Assignment rules can be tailored to your needs using any data available in ServiceNow to determine the best assignment for a vulnerability. These remediation tasks, created earlier for the Log4j vulnerabilities, have been automatically assigned to the best groups. But sometimes vulnerability ownership is too complex for rules. When a vulnerable item is unassigned or incorrectly assigned, we can use machine learning predictive intelligence to provide assignment recommendations in bulk, saving security analysts time in chasing down assignments and getting vulnerabilities to the right owners faster. But to fix a vulnerability, security and IT teams need more information than CVE ID and a risk score. They need to know what solutions are available, what other softwares could be exposed, and references to common knowledge from multiple sources. ServiceNow stores a library of CVE entries from the MVD alongside third-party vulnerability definitions. We also store reference information and a list of vulnerable softwares to be presented alongside your scan results. This is what the recent Log4j vulnerabilities would have looked like to an investigating analyst. In particular, this Log4shell vulnerability. The threat intel integrations help us understand what is happening with this vulnerability in the wild. Is there an exploit kit for it? Is it being exploited often? Solution integrations with Microsoft and Red Hat show the available patches and fixes and which solution is preferred for each item. This provides remediation instructions to teams without the need to search, whether it is applying a patch or something like changing a setting. With all your vulnerability data in the ServiceNow platform, even the high level reports delivered to executives are built into a single source of truth. This CSO dashboard is available by default and features interactive widgets with real time data. This helps show actionable insights into your security posture like the prevalence of the Log4j vulnerabilities, shown here. Vulnerability response is the control tower of defensive security across the entire attack surface, extending your response automation across application security, and operational technology, and IoT vulnerabilities. Application security testing scanners can be integrated to show security flaws on in-house applications. You can even perform penetration testing assessments on applications and capture the findings right next to vulnerabilities found by automated scans. With operational technology management, OT and IoT vulnerabilities can receive the same risk-based response with all of the nuance of their Purdue model equipment relationships and site management information. In the ServiceNow platform, your vulnerability data can be put into a new context with data from other business functions. And the experience can be tailored to your processes and metrics. Users can create their own reports and dashboards. The CSO dashboard is a great example of what customers can rapidly build using our GUI-based report engine and drag and drop dashboards. One of the advantages that ServiceNow has is the ability to bring together data from many groups to provide holistic insights across the board. Finally, it's easy to integrate your security tooling with ServiceNow. We offer integrations with vulnerability scanners like Tenable Security Center in IO, Qualys, Rapid7, Microsoft Defender, Vericode, Fortify On Demand, and Tripwire as well as vulnerability threat intelligence solutions for enrichment such as Recorded Future, iDefense, and Shodan, and ExploitDB. All these and more are available to install with just a few clicks from the ServiceNow store, alongside many more certified applications offered by third-party partners. Today we've seen how ServiceNow Vulnerability Response can systematically Harden the entire digital attack surface by visualizing exposure, automating response processes, improving prioritization with integrated threat analysis and business impacts triage, enhancing collaboration between security and IT, and providing the big picture analytics necessary to surface actionable insights. Thanks for watching. And stay safe. [MUSIC PLAYING]
https://players.brightcove.net/5703385908001/zKNjJ2k2DM_default/index.html?videoId=ref:DEM1518-K22