logo

NJP

Building on Past Security Efforts to Drive Toward Zero Trust

Import · May 19, 2022 · video

so i'd now like to invite uh mike road to the stage and have another um quick conversation to sort of dig into zero trust in particular something that's been alluded to at different points today of how do you know how to build on the investments and the tools are already there and and so the focus is about how to not start from zero on zero trust so mike how are you so thank you for being here today and um and mike wrote i should say is the deputy chief information security officer uh for federal uh for servicenow and um and so obviously you've been thinking about the zero trust challenge uh on any number of levels longer than uh longer than most um and can we sort of start with a baseline you know we've talked about the different guidance that's been issued here over the last uh year year and a half um how does uh you know how does the cyber order and um and m2209 uh line up with your general understanding of your definition of zero trust yeah well thank you troy so yeah zero trust to me when i first started hearing about eight years ago was really this nebulous term right it was cloud services way back 15 20 years ago what is the cloud is this up in the air where where is my data going i felt that way a bit about zero trust as well then started kind of digging into it a little bit more uh you know reading more more guidance and understanding about it i thought there were some great analogies here earlier today uh you know specifically the one about getting access into a skiff and if you're trusted to get into this gif well you're trusted to go everywhere else within that particular skiff and in reality no we need additional protections we need we need those additional gates across your devices across your networks and ultimately where your data resides and so xero trust really started hitting home with me a little bit more um you know i think there have been some efforts that have done previously things like the cdm program that have built some foundations for for implementing zero trust but ultimately it's going to be a journey i don't think there's there's definitely not a silver bullet out there today and anyone that does tell you that they've got a tool that can solve your zero trust problems run as quickly as you can because there's not one out there but it's really going to be more of a combination of tools combination of new technologies and processes that evolve over time and do you think the uh you know the guidance is out there is evolving accordingly because i lumped it all together but we've gone from sort of general statements that we should explore this to um uh you know to um sort of reference guides that have been put out uh by sysa by omb and now to very specific uh implementation plan requirements for for agencies do you feel like do you feel like what's being required is is appropriate to to get agencies to where they need to be it is definitely going in the right direction um you know i like like i said you talk about zero trust a couple years ago it's a concept um now you know cisa just showed some very specific guidance and details of what what the objectives are and trying to what you're trying to achieve through xero trust and i think between the government and and the government frankly has been been uh really the thought leader in this space and a lot of times that's an industry looking at government you know when we're protecting our corporate networks and understanding what we need to do we're looking at the government for some of the the latest and greatest uh guidance and and and capabilities that we should be looking at ourselves and one of the previous industry speakers today uh talked about how conversations been changing with with customers over the last several months are you seeing a shift in uh in in what federal organizations are coming to you uh for with regard to zero trust yeah a year ago it was uh mike what can what can you do to solve my zero trust problem and can service now take take care of that for me and while there's lots of things that we can do from an automation and orchestration perspective no there there isn't that silver bullet but you know again with the with the more detailed guidance that's been coming out agencies are getting smarter on this you know the requirements to build out specific plans for their agencies on on what their what their what their overall plan is going to be to implement zero trust i've absolutely seen uh the agencies getting smarter and smarter on this and what sort of building blocks are already there and i mean you can sort of take a um you know talk to particular tools or services that you or others offer um but also in the sense of existing federal security programs like where for agencies that are looking to leverage existing investments what do you need to make sure sort of part of your xero trust portfolio sure well i think cdm was a great is a great building block for for what agencies can leverage on from a pre-existing you know acquisition and tools that you have in place i think there were some challenges initially with cdm specifically around the idea of hey we're going to buy lots of tools we're going to buy licensing for endpoint protection dlp for vulnerability management and what i think a major lesson learned there was you can have all the tools that money can buy but if one the tools aren't integrated together if there's no communication across tools then those tools are going to be very limited in what they can do and that's one of one of the areas that we've been pretty successful in on the cdm side is you know a lot of uh federal agencies have leveraged cdm to acquire you know our servicenow platform to orchestrate and integrate these different tools uh we integrate with all of all of the major security tools that are out there into a single you know single pane of glass where you can you can create workflows where your vulnerability management systems your your vulnerability scanners will pop up a critical vulnerability and in the past it was you got to go figure out okay who owns that device who do i need to contact to to get a fix in place to get a patch in place whereas if you've got that integrated tool once your vulnerability scanner identifies it you've got you can kick off a workflow to get the team ready to to install test implement patch i know when when cdm was first kind of uh you know coming into coming to real fruition there was the challenge of well we've got to you know we now have to do the cdm stuff we already have our own security tools over here and agencies had to learn to you know figure out how to not have kind of you know two solutions running in parallel figure out how to integrate that are there similar um challenges now with cdm and these zero trust efforts are there are there risks of of having you know dueling solutions i do think so um you know i mean there's not going to call anyone on stage but there's many of us here that talked today about about tools and and a lot of our tools do integrate and work together but there's a lot of products out there and and each of the products has a different niche to it and i think it's really going to be imperative for the agencies to really do the research and understanding on what the different tools can do for you what challenge they can solve um don't let your vendor tell you this is the challenge you can solve or this is what i do this is what what what we do really really communicate what your what your problem statement is and what you're trying to achieve and then you can really find the right tools that are going to work and that are going to integrate together and um what about the um uh you know sort of going back to the guidance uh questions the i don't i don't know how deeply you've uh dove into into 2209 but the of the the server revisions that omb has asked agencies to make in their implementation plans i'm wondering if there's an area that you think uh you're especially happy to see of you know a a focus on a specific area or call for more detail there yeah i mean i think overall i think some additional detail um you know as as i stated the guidance has gotten better for sure um but if you're if if you're an agency cio you're you're ciso and you haven't been diving into the space for several years it's it's a big challenge and and the the timelines that are out there um people don't understand that this is this is not meant to be this needs to be up and running within this fiscal year uh this is this is a journey and this is going to be um a lot a lot of hits and misses um you know we're not going to have a perfect zero trust program i would say within the next 12 to 18 months there's going to be some very good and very effective pieces to zero trust but i think the the the call and ask for more more detailed guidance is is good it's helpful and and frankly i'm looking at it from our internal corporate side and how we implement this um we've got our own corporate network and we've got our network where our our customer data resides but you know we've got to look at this and we're looking to the government for some guidance on it as well yeah and you uh you know you mentioned that agents are asking smarter questions it's no longer hey can you you know can you give me zero trust in a box uh but as they're they're coming to to your organization what are the you know what are the sticking points what specifically are they looking uh to you and your team to help them solve with zero trust so for us it's really around the workflows and and really around you know servicenow is not going to come out there and and solve your endpoint protection not we're not an identity access management solution we're that's that's not what we do however where there's there's a workflow where they can automate something that was previously manual or that is currently manual um that's really where you know our discussions go and you know most of the requests are around how can you make me more efficient with knowing that i've got less resources uh less bandwidth i've got more products and tools but how can you help me optimize what um what i'm implementing and how i can get there and uh you know you mentioned automation which is one of the the kind of key cross pillar functions in the sysa model um we'll come back again later to how many pillars there should actually be in these in these models but uh um but how you know how should agencies approach the automation piece of xero trust yeah i think i think really you got to look at what you have in place today and and start attempting to automate anything you possibly can at this time um it's not a scenario where hey let me get all of my my tools my products in place my processes in place then let me start thinking about automating everything it's it's take a piecemeal you know uh like i mentioned the vulnerability management process if you can if you can automate the the area of once you've identified a vulnerability to actual implementing a fix if you can automate that to reduce the time that it takes to get that addressed then do it today that's gonna that's gonna help you from a zero trust perspective that's gonna help you from a security posture perspective today um so you know the way the way i look at it is is whatever you whatever you've got in place today look at ways where you can make some automation efforts because then maybe you save on resources and you can spend those resources in other areas that require more manual intervention and you know when you see organizations pushing for automation is the is the bottleneck um not having the right automation tools or not having the data and processes there and ready to automate both so um you know i think a lot of times the tools are there uh you've got the tools it's just not necessarily realizing that there are there are ways to integrate these tools um pretty effectively but you know another key area though is is we kind of get stuck in this mindset of this is how we've done things this is what we do um this is how we handle poem reporting this is how we handle um risk assessments and sometimes it's it's it's a good idea to take a step back and take the holistic approach of looking at hey where where are the steps in my process where i don't need a manual decision or a manual intervention point and and really look through to find those process to find the data flows um within your organization and that's really going to help lend itself to to to being able to automate more quickly good and you know this has come up over and over again this is a process when you said 12 to 18 months first i thought you were going to say i don't think we'll be there in 12 to 18 years and but the uh you know top to bottom people have talked about this is going to be a marathon and um and automation isn't the only thing that agencies need to be focused on as they're looking to you know leverage the tools they have get the data in place what are the other kind of core building blocks that you're urging your customers to focus on yeah and this has been mentioned a couple times uh during the sessions today one is you know how are you gonna protect what you don't know you need to protect so you know get an accurate inventory understand where your data is going um document your data flows really get a good grasp on what you need to protect and then at that point you can make some some better sound decisions on the types of tools you need types of processes you need um you know and that that's really really a critical aspect to it and with that uh that inventory that also kind of takes us to other you know other acronyms and buzzwords uh of the moment of of seascrim and and the push for cmmc and to bring like better you know better supply chain management as is there a way to sort of you know get that bird with the same stone as well or am i am i conflating too much there is i mean i think i think especially you know very familiar with the cmmc uh process and and looking at vendors that have gone through a validation process um you know i don't think it's again i keep saying silver bullet i don't think cmmc is a silver bullet on the vendors that you use or the software providers that you're going to use but it's another validation point for you as an agency that i i can try i can i can treat this this provider as more trustworthy or this software is more trustworthy it doesn't take away your your ultimate responsibility to to really understand what your risks are and what the risks are to the data that you're putting in these environments or putting in the software but i think those those frameworks those certifications are definitely things that agencies need to consider when making software purchases for sure and um in terms of what agencies are working on now you know you talked about some of the things you thought were good in the in the guidance is there you know is there any part of the zero trust journey that you wish was getting more emphasis uh right now whether from individual agencies or from the um you know the ombs and systems of the world i think uh focusing on the data is a big thing because that's ultimately the the end game here it's not hey who can access this network or who can access this application if the data is not sensitive i don't care who accesses that data so it's really you know getting a grasp on what type of data you're storing in your systems what type of data you're sending outside of your environment to to other agencies or or to cloud providers and the like really understand what the sensitivity of that data is and then that will help you with determining what level of protections you want to put in place because the protections are going to be different it's publicly facing information that i'm storing in my internal systems i'm not that concerned if it's if it's privacy data it's medical data if it's wartime data that's where i'm really going to going to want to spend and put my you know put my true focus in very good there are there are follow-up questions i could ask there but that would take us to a whole different workshop so i'm going to leave it there but uh but mike thanks very much for being part of today's uh discussion i appreciate the conversation welcome thank you troy

View original source

https://www.youtube.com/watch?v=dcqVSsg2CRA