logo

NJP

Drive technology best practices with ITOM Cloud Configuration Governance

Import · Jun 22, 2022 · video

hi everyone this is evans nicholson from technical marketing at servicenow today i'm going to talk to you about what's new for itom in the area of cloud configuration governance so what do we mean when we say governance for today's cloud center of excellence teams cloud governance means addressing questions like these are resources in the cloud actually being used what are we paying for and are the resources in the cloud configured and deployed per the norms established at the corporate level so what are your standards what's your company's standards for deploying cloud assets one important thing to remember is that misconfigurations can cause data leakage and then can you easily remediate configuration or misconfigured cloud resources when you find violations so let's go to the demo and i'll show you how with the help of itom cloud configuration governance these challenges can be addressed directly from the servicenow platform so we're looking at the cloud configuration dashboard we've got some speedometers up here but this is not speed this is actually percentage these are violations so what this means is 16 of my aws footprint is compliant so that's pretty bad we need to do some work there and 81 over on azure 81 compliance for all the assets or all the cloud resources that we're checking and i'll talk a little bit in a minute about what those resources are so let's look down here what's going on with aws what are the violating resources looks like a lot of vms of medium criticality so you've got your criticality colors there and then what what are the resources that are violating those policies so let's look at the drill down pane and we'll talk a little bit more about the objects so what we're looking at is virtual machines object storage or iam and that stands for identity access management currently with cloud configuration governance these are the main objects that we're looking for and we're reporting on and designing policies around so what we're looking at below are the actual policies so it looks like we have 36 vms that are missing from the cmdb and this is based on a policy that we ran so this is a violation of this policy if i go down to this one hardware type non-compliant aws and then this last one long-running non-production vm so 11 vms we found violate this policy long-running non-production vms and here's a list of our policies now remember this is not this is not all you get this is a framework on which you can build more policies and you can design based on your needs right so it's flexible and it's customizable and i'll show you a little bit about that with this first example so in our case we had a problem with some vms that were long-running non-production vms so they're not they're dev test uat right and they're running we don't know if we need them anymore is it a waste of money is somebody using this we're not sure so we designed this policy to check for that so let's go back to the policy list let's check out this one that actually is out of the box aws s3 enforce bucket encryption this simply goes out and checks for aws s3 buckets that are not encrypted as the name implies right but this is important because if you have sensitive information in the cloud it's not encrypted you're at risk okay nobody wants risk these days and that's a big fear actually of migrating things to the cloud is this risk factor a lot of people don't understand that and if you can show through these reports that you're compliant in this way it helps ease people's minds a little bit another thing you can do from here of course you can create policies but we need to test them right before we actually let these loose so this is the way you test it you go in and you can find a scanned run that has already occurred normally the way this i'm just going to pick this top one but normally the way this happens is these policies are assigned to a policy set and those sets are scheduled as a task and they run automatically and they populate those dashboards that we saw at the beginning of the demo so what i've done now is just i've checked this policy against a previously run scan and it is working because what we're seeing is a bunch of s3 buckets that are not encrypted so how do we fix that this is a report this is great but let's close the loop let's fix the issue you can do that by selecting any of these rows and you can hit remediate i'm not going to do that because this is not my environment i don't want to lock somebody out of their bucket but that's how you do it i love the fact that you can close the loop and fix the issue we're not just showing you a bunch of reports things that are broken that you need to go fix somewhere else we're doing it all from the single system of record service now all right let's go back and go back one more and again so we're back to the compliance list now let's go to the remediations tab and let's look at some of these things we've fixed we saw a little bit about how we would address an s3 bucket non-encrypted we can see you know some reports on that here and then hardware type looks like on the azure side there were some hardware types that were not compliant monitoring state vm probably wasn't being monitored so we fixed those and then probably my favorite the bottom how quickly were these remediated this is really important for those metrics those slas that your team may have and if assuming these numbers are good this is something you could share with your boss's boss's boss but in all seriousness it is good to know how quickly your team can react to issues that have that we found and this is this is how you see it right here so speaking of reporting let's go to trends this is a great way to look at the big picture you know how many violations did we find are is it getting better or worse in our case it looks like it might be getting a little worse over here but we did pretty good here a dip down around the 22nd so this is a nice way to visualize policy compliance for your cloud items your cloud environments this concludes our quick demo of cloud configuration governance and so let's recap remember this is not just a static set of policies but it is a platform it's flexible it's extensible and you can build more policies as you see fit moving forward your cloud center of excellence teams when they establish new standards they can create new policies and enforce those standards another benefit is you get a powerful set of tools to track violations on your cloud environments this can help you identify unused resources as well as discover security vulnerabilities in the public cloud and then when we find issues we find violations we can remediate them directly from the servicenow platform for more information on all things itom check out the main product page thanks a lot and i hope to talk to you again you

View original source

https://www.youtube.com/watch?v=XERLhm7Sczg