logo

NJP

Systematically Harden the Digital Attack Surface with ServiceNow Vulnerability Response

Import · May 24, 2022 · video

today we'll be looking at how servicenow helps it and security teams work together to systematically harden the digital attack surface organizations face vulnerabilities in the tens and hundreds of millions and an ever-expanding attack surface the recent log4j vulnerabilities showed us that response teams need to be ready for emergency exposures in high volumes across different attack surfaces servicenow vulnerability response helps security and it teams work with this data at scale making it easy to find what matters and act on vulnerabilities in bulk maximizing efficiency the vulnerability manager workspace allows security teams to visualize their data in watch topics this makes it easy to track millions of vulnerabilities and visualize exposure watch topics show the types of vulnerabilities and assets that are most important to your organization security teams can set up sophisticated watch topics that capture specific slices of their data and monitor when to take action such as the log4j vulnerabilities shown here when the response team is ready to act on a slice of vulnerabilities they can initiate remediation in bulk across a whole wash topic by creating a remediation effort the work will be automatically divided into remediation tasks and assigned to the appropriate stakeholders in it remediation groups remediation efforts and tasks help us organize vulnerability data into easily managed chunks so that it teams can quickly and efficiently target and remediate the most critical vulnerabilities that slip through the patching process the it remediation workspace gives it owners a view into their own work they can see their assigned tasks vulnerable devices they own as well as the solutions and patches available to secure those devices from here our i.t remediation owner can work on fixing these vulnerabilities within their remediation target they can even schedule a patch deployment through microsoft sccm or hcl bigfix if they're ready to fix the vulnerabilities in this remediation task they can create a change request at the click of a button change requests can be created easily and accurately from here using your organization's standard change templates and any customized change approval workflows that have been put in place note that information about the vulnerable assets and how to fix the vulnerability is pre-populated into the change request if available this integration is bi-directional so when the change has been implemented the remediation task and its vulnerable items will be marked as resolved and await confirmation from the next scan in this case we'll simply resolve these leaving a note that change implementation is in progress but how do security teams and it remediation owners know what to work on first using threat intelligence and business context available in the now platform vulnerability response provides true risk-based vulnerability management tailored to your enterprise servicenow can act as a calculator of calculators pulling in information from all sources and providing a 1 to 100 score of cumulative risk simple gui based calculators can be used or if desired more precise and complex logic can be supplied in javascript for instance we can change the weight of the input criteria to prioritize vulnerabilities with an available exploit on internet-facing cis that support a business-critical service we can even incorporate third party sources into risk score calculations like the tenable calculators seen here to get vulnerabilities to the right owners scan findings are automatically assigned to groups or individuals based on rules assignment rules can be tailored to your needs using any data available in servicenow to determine the best assignment for a vulnerability these remediation tasks created earlier for the log4j vulnerabilities have been automatically assigned to the best groups but sometimes vulnerability ownership is too complex for rules when a vulnerable item is unassigned or incorrectly assigned we can use machine learning predictive intelligence provide assignment recommendations in bulk saving security analyst time and chasing down assignments and getting vulnerabilities to the right owners faster but to fix a vulnerability security and it teams need more information than a cve id and a risk score they need to know what solutions are available what other softwares could be exposed and references to common knowledge from multiple source sources servicenow stores a library of cve entries from the nvd alongside third party vulnerability definitions we also store reference information and a list of vulnerable softwares to be presented alongside your scanner results this is what the recent log for j vulnerabilities would have looked like to an investigating analyst in particular this log for shell vulnerability the threat intel integrations help us understand what is happening with this vulnerability in the wild is there an exploit kit for it is it being exploited often solution integrations with microsoft and red hat show the available patches and fixes and which solution is preferred for each item this provides remediation instructions to teams without the need to search whether it is applying a patch or something like changing a setting with all your vulnerability data in the servicenow platform even the high level reports delivered to executives are built into a single source of truth this cso dashboard is available by default and features interactive widgets with real-time data this helps show actionable insights into your security posture like the prevalence of the log for j vulnerabilities shown here vulnerability response is the control tower of defensive security across the entire attack surface extending your response automation across application security and operational technology and iot vulnerabilities application security testing scanners can be integrated to show security flaws on in-house applications you can even perform penetration testing assessments on applications and capture the findings right next to vulnerabilities found by automated scans with operational technology management ot and iot vulnerabilities can receive the same risk-based response with all of the nuance of their purdue model equipment relationships and site management information in the servicenow platform your vulnerability data can be put into a new context with data from other business functions and the experience can be tailored to your processes and metrics users can create their own reports and dashboards this cso dashboard is a great example of what customers can rapidly build using our gui based report engine and drag and drop dashboards one of the advantages that servicenow has is the ability to bring together data from many groups to provide holistic insights across the board finally it's easy to integrate your security tooling with servicenow we offer integrations with vulnerability scanners like tenable security center and io qualis rapid7 microsoft defender veracode fortify on demand and tripwire as well as vulnerability threat intelligence solutions for enrichment such as recorded future i defense and showden and exploitdb all these and more are available to install with just a few clicks from the servicenow store alongside many more certified applications offered by third-party partners today we've seen how servicenow vulnerability response can systematically harden the entire digital attack surface by visualizing exposure automating response processes improving prioritization with integrated threat analysis and business impact triage enhancing collaboration between security and i t and providing the big picture analytics necessary to surface actionable insights thanks for watching and stay safe

View original source

https://www.youtube.com/watch?v=oIu5TEZgyuE