SecBytes (S2E1) : DLP (Data Loss Prevention) Incident Response with ServiceNow
[Music] chris walker your security doctor back again for another exciting session around data loss prevention incident response and that's going to be today's topic we're going to talk about data loss prevention our newest addition to the secops family and how we can actually start to streamline those day-to-day operations handle incidents from a day loss prevention perspective some of the different integrations that we actually can connect to today and then we'll just do a high level demonstration around that now of course today's conversation is brought to you by my pocket protector and of course servicenow so let's go ahead and get after our agenda first and foremost let's go ahead and define what is data loss prevention next we'll talk about the dlp challenge and how servicenow is planning to solve it last we'll look at the integrations and then of course a very simple demo of the data loss prevention offering here at servicenow so let's talk about data loss prevention what is it well we've clearly defined it right here but there's more to it data loss prevention actually classifies regulated confidential and business critical data identifying if there are violations against a set of defined policies think hipaa or pci or even gdpr and it's typically driven by those regulatory compliance efforts where we need to understand and identify how we enforce the alerts and the protective actions to prevent end users from accidentally or maliciously sharing deleting or moving this data from the organization and putting them at risk and that's what happens we see this on a day-to-day basis a lot of these organizations and industries have either users with malicious intentions or just simply clicking something incorrectly which then can actually put a lot of reputations at stake trust transparency and of course the reputation of your brand and your business so what do we need to do to protect the data loss prevention and make sure that we're controlling these different endpoint activities and filtering data streams and so on and so forth so in order for us to achieve this we need to understand the challenges so as we can see here servicenow was presented with this challenge from a series of conversations and customers and how can we start to go through specific use cases and also identify this data from all of these different areas of concern now as you can see we have data loss prevention admins user needs and manager needs that need to facilitate very specific use cases point blank we actually have the ability now to see the challenges and where they exist the bottlenecks and a lot of the issues so from here we can see data loss prevention admins they need an enabled integration for some of the popular integrations we'll be covering today the analyst also needs to be able to actually facilitate the hands-on keyboards right assigning to the users and managers and being able to take those open incidents close them and take them through the process now the end user of course needs to understand what they did wrong what happened why was this an action that was taken incorrectly and what do i need to do to further educate and train myself and so we've come up with a solution to facilitate all these use cases finally being able to help and facilitate managerial needs reviewing these incidents in a centralized and visible workspace which we'll be covering in today's demonstration so let's go ahead and get right after it starting with the initial data loss prevention integrations that servicenow has built all right i'm excited you're excited data loss prevention is excited before we get into the demo i want to go ahead and just preface the integrations since that was part of the agenda so over here are three integrations semantic proof point and net scope now we're going to continue to mature and evolve data loss prevention with more integrations functions and feature sets so stay tuned we're very excited to see this continue to grow now for the purposes of this demo we're going to be going through three key areas we're going to go through setting up dlp notifications an assignment for end users we're going to create the assignment rule for dlp incidents and then we're also going to set up the response due date rules and just kind of showcase what that looks like we'll come full circle to showcase what the workspace looks like for the manager as well as what the analyst from the data loss prevention side would see so let's go ahead and start with the basics we need to go ahead and actually set up our default configuration so you can see here i already have this configured but in a real world scenario this would probably be set to zero this would not be checked off and of course these areas would not be filled in so we're going to go ahead and just go through this step by step now the purpose of this task is to enable you to specify the frequency at which email notification should be sent to your end users for example you can set a notification preference to accumulate these incidents and then send them an email digest maybe on a once a week basis so by assigning that incident you can specify which group to initially assign the dlv incident to now we've done that we can now identify what needs to be prioritized for our data loss prevention operations teams so let's go ahead and select the seven that's a good number let's go ahead and automatically update our parent state based on any child incidents and then of course let's go ahead and select our default dlp ops group and for our end user identifier this is actually what we use to identify the end user so some possible values here we're going to go ahead and select the file owner and then just simply click save boom we are done so simple next let's create the assignment rule for data loss prevention incidents so we're going to go ahead and go to our assignment rules from our application navigator here you see i've created one to assign data loss prevention incidents now this is pretty straightforward and very simple the purpose of this area is to not just configure what the assignment rule is but also to configure how it's going to be assigned based on a subset of conditions so we can see here we are assigning a dlp incidence i can put in my description here my scan source is the endpoint file system of course we can select other scan sources and then my severity conditions are high and medium here i'm going to go ahead and assign this to my manager and use the manager field and of course my file owner to identify the end user so now that i've configured that let's go ahead and move over to the response due date rules now with the due date rules it's very straightforward this is how we're going to now escalate to a higher tier right in this case my manager to set up the response due date to determine how much time do you want to give to your end users to respond to this assigned data loss prevention incidents so for example let's say a user had credit card information in a cloud provider or on the network in some file system what do we do about that well we've identified it we've detected it now we've opened up an incident and we've assigned that to the end user with an email but they probably have a couple of days before we're actually going to go ahead and take some brute force approach whether that's removing the sharing file permission settings or disabling access or maybe some other type of internal business process based on the policy so let's go ahead and set up that escalation so here we have our response due date rules here we have one that's escalating to the manager in several days again we've set this to active our scan source is set accordingly right the endpoint file system medium low and of course it's going to escalate any overdue incidents to the user group dlp ops group and we see escalate has been selected so now that we have that conditioned we can go ahead and create the actual response meaning the email that's going to be sent out not only to our teams but more importantly to the end user because they need to understand the violation the policy and they also need to understand what file is associated to this particular issue so let's go into our dlp administration let's go into the templates and now let's go ahead and categorize these internet notifications for end users so that we can send them an email about those due dates or even coach the end users about what to do when certain conditions are met based on the email that's sent out right we can select a number of different variables so let's take a look at one of the default templates for escalation this one here is going to go to all recipients we can obviously condition this template based on a number of different fields but for the purposes of this demo i'll just show you what escalated incidents look like from a digest perspective so this is a weekly digest it's saying hi user the following incidents have been escalated and here we can see the over view table right the records or the incident records that are open so in this case maybe we wanted to add some more fields right some more variables so on the right hand side we can do so and we can do that we can actually showcase a couple of different things from the target user maybe we wanted to go ahead and capture their location right uh maybe we want to capture the date when it when this actually was created by um maybe some other information right their first name last name so there's a lot of different areas in here that we could certainly cover in terms of being able to again surface the most important relevant information so that the end user knows exactly why this particular email is being sent to them what the violation is what the policy was and so again we're coaching them we're training them we're educating them to make better informed decisions with the data that's in their possession so again it's really important to understand how we do that and of course we can facilitate these different templates by leveraging these different variables within the email template now that we have all of that set up again we can set up your incident response options those incident response options will allow you to perform a series of different tasks right based on the type of dlp incident whether that's deleted content or encrypted files or reporting false positives or a wrong owner or even reviewing entitlements again all this can be carried out and done within your data loss prevention administration so we can go ahead and set up those incident response options as seen here bring this up very quickly here i have my default option this is going to showcase some actions that can be taken and how we can actually respond or report these data loss prevention issues so again this gives you another way to condition filter and then of course report on those end user action mappings to then put an action behind this response right and so for an example right sharepoint implies that the scan source is sharepoint which now means we can either enter the name of the incident response or look up using that search the action would be that user responding to the incident and they can select that set action so that allows us to now understand what the user is doing and then taking the appropriate actions to then of course you know remediate this particular potential risk so we can go ahead and facilitate all of that there now of course when we look at these specific actions or these business processes of course this is going to be everything that we can do in terms of being able to facilitate more of those internal conversations but really facilitating better cyber hygiene right better data loss prevention and prevention so now that we have all these different configurations done from the administrative perspective let's now go ahead and see what this would look like from the operation workspace perspective so as the dlp admin as the analyst i'm able to see a lot of critical components that i wasn't able to see because all my sources were disparate and siloed across many different sources but now that i'm sourcing everything through those tools i'm able to see open incidents by severity in a total count top offenders based on those open active incidents i'm also able to see the scan source as well as incidents by policy most importantly i can see open incidents by age and this is just telling me between 61 and 90 days i have 139 total incident count and then open incidents by status right so by those states i can see i have 46 open 45 in review with the percentages right next to them so it's just a really nice way to again centralize this data all this information and then be able to prioritize my overdue critical incidents or incidents that are assigned to end users specifically that have not been resolved so this is a great way to facilitate those key performance metrics and those indicators on top of that as an analyst this would be my view so i would go into servicenow's data loss prevention tool i would then be able to see the specific dlp incident record that's been assigned to me and then of course open it and start to facilitate next steps to remediate and rectify this issue here you can see very quickly the details of said incident record but what's really cool is the file permissions we're pulling this information from those third-party tools such as netscope and proof point and semantic and we're able to pull and aggregate this information so i can see the name the permission sets all this information will help me further do my analysis and investigation to deem if we have a serious issue on our hands we can see that it's been assigned since i am playing the persona of a data loss prevention analyst and i'm in the dlp ops group we can see this was assigned to me of course we have our activity stream we can add attachments so on and so forth and then we have some options here at the top right and so going back to those user actions what are some things we can do well we could report this as a false positive maybe this was a scenario where the user actually did something but it was not malicious so now we need to go ahead and just report this as false positive they did it by accident maybe it's the wrong owner so we've identified this incorrectly let's go ahead and facilitate that conversation and of course then we can go ahead and submit a response or simply compose an email saying we've received it we've acknowledged it and we're going ahead and changing the status to maybe complete in this case if we're reporting it as a false positive with the subject body etc etc so we can do these different facilitations right within the actual workspace from my dlp incidents with that i'm going to go ahead and wrap up that was just a brief overview of data loss prevention incident handling and how we can facilitate those different dlp integrations right within security operations here at servicenow as always thank you so much and always stay safe
https://www.youtube.com/watch?v=bzqWBL6hb_8