Continuously Monitor and Intelligently Respond to Tech and Cyber Risks
hello and thank you for taking time out of your day to learn about how your organization can continuously monitor and intelligently respond to evolving cyber risk today we're logged in as andrew taylor which has a view of risk management where he can effectively communicate with stakeholders across the organization through integrated reporting of that current risk supported by the now platform so what andrew is able to see is those entities with the highest risk in the organization different areas that that risk lies and ultimately that risk plotted on a heat map what we can do is expand that heat map to get an even deeper view into those risk and on the right hand side we can see the risk register items color coded to where they lie on the graph so there's a lot of flexibility in this reporting ability to filter by entity and see exactly the risk you need if we go back to the dashboard there'll be some tasks that andrew will be able to complete on the right some quick actions that you can launch and down below we can see what areas have the highest risk what tasks need to be completed what controls need to be implemented what risk events have been triggered and then ultimately what issues have have arisen out of that but today what i really want to focus on is our ability to perform risk and control self-assessment using automated factors so what i can do is drill into a particular risk here for example loss of availability we can see where that risk lies within the organization grace being the owner of that risk categorized by i.t or maybe enterprise risk and down below we get an idea of the status of the min the risk it's already been completed and we're in that monitoring phase so from the assessments that have been performed there's been a high inherent and residual because the controls that are in place are not effectively mitigating that risk so let's go into a risk assessment and see why that is so drilling into a risk assessment that was performed by grace and approved by james what we can see is the different inherent and residual ratings both being high and then that controls effectiveness being ineffective ultimately driving that high residual score so we're using a lot of automated factors so we don't have that subjectivity that the human element brings in but when grace logs in they'll see a very similar view to this on the right hand side they'll have information on what is requested of them and what needs to be completed if we want to we can drill in and see that assessment so starting off on the inherent assessment grace provided the impact and likelihood and we were able to combine those to get an overall score of the inherent risk next grace would have gone on to fill out that control assessment so controls are brought in we can see their compliance status and then ultimately if there's any indicators which is our automated testing method we're able to pull those in and show how this is automatically failing now there's still manual testing methods like a design or operating effectiveness the design effectiveness here being effective the system is taking in to factor all those different methods including the indicators and more manual testing methods to get you an overall compliance rating this one being ineffective so that will then drive our calculated overall residual score which is then high and grace is asked to give a risk response so the risk response here being mitigate but she could have easily chose to reduce transfer avoid or accept that risk and provide their comments below so once this was approved we're able to see that score and ultimately what we can do now is look at the controls that are in place to mitigate that risk so we saw that one of the controls was failing and non-compliant so we can see that the perform external vulnerability scans on the organization system is failing and if you remember that was failing because of the indicator that was tied to it so jumping into here we get an overall view of that being non-compliant right up front we're told why the reason is that indicator is failing and then if we want to we can jump into the indicator indicators here are a way that we can automatically track the effectiveness of a particular control and to get started we can take advantage of cis controls which i'll talk about in a moment or we can inherit them from templates and replicate those throughout the organization for something like this about vulnerability scanning jumping into the indicator template this is gives you the ability to replicate this throughout the organization we can see what type it is whether it's automated or manual this one being automated we're grabbing that vulnerability data and seeing how many times it's performed so we're counting how many times and if it's over one time we give that a pass but right now it's not being performed so it's getting a zero and then down below you can set additional criteria such as where it's targeting for this example it's inside the servicenow platform or cmdb and that information is being collected on a weekly basis and recalculated so that's the template that we pulled from and now if we go back to the indicator you can see that we pulled from that template and tied it to a particular entity and a control all the other information inherited from the template and then down below we can see again how frequently it's being collected and ultimately the result of it being failed jumping back to the control we can see the indicator that failed and ultimately an issue that arose out of that jumping into the issue this is where we would assign it out to an individual i.t owner or the business owner to ultimately understand the issue and remediate that lastly once we performed a risk assessment understand that the mitigating controls tied in those automated factors what we're able to do is respond to mitigating that risk in this case the risk response task has been automatically generated and signed to grace to be the respondent this task helps users to determine if a vulnerability scan might be needed or if adding more controls might be a better suited solution now you might be asking how do we define these indicators what we have is the technology controls monitoring accelerator this provides cis controls to jump start in defining and monitoring those indicators so this can be downloaded and import into the environment align to your different areas and use as a baseline to get you started thank you for taking our time today to understand how we can improve decisions and performance with risk intelligence embedded in daily work and integrated across the enterprise for any questions please reach out to your team or visit servicenow.com risk thank you
https://www.youtube.com/watch?v=z_0g4vuK1_c