logo

NJP

Secure Enterprise Visibility Powered by ServiceNow

Import · Aug 02, 2022 · video

when our kicked off uh first i wanted to say thank you for everybody that is attending today we really appreciate you taking the time to join us to talk about secure enterprise visibility um the solution that we have been talking to our customers in great detail about and uh our customers are very interested in the things that servicenow can do to help them with their challenges so we're gonna go ahead and get started excuse me just one second i'm having a oh let me share my screen again sorry about that um so today with me is my my dedicated team um and it's myself matthew beard i'm part of the secop solutions consulting team i also have chris walker who's part of the sec ops advisory consultant team and also david desh who's with the i tom advisory consultant team and then also john st john for the risk solution consultant team we'll be taking you through the webinar this afternoon all right the agenda today is going to be we're going to touch on the visibility challenge and strategic comparatives we'll go into the service now as your source of truth and then we'll get into the system of action and then we're going to jump into the demos big bulk of the webinar will be the demos at the end of the presentation we are going to have a list of five questions we'd like you to answer we love to get our customers feedback to make sure that we're providing the value that our customers are looking for um and so we can generate more webinars and make sure the right content is out there for everybody so and this to start we're going to talk about the enterprise visibility challenges so one of the first challenges that a lot of our customers are talking about when it comes to visibility is the the lack of inconsistent incomplete inaccurate out of date data that impacts the confidence levels within their organizations this is something our customers want a lot of help with and come to servicenow to make sure that we can remediate those challenges but some of the other challenges that they are looking at are the growing number of resources to handle the addition of on-prem and cloud technologies these resources are supporting multiple technologies and they need the proper visibility to make an access to the data to make decisions quickly also they are concerned that there's too many point solutions this creates more complex processes and gives them no single source of truth right typically each tool that they have has its own data point and they have to retrieve data from this point tool at this point tool all these different tools and this promotes that time-consuming process right that's one of the biggest challenges they have and then the hyper-rated change that they deal with especially with digital transformation and also the explosion of cloud and container-based services this complicates the issues even further um you know so we talk about these challenges but what are what are the impacts how does this impact our customers right slow incident response resolutions failed remediation efforts are out there and then also the lack of shared information across i.t security and other business units it's virtually impossible to manage what you cannot see or track so we talked about more about channels but let's talk about the business context right it's you know the ability to tie services to other assets and and and get more you know that's what we're hearing more and more customers talk about is that that ability to tie these services to assets and some of the challenges that come with that are you know the manual creation of reports past assignments sla tracking performance issues um but that alco also piles on with the dynamic nature of networks um it's an ever-changing landscape you know both for it and security perspective i mean we could do a whole nother webinar on the threat actors that are out there from a security perspective that impact security i.t and business it's not just security that's affected by that it's the whole landscape and then also the complex custom applications requirements that are ever changing for organizations um the stat here says 54 percent of leaders are saying that business i.t and security is that alignment is not existing right and our customers need that customers want that and that's why they're coming to us and are interested in this secure enterprise visibility that we can offer um but that you know that with that business contest it creates more problems also for prioritization outages slower response times i mentioned before very difficult for customers to that don't have this visibility to perform at the top level that they want to um so going in you know there's five areas that we focus on we'll kind of get into that into the demo and everything um more of the technology but you know when we talk to our customers and we want to address the enterprise visible challenge for them you know there's five areas that we really kind of focus on um you know it's a strategic alignment with with business i.t and security to understand those gaps right we want to make sure that everybody's unparalleled and everybody's communicating that's very very important um the strategic partnerships you have out there you know you want to make sure that you work with a partner that has the ability to to create that roadmap create that strategy and deploy that strategy right and when it comes to deployment think about a phased approach you know when we talk about strategy there's there's a lot of different stakeholders involved right and they want that they have their requirements and they want their quick wins we do it by doing a lot of multiple modules to get those wins for those stakeholders and meet those requirements there's flexibility involved also right you have to think about thinking outside the box um encourage and have the willingness to collaborate and think of new process and consider those processes and also setting the right expectations you know establishing a proper cmdb and a secure visibility program is an ongoing program it's not a point solution that's what we stress with our customers you know your business is extremely dynamic and solutions you rely on need to be dynamic also and so what i'm going to do now is pass it over to david dash who's going to talk to you about servicenow as your source of truth so david if you want to take it away thank you matt appreciate it thank you all for attending and coming to hear about secure enterprise visibility um matt talked about some of the challenges now let's start looking at how we can use servicenow to address some of these challenges servicenow is your source of truth and at the center of that is your cmdb and this enterprise visibility provided by servicenow within cmdb is the key to that operational success that a lot of our customers are looking for it gives this centralized place and a single system of action to interconnect your entire environment and have that enterprise visibility across all of the different things that are happening we start to see results in terms of faster incident resolution and changes are more successful and more incidents are being resolved with problems it's because we start to leverage servicenow as that place that allows us to have one place to go for all of our data all of that information about our enterprise that we need to have to run effective businesses and once we've built that we start branching out and secure enterprise visibility focusing specifically on security operations and managing risk in relation to the enterprise environment john can you add some context on how integrated risk management plays into this story absolutely david and thank you again everybody for attending um in regards to integrated risk management also known as irm there's several better together stories across the servicenow platform as you can see here when you look at irm and itom you're able to provide real-time compliance updates against internal policies and external regulations for it configurations you also have cohesive exception management processes to track i.t exceptions from compliance perspective able to aggregate risk scores across service mapping independencies and also able to automatically trigger risk assessments in response to ite events now with irm and secops you're able to generate an accurate measurement of risk and security posture of your organization you can see visualize risk scores from vulnerabilities incidents misconfiguration and suppliers you're able to utilize the defined and embedded integrated exceptions management process and you're able to continuously monitor the effectiveness of security policies controls and mitigations now i'd like to hand it over to advisory solutions consultant for secops chris walker thank you so much john and david now we have an understanding of the cmdb we have an understanding of risk now we need to understand how do we actually prioritize that visibility and all that business contextual information so when we think about this it's important to not only have transparency but have a tactical approach to how we handle this system of action where we can now execute immediate response through playbooks through security risk and beyond those specific areas of concern so as we're showcasing this keep an open mind and remember that it's important to have complete visibility across your entire enterprise ecosystem in order to identify these different entities and protecting those assets and investments we can take all of those disparate tools the disorientation and we can start to take that disparity and give you the clarity which you'll see here in our demonstrations coming up very shortly as we continue to go through the guided presentation of today's secure enterprise visibility webinar most importantly the key takeaway for today's discussion is to transform this data so that it can digitally give you the information you need using proactive approaches workflows and day-to-day operations that can be measured by performance analytics analytics metrics as well as intelligence that runs behind the scenes here with the servicenow platform and with that we're going to go ahead and get started with our demonstration first and foremost i'm going to have my colleague and my leader here mr david please go ahead and take the four thanks chris um so i'm really glad we got out of the sideways so quickly it's one of my goals um i'm just consulting so i like to show the platform uh the next screen that we look at will be the platform this picture is a picture of my home lab i drew this about a year and a half ago it took me six hours to draw this picture give or take the next day for those of you familiar i added an extra esx host and this picture needed to then be edited i said let me do this the smart way and see how servicenow can help me draw this picture and other pictures in my environment and just if i can understand my lab then my customers are going to be able to understand their environment so what what is my lab what is that picture representing let's get on the platform and i want to start out this is in servicenow the asset table uh a lot of the time talking with people using the platform and there's some question about well how is the cmdb different from a list of assets these are the assets that create my home lab environment i've got three esx hosts a number of cisco switches a wireless network some wonderful people at ubiquity even some iraqi gear going on virtualized windows environment as well there's 25 assets and generally those are some things that associate with cost right whether that's a physical piece of equipment or even a software license i'm going to go ahead and look at my core switch and see what that type of information that we have here is on our asset record this is where we track those things associated with costs it's a very financial record financial tab depreciation different contracts or warranties that it might be associated with and even expense lines that it's associated this asset however links to the configuration item a very specific one-to-one configuration item and this is where we started to understand how this switch plays into the rest of our environment this is where we capture the information that's more technological all of the relationships to other things that i have inside of my environment and this is where we can build our cmdb in addition that contextual environment information like our tables or mac tables or our neighbor information is also discovered and stored within servicenow and for your technical folk there are a lot of cool things that can be done if i understand the device neighbors of this switch also sometimes it's easier to look at a picture so depending what we're trying to look at we'll bring up our dependency map and the first thing we're going to see is this bigger diagram this is showing a certain type of relationships um and i'll use an example this windows server has an ip connection to this switch because this switch is my gateway for this server's ip address but i know i'm missing a layer too hot here these are logical connections pictured in a certain way this switch has these switch ports all right that starts to work if i want more of a layer 2 diagram and understand each hot i can just go to a slightly different view and now i have that same core switch and that same windows server and i have my layer 2 hop here as well i'm going to look at the entirety of my cmdb we saw that i had 25 assets for those 25 assets i have over 5500 configuration items this does include my on-prem lab as well as small presences in azure and aws but what i really like to juxtapose is my list of assets contains 25 things that i need to be financially concerned about my cmdb and all group by class contains 5500 different objects that i'll do different things in my environment and can be important to different people and to different sets of analysis or processes and tracked in my cmdb are things like a tracked configuration file or my database instances these are not things that we would generally track as an asset but things that we need to know so it's always important to me to show this type of overarching view about the breadth and scope of information that becomes stored in services now the other half of our cmdb in addition to those cis configuration items are the ci relationships or the relationships between those configuration items for those 5500 configuration items i have an additional 7 700 relationships and it's those relationships along with database reference relationships um in the database itself that allow us to understand the impact of everything that's going on and so that vcenter environment that i took six hours to draw the picture of a year and a half ago decided to go and ahead and discover it with servicenow instead uh there is a video on youtube about the first time i discovered this environment and it took 28 seconds to understand all of this and again we have a picture there's going to be a lot of information here i'm going to zoom in and i do have my filter if i need it to make everything a little bit more readable but the information that everyone needs is already here i know about my vm network adapters and how they connect into my network or i know that i have these hard drives that are providing these data store disks and that if i manage to take down this sand this is what's going to be affected or if my esx host has a vulnerability that if i have to take that host down to patch it i need to be motioned in these machines somewhere else so i don't interrupt my connectivity the last step from building this foundation for our visibility picture is to take what we've discovered and the cis that we've added and know about our environment and i'm going to switch out of my demonstration service now instead or out of my home lab servicenow instance into a one loaded with demo data and i'm going to look at what we call a service map this is the next level those ci's and those relationships reflect relationships that are written somewhere that we can discover through an api or snmp or through ssh and we know where to look and form those relationships the service is the combination of those cis in such a matter or manner that they provide our users or our customers the functionality that they need and so when somebody calls my help desk and says hey i can't order anything today or i can't check the status of any order immediately that that newer technician working at my help desk can go look at a picture of what provides that user customer the ability to check that order status and know what's going on or if a vulnerability comes in we know that that vulnerability affects a piece of our ordering system that's very important to fix and these relationships focus on this bottom left-hand corner they are not those written down relationships this web server uses these three application processing nodes and communicates with this database and there's no wire from rabbitmq where all of these top four things exist to v1 x42 but once we're able to look at connection tables take tribal knowledge and understand how that should be reflected in servicenow and use automated processes within servicenow to discover services like this we then complete that foundational picture because we understand how our environment is assembled to provide those services that are being provided to our users our customers our business with that i'm going to hand off to chris and chris you want to take over and explain how we're going to lay on top of this foundation that we just built thank you dr david really appreciate that insight on the cmdb which sets up that foundational principle and the importance of visibility so now that we have the visibility what's the value add with security operations how do we connect security to the rest of the enterprise well we do that with servicenow's security operations so now on top of david's house of cards we now know how to identify prioritize and then respond to those vulnerabilities to those incident records which can be generated from alerts that are coming from david's house in this case right maybe there is a potential breach from the front door or the garage door was left open or one of his security cameras has gone down an alert can be generated to create that security incident record so that way your teams know exactly what needs to happen in terms of that process or that playbook so what i'm going to do now is i'm going to share out my instance we're going to be focusing on how we're connecting those security components to that it operational management component that david had just demonstrated so i'm going to go ahead and share up my screen here and we're going to pivot right off of david's conversation so thank you dr david really appreciate that i'm chris walker the security doctor here for the sec ops organization here at servicenow and i want to make sure that as we level set this playing field it's important to understand one thing complexity is really everyone's new reality right we saw the dependency view we saw how things are mapped through service mapping but it's rapidly understanding that the attack surface continues to breach all of these different controls and tools that we continue to invest in and what happens is a lot of these different vulnerabilities whether they're infrastructure or container or misconfiguration risks or even from remote employees accessing content that does not need to be accessed and doesn't map back to a control or compliant compliance initiatives what we want to do is we want to create that digital blueprint and so this blueprint that david had mentioned right that dependency view allows me not only to see those dependencies and what they're mapped to or tied to but also understanding what's in the details behind this now as we had mentioned before what if i wanted to actually see the security incident records and vulnerability items that are tied to those affected configuration items those affected cis with a simple toggle here within my dependency view i'm under it services so as the it database administrator i now know that there is a vulnerability and there's also in addition to that a security incident record so by clicking on that specific entity here within my blueprint i can see a series of security incident records that are tied to my apache linux server so these are the cards that are dealt to me how i play this hand is where security operations comes into play because we are not only enterprise case management but we also have soar capabilities and so we are a sore and so much more when we bring in all of the different product offerings into fruition as david mentioned because the reality is everything here is overwhelming there's an overwhelming intake of threats and alerts and events that are happening behind the scenes so how do we handle this at scale so in order for us to do so we can now see all of the different details for our security incidents we can also see that this in impacted ci has a vulnerability item record which is being ingested from our vulnerability scanning solutions so those tools that you're using in your ecosystem can aggregate the information over into servicenow's instance which will then allow you to write back to your cmdb to create that one-to-one parity right the parity not disparity of that visibility so now that i have this visibility and as an analyst i want to understand what's my next move what's the next step because over 76 percent of organizations have no real common view of these assets or applications across security and i t and all of these other areas of concern so now simply by going into my security incident record i can actually just hyperlink right to that security incident record in question and i can see that this particular threat has been tagged threat crowd with threat intelligence has determined that there is an observable that has potentially malicious behavior in this case it could be a malicious url so it's enriching that security incident based on the alerts that we've detected from david's house we also see that there might be a likely phishing attempt right so there might have been an email that was received clicked on with some type of attachment that had malicious intent behind it right some type of attachment that executed remote code or some type of other vulnerability within their specific asset so we have two areas that we already have right at the top and we've already identified this through a security tag as you see here now we can take it even a step further you'll notice that because we have seen these things in our environment we also have our knowledge results so we can see specific knowledge results populated to guide us through potential answers or solutions and in addition to that we can also start to leverage your threat intelligence tools again further enriching those observables into your security incident records again writing that back to the cmdb so you can see what does the ci have what's being impacted what happens if i don't address this risk score over 50 or this criticality of high what happens right who is going to handle this and that's really the begging question for a lot of cyber security professionals it's who's in charge of what who does what and so we help you by guiding you through those playbook processes and those resources by rolling up those different incident records and vulnerability items into what we like to call our playbook approach and so the security playbook approach will guide you through a nist adherent process and we follow the same nist adherent process for nist 800-61 it's following that same computer incident handling procedure and all of the preceding protocols that we see in day-to-day operations when it comes to these different vulnerabilities and different security incidents that increase the workload so what happens when this workload increases right i have my incident records i know that david's house has been impacted in some form because i can see the configuration item has identified this as such and now i want to take this one step further so as i mentioned before we need that playbook and with servicenow security operations we're able to supercharge itom because now that we have the enterprise visibility we can start to identify prioritize and respond through a series of what we call these playbooks these playbooks are really valuable resources to not only prioritize based on risk and business context but start to automate either through ai powered workflows or collaboration through the playbook guiding you through the different steps and that chain of custody right so now as the analyst i can see we have a denial of service attack i can see the potential tags giving me some information but most importantly i can see who are my affected users right so luke skywalker has been impacted there are similar security incidents that are also being identified from the observables that match that threat intelligence feed that we're leveraging we can also see our configuration items so cis that are also impacted by that so we have a centralized view now right we've centralized and we've orchestrated a single pane of glass but let's take it one step further right how do we investigate how do we go through these step-by-step process and so now we can actually see our impacted users we can go through the investigation but most importantly we can see observables to actually now not only detect but protect those specific assets or entities and so over here on the right hand side in our playbook right back to what david was mentioning right service mapping provides that line of sight that your database admins and i.t practitioners need to now triage and isolate that issue well that's great chris well how do i triage it well let me show you on the right hand side over here we actually have the answers to those questions the first step is to review the malicious observables and you can see here this was a security incident task sit that was manually generated by our analyst or maybe our managers now of course we do have a series of playbooks that are already pre-defined so it gives you a stepping stone to build off of that and define your own business use cases and playbook resources we're going to go ahead and start this task and once i've started this task i can now enter in any relevant notes as the it practitioner but most importantly it's actually going to showcase the steps right because as you're putting data in you're also going to produce very valuable results on the outside of this meaning knowledge based articles can actually be orchestrated through this process so as i'm going through enriching this security incident record we can also curate knowledge articles that literally will show me the step-by-step process that will guide me through what steps need to be taken in order for me to isolate this particular issue and contain it so my steps here are to review the malicious observables so i go over into my explore tab in the observables i can see that we've determined and defined a malicious url or in this case an ip address so i can go ahead and perform a citing search which will do a global lookup to determine if other instances are impacted by this observable but for this particular use case i want to simply just block it right i want to orchestrate this block and this block request can be done either automated or in this case a manual post execution to that api now i'm going to go ahead and run this particular step we have already integrated palo alto as part of our own implementation and i'm going to go ahead and execute the block request for our global domain block list now any additional instances that have have that observable will also be automatically blocked by the firewall once i submit this so immediately we're starting to eliminate the hands-on keyboards we're implementing a playbook and a solution that adheres to nist compliance but also making sure that we have a complete audit trail of all of the steps that are taken which in this term we call our incident timeline so we can see all of the different operations and activities that have happened from the very beginning infancy stage of when we actually detected this from david's conversation right the visibility service mapping now we can start to triage isolate contain eradicate and of course close out this particular uh issue in question so this really becomes your battlefield to determine how you're going to handle collaborative collaboratively i should say via either an automated or hybrid process by leveraging different flows through these playbooks and to give you a very quick example of what some of those flows might look like in your instance you will have a flow designer and with security operations and a series of other products there are series of different playbooks that are predefined and out of the box this is going to give you the opportunity to start with something right something that is going to give you the ability to not only curate your own business processes but it's going to allow you to track performance across the entire organization how fast are we responding right mean time to remediate or mean time to respond how fast are we eliminating these vulnerabilities or these incidents that have been activated right so we need to understand how those specific entities are going to be handled across the actual organization and so in our example today right we are talking about malware right ddos attacks maybe a phishing scam has been detected so we have a series of different templates that can be leveraged through security operations to actually orchestrate how you could handle those from a automated perspective right and so it's going to give you the granularity the consistency but also the output of those results it's going to help you facilitate those conversations internally where can we improve the process as a cso or a cio as that persona i want to improve that process but i want to improve that process by leading the digital transformation for my organization to not only induce these playbooks but also adapt to constant technologies changing making sure i have operational excellence revenue growth security compliance and we can see here all of the different steps that are being taken so i've only illustrated just again a very high level way to actually handle some of these different incident records right going back to that dependency view we see we have two security incidents and we have a vulnerability item with the vulnerability item we also provide vulnerability response which handles patch orchestration deployments and those change management controls that happen again behind the scenes to make sure that those house of cards don't fall over so we need to make sure we isolate those issues so as we're continuing down this journey right because it is a journey the cmdb is a journey and in order for us to drive that resiliency and accelerate remediation we tell this better together story because not only are we gaining this visibility and insight in real time we now have the contextual information to assess our current security posture well how do we do that chris well it's a great question the way we assess that is through our performance analytics dashboards and this is another incredible component that i used as a customer myself back in 2014 i didn't know where to start i had crowns pens paper a big notepad and way too many red bulls it was really a nightmare for me i did not know where to start because i had so many different siloed tools solutions and sources of truth i needed to figure out a way to put all of these different entities and different data sets into one view and so the ability to now leverage these performance analytics provided me with real world results now i could see from a compliance perspective what controls are actually passing and what controls are not and identify those assets in question so that i can fix those issues whether it's two-factor authentication or maybe it's a password complexity issue or some other type of control that's not meeting nist or iso or fedramp or hipaa or some other type of certification right i need to make sure that i'm as efficient as possible to reduce the risk and the overall costs of a data breach or in a leak or an exposure i can also see vulnerability response and security incident response how well is my team effectively using those tools in those solutions right how do i manage these enterprise systems assets and limit the system sprawl or this this blast radius well i can do that by streamlining itom with security visibility to showcase here's how much time from an automation financial perspective we're saving but also here's how much time we're saving from a day-to-day operational perspective right so we're improving business results we're breaking down silos and at the same time we're improving the security posture so now i can see all my known vulnerabilities i can also see my incident backlogs what are the current incidents that are currently open what are the incidents that require my attention from a business criticality perspective or better yet who are my repeat offenders that are in my environment right and so that cmdb is so critical and and very powerful to really start to build out what your cyber security strategy is so now i can see all of these different assets and i can immediately excavate the information i need to start putting in those processes whether automated hybrid or from a manual investigatory research perspective so again to recap as we're continuing to go through this journey right we started with our dependency view we have all of these appliances in david's house we now know that there are incidents and vulnerability items that are impacting these services what happens when these services are down well if they're tied to any other dependencies they also shut down so it's just like when the power goes out we lose internet we lose lights we lose pretty much everything and we're dependent on being able to work either remotely or from our office so it's important to be more proactive it's important to leverage and train your tools and what's also important is as part of that proactive effort we also want to also we also want to implement better building blocks for transforming security operations with itom so for us to do apologies there for us to do that we need to go ahead and take this even one step further and so for those threat hunters on the call for those who have seen or used threat intelligence tools we also have the capabilities to leverage our miter attack heat map and navigator now this is another fantastic offering that we have natively with our solution we can take all of these relevant feeds these sources and we can start to visually represent where these different adversarial behaviors tactics techniques and procedures are living and breathing within our ecosystem so on top of knowing what assets are impacted we can start to predict it predict what areas need better mitigation what areas don't have the best detection coverage and we can map that back to those security incident records and to those vulnerability exposures and so we can immediately see this from the enterprise attack perspective or ics or mobile and then of course we can filter through this or even select specific data sources or see if it's a specific malware a specific malware attempt that we're looking to investigate or specific tool set that we're using as a sensor and so again there are so many different tools here that we can leverage but overall we want to take all those tools and we want to really put them into one solution where we can collaborate with more automation with more performance tracking and then that's going to help us eliminate a lot of those bottlenecks and gaps that we run into on a day-to-day basis so as i mentioned we're here to prescribe that cure and we really want to focus on how we improve resilience and business-wide performance so with that now that we have that baseline and we understand how the incident response side of the wheelhouse works let's start to talk about how we can help our end users right our clients those external users who are reporting these issues now with our security incident response catalog this is another great value add because we can actually use a lot of these out of the box predefined catalog items to start to orchestrate workflows after these specific catalog items or requests have been submitted so let's say i have a privacy incident and from this escalation i've determined that david or robert smith in this case we've detected there's a privacy incident that has been detected on one of the appliances so this could be a compromised account maybe it was pii that has been potentially breached or leaked from their accounts or from their asset in question so immediately i can go in and i can start to capture the relevant information check off if pii has been compromised add an attachment and submit now this is going to generate a security incident record so again i'm eliminating the need to have to pull from all of these different sources rather the tool will work for me and do the workflow to cover the most critical concerns through this real-time risk assessment so now when we take this over into the security operations centers right for my sock team members on the call what's important now is i need to have kind of my own virtual space to see all of those entities and honestly this could be from either a local or global perspective depending on if you are maybe an mssp or if you handle this from a day-to-day perspective as an i.t administrator or a practitioner regardless of the scenario we have multiple dashboards that will meet and exceed those requirements that you may have and so initially here i can see my security incidents by configuration items it just shows me such a simplistic way to visualize and represent this data most importantly it's going to replace a lot of the manual processes right the emails the spreadsheets the chats right we're in constant walkie-talkie mode let's get away from that and let's use david's approach to map out our entire house now let's protect those assets right and let's find out which of these assets have incident records tied to them let's understand how many major incidents have been escalated right major incidents meaning there are more than 50 different alerts that have come in for this same issue how do we handle that at scale it's an important question to challenge yourself with and ask how would we handle that in a real world scenario where 500 pcs or servers have been affected at one time and i'm going to showcase how we have addressed that concern as well leveraging our major security incident management workspace or our virtual war room so again these are just more analytics more reports for you to leverage and these are all out of the box which is fantastic news for everyone so you really don't have to build this we've really built this for you and we've scoped these applications to really take a wild garden approach to make sure that you only have access to what you can see based on the roles right based on your description your title but it's important for your eyes only to see some of this information and we can hide certain information as well for users who are not supposed to see confidential information that's internal for specific teams or for specific i.t leaders we can also start to look at this from a detection and responsiveness right so your slas so for my i.t itom leaders my i.t practitioners help desk managers sock managers this is a this has become our standard how well can we perform in these different environments how fast can we swim in this lane can we swim faster can we meet the expectations well we can and we can baseline this with our service level agreement metrics and again this is another component that's out of the box again can be customized to your liking but we can at least start to understand how many false positives have been detected what are true positive security incidents are we actually targeting and tackling some of the incidents that actually do have concerns behind them and actual prioritization what is that source effectiveness and so again we're just going through all the different ranks and then of course understanding the analysis behind that where are we when it comes to how many incidents are opened in the analysis phase versus the eradication versus the recovery so again it just really helps you baseline a lot of that information versus having to keep track of this through a multitude of spreadsheets and internal conversations now with that i mentioned the major security incident component right and so this is actually a new integration it's actually just enhanced security incident response this is actually massive i wish i had this back maybe 10 years ago this would have saved me a lot of time a lot of frustration most importantly it would have saved me time when i went through nist 2701 or iso 2701 i should say apologies so many certifications but this really would have helped me collect from a collaborative approach help my teams and all of the other key stakeholders collaborate in one space so what we've introduced here is major security incident management what we can do now and achieve is if you have now detected from your seam technologies a multitude of queries are coming through and we see that there is a brute force attack and it has now breached 50 maybe 100 accounts we need to go do something about that but we need to take more of a collaborative approach so when that crisis arises security teams need to be able to bring those individuals right hr legal network database devops secops everyone needs to come together to share all this common knowledge and this data and the artifacts right collecting those artifacts so we can take this comprehensive approach by leveraging these major security incidents and the way to simply do this is as i have my example up here for david's example from his house right making sure that we have not just the visibility but now the capabilities to promote this to a major security incident i can promote this and any other incidents that need to be linked to it i can do so so now we're taking a much more collaborative approach because now this is where the seem to be really supercharged and we're leveraging those components i can see based on this ransomware attack 22 assets are impacted by it 30 users are also impacted by this and we have nine different locations based on that cmdb correlation right that information we already have to now provide us with quick insights on what needs to be done and what teams need to be involved so immediately we can see our teams have been assigned our incident response teams there's the total count of how many are working on this ransomware attack network applications right our major security incident reviewer so in this case that could be an msi manager role we can see the linked security incidents what state they're currently in we can see those trends over time we can see the progression the tasks that are in progress or completed or assigned and so it's just nice to have this relevant information in front of you but wait it gets better i can actually now integrate threat insights and response capabilities through security and some response with microsoft teams and so we've developed a strategic partnership with microsoft to be able to now incorporate teams and sharepoint which offers a collaborative kind of file sharing capability where we can now see my sharepoint online folders and documents which can now be uploaded to those respective areas so if i'm on the legal team and there's a legal document that needs to be added and shared because this is a ransomware attack and there might be some litigation or discovery because of those affected users that i know about right maybe there's a ceo or a c-suite leader that requires special attention that happens right it happened to me all the time we used to have 15 extra laptops on the side just for the ceo in case ransomware breaches compromise anything happen just as again a precaution so this is a great way to start to facilitate that collaborative effort now from there we can also communicate much more efficiently because now we're using specific channels we can create these channels on the fly within this major security incident management console and now i can have the right teams communicating right and so we can see the system user check the state of our child security incidents we've gone ahead and added right margaret has added something into the executive folder and so we can start to go through and facilitate those conversations and have a better unders understanding to then justify next steps in terms of how we're going to handle the incident impact as well as how we're going to handle so we can see those are the ci's so david's house is reporting all of these cis we can see the incident records we can see who it's assigned to we can also toggle through all of our linked security incidents as well as all of the vulnerability items in question and last but not least we can also see the threat intelligence feeds we can see all the different observables so all of this rel information is relevant why because once we have now remediated and removed this exposure or this issue we can now generate a status report and this is honestly an area i would love to focus on very quickly these status reports are very new to the space and what's nice about these status reports is because we have all that rich contextual information i can actually now go ahead and create either a technical status reports right for my technical teams or an executive status reports and i can do this in real time it's going to now generate this preview and it's going to take all the information all the hard work right the sweat the tears everything it's going to take that and it's going to generate an executive report so that when we sit down and we have these post-mortem lessons learned conversations we actually have a report to go off of because it's captured all the artifacts the communication the impacts the affected ci's right who was involved my teams now i can start to promote within i can start to influence better conversations because we're using that better together journey with itom with security with the risk with irm right so everything's starting to come back into fruition and so it gives you a nice template and different visualizations that can be scoped out so this is a really incredible addition i think extremely valuable a lot of our clients and customers don't know about it just yet it's fairly new but it's a great way to now share collaborate and of course observe how well you're tracking performance across that enterprise visibility and security just doing a quick time check here i think we're on board we're going to move over now to the vulnerability side so we talked about security incident response playbooks the workflow that order of operations also being able to take this information putting into a miter attack framework being able to use the threat intelligence to better justify decisions moving forward because everything is data driven we're harnessing the power of the data so david's house is the data powerhouse i want to make sure that david's house is always protected at every angle inside outside upside down we need 360 degree global view now that we have the visibility let's go ahead and take that into how we report that performance how we report on the remediation efforts and we can do that through a series of these reports as shown here which again can be customized at any time now let's take it to the flip side right so we've responded to an incident record and that's something that's very common in this cyber security space let's expand that a little bit further now we've introduced new workspaces for it and vulnerability managers before i get into the workspace i wanted to quickly showcase another executive performance analytics dashboard now this is again your blueprint your battle plan this is how you can understand what is happening in my ecosystem that requires my immediate attention how can i help my technology innovation roadmap to provide solutions to consolidate existing systems so i can drive that efficiency the financial impact right understand all these applications and policies and procedures are they compliant can i reduce cost compliance well i need to understand what the threat landscape looks like from an exposure perspective so with vulnerability response we can achieve that and here we can see i have a simple report that i've generated for sisa's known vulnerabilities and this is just a report that's available from sisa.gov so i can actually pull in this report i can see all the vulnerabilities by name i could see them maybe by product and you can see that this information is being populated dynamically in real time we can also look at different age range or maybe internet facing so this is again giving you that capability to ensure that the business has the right technology infrastructure applications and services needed to meet those strategic goals how are we going to handle these known vulnerabilities where do i need to prioritize my teams to be most effective we can do this from vulnerabilities across different locations right so an example here of country so you might be handling different locations whether that's just here in the states or maybe it's from a global perspective we can handle that at scale from a global from a global lens how about understanding services that are impacted with the most vulnerabilities or better yet how many vulnerabilities are aging over a series of time we can see these different trends in analytics and start to improve that process and coverage by making sure we have implemented a better remediation effort which is actually going to tie in really nicely with that new workspace i mentioned before i move into the vulnerability manager workspace i did want to showcase another out of the box functionality here again this ties back to the discussion david mentioned right we know what we have in our environment in our house we see the appliances but if these appliances have vulnerabilities we need to know which ones we need to look at and if there are exploits available and solutions great let's prioritize that and automatically assign that to the right groups so we can go through patch orchestration and that deployment right our patch tuesdays our network maintenance windows over the weekend we need to make sure that we're prioritizing that because everything here that is being shown is time based and it's business critical to your assets your people your process your technologies so immediately i have a top 10 vulnerabilities with exploits available right these cvs being pulled in from the nvd library this is also providing more contextual information from those vulnerability items that have been discovered through your vulnerability scanners right so again we're bringing this all into fruition into one space how about the solutions the solutions right here on the right hand side how about what are my top 10 oldest vulnerable items right what's in the backlog maybe these can be deferred and closed out or automatically closed out if there are no available solutions at this time so there's lots of different ways you can use this as a baseline to improve overall security posture now of course improving is great some of the manual operations is great automating as much as we can is honestly the best use case scenario but it's not always achievable now there are ways to leverage some of the technologies we have here through security operations through itom and through the entire now platform we can train our solutions leveraging predictive intelligence one of the most popular use cases i hear from a lot of our customers and clients and they're running into a lot of frustration of where does this go to who is supposed to be responsible for this vulnerability well using the classification pillar here for predictive intelligence this is going to allow me to assign the right person building a confidence score so let's take a look at what that looks like really quickly so bringing it back to david's conversation right i need to know what the asset is the asset is here our ci now i need all the other contextual information coming from my vulnerability scanner but better yet i need to train my solution from that historical data and i would say by default 30 days of historical data is a lot of data and that's really the sweet spot so after those 30 days my classification pillar of predictive intelligence is now going to indicate that based on all of this information the risk rating the score and also the cve right the vulnerability the summary the severity all of the exploits based on that there's a confidence score of a 92 almost nine basically 93 telling me that the unix support team is the most fit and is that subject matter expert group that can handle this specific vulnerability so we're eliminating that guesswork right and that's honestly 50 percent of the frustration is finding out who does this need to go to so i can improve my security response as well as eliminate the exposures that have been targeted against my entire enterprise ecosystem so this is just another value add that we provide with the entire better together story in this journey i'm going to touch very lightly on some other components that we have so if there is interest here feel free to reach out we will also be reaching out after our demonstration for follow-ups and questions and demonstrations if you'd like to do more of a deep dive workshop but we also do provide application vulnerability response right that can tie into software access software access management or software application management we can also look at vulnerability management from a container perspective with prismacloud so if there's users on the call attendees who want more information on this we can absolutely tie into that as well again all this relevant information ties back to what that cmdb because that is our foundation and our source of truth we now become this system of action which leads me into the vulnerability manager workspace this is how we're going to go through that one vision of value for your team's performance to handle all of these vulnerabilities at scale i was on a call just before this and this customer had 10 000 vulnerabilities in tenable and they did not know how to handle them they did not know where to start and prioritize that level of remediation efforts and so i was able to show them these watch topics these watch topics allow you to condition specific vulnerabilities may be based on a cve or a risk score or business criticality but it allows you to fine-tune the specific areas of concern that you want to be presented with and then assign it to those prospective teams who are now going to take that and open up those change requests and go through the entire remediation process and so here's a couple of examples that we have as part of the vulnerability manager workspace for vulnerability response here we can see vulnerabilities on external facing assets and it gives us some visualizations over time what's our active vulnerability items what are deferred what vulnerable cis are distinct in my environment right we have 67 pcs or computers right we have some plc's here and we can also see distinct vulnerabilities as well now what's important here is i have this great information to understand there's something i need to do here and so what we can now do is we can open up what's called a remediation effort this remediation effort is going to just walk you through three simple steps to condition assign and then prioritize that entire patch registration process so i'm going to show you what that looks like here very quickly here i have some critical overdue vulnerabilities that require my immediate attention and i've opened up a remediation effort so as david had mentioned before right we can only protect what we can see i now see this information i now know that i'm there's impacted services or maybe affected configuration items that require my attention so in order to be effective i now need to go through and create a change request so we'll see here i have this remediation progress bar it's just the progress bar we love to hate just like when we're installing updates from ws or from our update tools through patch orchestration through sccm we can start to see the same components here through a gui perspective so now i can see all the vulnerability items i can see those cis because why we have our cmdb and again we're keeping this information as a one-to-one parity to make sure that we are prioritizing but also identifying the right assets to now go through change management so i can select these in bulk i can select them one by one depending on what i need to do here i'm going to go ahead and create that change request and you'll notice that by default it's going to automatically add those configuration items to my change request so that my change request teams my change advisory board write my cabs they'll know exactly what needs to be done what assets are impacted and if there is approvals required or additional steps or investigation required then they'll be able to do that because again all the steps have been laid out here programmatically now once i've opened that up it's going to of course generate that activity stream and it's going to post this to the activity so we can see this kind of cookie crumb trail right the audit trail of everything that's happened from the early stages of the analysis all the way to the final closure and recovery of this particular patch process and because we have that deep integration with sccm and bigfix it's a very seamless transition because now all that relevant information is in one place now changing the persona as the vulnerability analyst i need to have my own view and so we've created the remediation workspace so because i've assigned those vulnerabilities to robert smith and i'm playing that persona we can see here that i have two vulnerabilities that require my immediate attention and so by going into those remediation tasks it's going to take me to my workspace and it's going to show me the progression any patches that may be scheduled or ready to be scheduled but most importantly it's going to tell me what the preferred patch is if there is a patch request and then also if the patch was downloaded and when it was scheduled for again centralizing that right getting away from the silos and crossing wires and solution overload we can provide you with that contextual information so your teams can be faster and more efficient as part of that entire process all right and with that that will conclude my portion of the demonstration i'm now going to go ahead and share out one final slide here and then we will open up our pull questions so bear with me one moment all right so i'm now going to share out this last screen here all right and can we see my screen okay david yeah okay okay perfect so to bring everything back into perspective right securing that enterprise visibility right it's our responsibility to create a very smooth and functional infrastructure across those operational environments right that are going to support the deployments the eradication and of course the recovery of these different exposures incidents alerts and events that are happening across the entire ecosystem and so where we start to see this is we start to unify our teams across i.t operations and security operations because we're taking this what we call the approach meeting the products what happens is we're investing in so many point tool solutions half of them get used and maybe used to their full potential and the other half becomes shelf wear or they start collecting a lot of dust well at servicenow we'd like to take the dust off or better yet maybe we can start to consolidate your systems and we can start to orchestrate and gain that enterprise visibility by itom right using the discovery components the visibility the service mapping and noticing everything on those dependency views those blueprints that david had mentioned then being able to prioritize those based on risk business impact criticality and being able to automatically assign that through a series of flows through artificial intelligence and even machine learning training the solution to work for your teams so that what we can provide better action efficiently across that entire enterprise and we can see here at the bottom that cmdb that's what's holding this all together that cndb is helping us connect security to the entire enterprise and any other third party systems that we want to tie into we can easily do that because now we have a cm a rich cmdb that is constantly evolving and maturing as well as ingesting new information that's going to be applicable to when we go through our proactive enterprise attack management perspective and of course we'll always have some reactive components so there'll need to be case management and so security operations is more than just case management we also have soar components or capabilities and so you're really bringing in all of the systems into enterprise visibility but also into security and how we connect that throughout the now platform and with that that is going to conclude today's session i wanted to quickly thank everyone so much on behalf of servicenow thank you for attending today's very impactful session before we conclude you should see a series of questions that will be presented to you on your screen to gather that feedback and i want to thank everyone again and as well as my presenters thank you so much yeah thanks chris thanks everybody that participated today and thanks everybody for joining we really do appreciate your time um we will be sending the recording out to everybody that had attended and who had registered um today so thanks again and uh feel free to answer the questions like chris had said but we do appreciate it thank you all right i think we're good with the pull

View original source

https://www.youtube.com/watch?v=CObRXu-aGx4