logo

NJP

Defense Against the Dark Arts of Security

Import · Aug 25, 2022 · video

okay so hello everyone welcome to our webinar today for major security incident management a virtual battery room for defense against the dark arts of security uh today i'm joined with my colleague mika who is going to be covering how to take things more actively and learn how we can utilize software asset management to hopefully uh remediate against the vulnerabilities and security incidents before they actually occur now before we actually get started just some housekeeping items i'm going to start with the safe harbor notice for forward-looking statement now this presentation may contain forward-looking statements that are based on our beliefs and assumption and on information currently available to us only as of the date of this presentation now your surrey today is my me my name is mohammed nasir and i'm a senior solution consultant specialized in security operations i work for the workflow of magic company servicenow and i am a self-proclaimed slytherin resident and my colleague today is mika i'm gonna let her introduce herself hi everyone so my name is mika anderson i'm also a solution consultant here at the magic house or magic school of uh servicenow um and i specialize on the i.t asset management side and my house is ravenclaw perfect thank you so much mika now the agenda for today's webinar is going to be as follows we're going to start with major security incident management just a quick overview why it's important why we should be looking at it uh then we're going to jump and see how to be proactive with software asset management so the idea behind the best better together story between software asset management and security operations is how we can actually utilize software asset management to fund the assets application devices services etc that could be vulnerable to major vulnerabilities or security incident or security incidents before they actually get promoted to a major security incident now after that we're going to come back to a final tour where we basically are going to look on how we can elevate security incident from regular security incident to major security incidents um after that we're going to see how we can manage these major security incidents from an overview perspective to the tasks that are going to be assigned to the different different employees or teams that are assigned to that security incident how we can collaborate between teams whether they were in security i t hr legal etc on these major security incidents and finally status tracking and reporting now sit tight and park your rooms this is going to be a very interesting one now i'm actually going to disable my camera before i jump into the rest of my presentation here just to help my internet not crash okay so what makes an incident a major security incident rather than just a standard security incident um here we have this simple graph that basically helps us explain uh what is a standard security incident versus a major security incident now the main user persona that we often see utilizing um standard security incidents are stock analysts or whoever is working on sock to actually help remediate the security incident along with security admins in some cases where we need their approval or if they um thresh they pass a specific threshold where an admin should be there to basically monitor uh the response associated with that security incident now when it comes to major security incident the main user persona is going to be the major incident manager and that's someone we just call when there is a very specific heart task that they need to be focusing on uh the quantity of standard security incident that obviously depends on the organization and their size but it can vary to an average of 100 incidents per month when it comes to major security incidents we're looking more toward one to two to maybe three four at the max major security incident per month uh sure we hope we do not exceed that um the duration a standard security incident usually spends on the environment of the um affected company or organization as a matter of hours it can be stretched out two days uh one major security incident unfortunately because they have been embedded into the environment usually take a bunch of weeks months i've even seen use cases where it's been stretched out to years now the automation flows uh technical response oriented when it comes to standard security incident while in major security incidents it's going to be communication and collaboration focused so we actually rely on the collaboration between all of the different teams uh when we are helped remediating that uh security incident the artifact handling a handle attached to incident record when it comes to standard security incident while a major security incident that's going to be a hundred possibly thousand integration uh file share repository these could be logs this could be other trails uh this could be emails a bunch of different things our communication method when it comes to the standard security incident is going to be task driven so whoever has a task is going to feel the need to communicate with whoever is actually performing that task while in major security incidents we're going to have emails text web conferences initiated and tracked by the incident itself the collaboration uh in sanders security incident we often see uh outside of the incident itself manually copied to incident when required so we can have collaboration uh and standard security incident we tend to usually utilize the workflows that we have to automate the response for the standard security but sometimes we do have to do things manually while in major security incidents the collaboration is more going to be chat oriented so we created the chart function and the file share activity tracked within the incident for authored and status purpose uh finally reporting focused um inside of the security incident we just want to look at the overview of all of the incidents that we've worked on what they have what kind of risk they presented to our organization versus how we've handled it uh while a major security incident we actually want to look at all of the information about that incident uh how it had affected what is the risk that that specific incident opposed to our organization and et cetera so let's look at some of the facts about a major security incident and specifically ransomware now the white house have actually been quoted in june 2021 that ransomware are a threat to the core operations um it also in 2021 the average bill for a ransomware attack with downtime people time device codes network codes loss of opportunity etc was around 4.62 million uh and that does not include the ransomware paid for these ransomwares uh we've also seen 150 billion in 2021 cyber security and risk spending um number one in 2021 priority for the cios was ransomware uh we've seen 40 to 60 improvement in response speed with security operations and servants now uh 80 of the observed attacks use vulnerabilities reported and registered for more than 90 days uh and this is where we're gonna actually be utilizing sam because we know that the vulnerability exists but we haven't taken the appropriate action to remediate against that specific vulnerability and finally 2.3 million us dollars are the additional breach costs for those environment with high level of compliance failure versus low-level compliance okay so what exactly is major security incident management and what did servicenow do to actually help build the single pane of glass so major security incident is going to be your single pane of glass where you can basically see all of the different affected assets who are the affected users what are the affected location when it comes to that security incident who are the teams that should be working on it what kind of collaboration do we want all of the details around it is going to be in that specific single pane of glass so rather than working on a bunch of different security incidents which later on i'm actually going to be jumping onto the service now instance to demonstrate what that looks like uh you're only going to have the single view that houses all of these security incidents together so what does that exactly mean and what does that entail number one we have the dedicated workspace for the major security incident manager to coordinate incident response whether that was with the different teams with different management personas etc we have the collaboration workflows by microsoft teams and evidence management with microsoft sharepoint integration so we actually embedded the ability to uh start specific teams channels and start um different sharepoint folders to share the document and artifacts around the security incident within that single pane of class we also offer task management for security i.t and non-ita roles and the summary metrics to quickly see the status of that incident so sometimes we have to involve hr sometimes we have to involve um legal sometimes we even have to involve third parties who aren't working with the environment so we want to make sure that we have a place to manage all of the tasks assigned to all of the different individuals who are going to be working on that security incident and major security incident definitely makes that much easier for us uh number four we have the executive and technical status reporting summary and progress for incidents and team working on it so we want to be able to actually generate a report that we can present to management or present to whoever is concerned about that security incident so we added the ability to build that report right from the single pane of glass and you can later on export that report into a pdf format and email it or keep it for your safe reviews now if you are familiar with um servicenow i'm sure you are also familiar with the cmdb and how important cmdbs can be uh when it comes to all of the different offerings that servicenow has now in this deck here we can see what exactly it offers to different offerings whether that was itom itsm itam itbm but our focus today is going to be security uh so we can see that the value of a cmdb or a mature cmdb is going to be critical uh what exactly are the benefits of maturity in db when it comes to security operations now number one and this is the most obvious one is going to be the prioritization uh on that is based on the business criticality so we can actually utilize that cmdb to see how critical the asset that has been affected and how important is it for us to remediate it in time versus what are the dependent assets on it or the dependent services etc uh also utilizing the cmdb we get faster incident isolation and response and that is because we know where the security incident is in fact whether that was its location or if it's within an asset what application that vulnerability or security incident is on so that eventually leads to a faster incident isolation response uh finally we had we have end-to-end risk visibility so understanding where is the asset or the application or the service is we understand what risk it presents to us and how we can actually immediate against it now what are the key metrics when it comes to the cmdb and security operations is the reduction in time to remediation of p1 vulnerabilities i'm also going to be covering that in fact in the um instance once we jump into the live demonstration and before i actually jump into major security incidents which is going to be our main topic for today i kind of wanted to cover how we can take things proactively so before i jump into my part i'm going to pass it down to mika where she's going to walk us through software asset management and how we can utilize it uh into thinking um matches practically thanks mesa all right so taking a look into software asset management and how it ties into your security place in terms of software asset management on the platform really what it is is the end-to-end management of all of your different software installations to be able to answer the questions of what software do you own are you buying what you need and are you using what you have so in terms of being able to identify what users have you know specific applications that are unique to marketing or finance in order to determine if there's any um you know unnecessary spend or even in in today's conversation talking about risk it's going to be really important to determine um and gain visibility on any software that might be at risk of these vulnerabilities right so when we take a look into how sam plays in with um psychophysics if you want to move into the next slide so one of the ways that we can see sam work better together with security on the platform is really through identifying where the most recent vulnerabilities exist through outdated software models and so as discovery is running and pulling what's installed on your employees devices on your customers devices this is how we can determine where we might need to take action and be proactive in order to say hey certain pieces of software have been on devices and it's not really being utilized or this type of software is the real you know a really old version of that particular model so let's harvest that back so that we can determine and keep our employees as safe as possible all right so last thing i want to highlight here so from the point of software asset management really the intention is to be able to not only reduce on cost savings and you know increase efficiency in your software processes and provisioning but also to reduce risk and really the highlight here is to look at software exposure what kind of software do you have on your devices do you really know the end to end of all of the different software on your employees devices as well as restricted software being able to determine and harvest back any licenses that may not need to be utilized maybe they have um you know a harry potter game that's installed on their their laptop and we want to ensure that um we're we want to make sure that we're in tune with all of the different software that's on their devices so being able to track on harvested licenses as well as the lifecycle management is going to be really important and so from this point we can talk about software exposure assessments and so at this point we can check for vulnerabilities ahead of time and be proactive and so we can identify these see what devices are impacted and then automatically create security incidents or be able to track those vulnerabilities within the system before any major attacks come up all right so nasa i'm going to go in to share my screen really quick just to show how we can be proactive and set up um security incidents with software asset management please and then let's actually take a pause here for any questions in the chat i'm monitoring the questions as they come i'm gonna um answer any that are related to security and if any are related to itam i'm just gonna defer them to you once you're done sounds good all right so when we take a look into software asset management on the platform uh can you see the software asset overview laser yes okay so when we take a look into um software asset management we're gonna see a quick view a high-level view single pane on this particular type of data so when we look at software we can look into any old models and from this life cycle report we can take a look into the life cycle of all of our different software models that are being discovered filter by risk and so at this point we can group by risk and take a look here into any of these software that have been calculated at a higher risk and are at the end of support and so in this case we can indicate that there are people who still have this software installed on their devices maybe it's time for them to upgrade or maybe we need to harvest that back and reach out to those four individuals that have that particular model and so we can ensure that we are maintaining compliance and keeping our utmost security the other way that we can look into this as well is through license usage and so using microsoft as an example we can take a look into what is compliant and what is not compliant take a look into vizio and let's say with our older model our 2013 any unlicensed installs so without going through that software provisioning process we can see that there are 10 users or devices who that device is assigned to and potentially harvest back any of those older licenses that either might be at end of support or are an outdated model that most people within the organization don't utilize and then the last thing i really want to talk about here is the reporting capabilities and so being able to be proactive on your different software installations so we can check for publishers and products out of compliance but in terms of the risk of security incidents we can check for any um content that hasn't been downloaded into our software repository so that we have the most up-to-date data within our asset repository and then identifying removal candidates so this is going to be indicative of the different justification models so in this case we can either see low usage but for the sake of security we'll see here any restricted software or any unlicensed software so users that may not have gone through that policy or have gotten that first level of approval from their manager to get that software on their device and so this is going to set us up for the next piece of the conversation when it comes to identifying any vulnerabilities on those software all right and so nasa if you want to go back into the presentation all right so when we talk about software asset management and being able to take a look into some of those candidates those software models that are at risk of exposure we can also see here how it operations management pulls into this as we utilize the best practices when implementing discovery tools so really the foundation is being able to get visibility into the type of data that is in your different devices and that comes with that particular discovery source so the best practice here is to ensure that you are setting up your discovery tools and that we can get full visibility into all of the data and assess that software all right any questions on the software asset management piece nasa do we want to pull up the poll um i know there was a question that we had absolutely so we actually have one poll ongoing right now um if you can all see it oh okay here we go okay i just launched the poll and let's give it a couple of seconds to see what everyone responds is and please remember there are no wrong answers here yeah mika honestly one of the things that i used to struggle with a lot when i used to be in the sock was the amount of times we would get security incidents because someone had installed an application that they didn't know um that they had to get approval for or application that was uh commonly known in the security world but to have a back door um into the environment so i'm glad to see that servicenow takes these things actively and can actually monitor and see whether the applications on the user's computers are approved or not yeah and it's all about being proactive as well so being able to not only get that data on that software and get the visibility but taking remediation actions right like not just you know i found software that is at risk or at exposure but being able to immediately take that off absolutely without having to use another tool absolutely i can't even imagine how much time that would have saved me okay so looks like we already have the results for the poll i'm actually very happy to see that 40 percent of the attendees use servicenow cycles versus just 30 percent using itam so that makes me very happy um well hopefully by the end of this webinar we can convince you to utilize both of them that's awesome seeing how many people are utilizing itam as well and seeing what um knowledge across the different areas of the platform absolutely yes hoping all of uh the itam users are team or house ravenclaw [Laughter] okay and this is another uh poll i'm actually gonna keep this one running while i cover the rest of the presentation today just for the sake of time um and if you want please help us gather some data on how many individuals have a mature same degree okay now jumping back into major security management and what exactly that means and what exactly it offers the organizations so um i'm not gonna take a lot of time covering that on the presentation part because i want to make sure that we have enough time to jump into the instance and see these things live uh but major security incident management will quickly determine the state of a major security incident from one location uh so as you can see on the screen here we have this timeline that basically gives us a quick overview of how the incident is progressing uh whether that was by the task or uh how many tasks are currently in which state because a major security incident could mean that there are a bunch of different many security incidents associated under that big umbrella of major uh so we can see how many of those uh security incidents are in recovery versus contain analysis etc uh we can even see how many tasks are assigned overdue or in progress uh we can see that the active teams that are linked to that incident by state collaboration and more directly from the overview screen so we can see which teams are assigned to what state or what task and how much percentage complete they have done uh we can also monitor the data trending over time to ensure incidents are resolved quickly and efficiency we don't want to promote regular security incidents to major security incidents and just forget about them we want to make sure that we actually um are um remediating the security incident and hopefully um eliminating that risk and the results for the second poll are in it also looks like most of the attendees today are utilizing servicenow cmdb which is very uh great and i'm very happy to see that now the other thing that we can get from major security incident management view is the details about the incident and all of the child incidents that are there under it so we can see the details about the major security incident all of the active team members and more to give the incident commander a fair understanding of who is involved we can also see the uh or browse into each child security incident and vulnerable item to understand more about it or if there is a specific task that is associated with one of those child incidents we can actually help remediate that from the major security incident view we can also create private work notes and see all activity related to the major security incident ladies are you sharing the major security incident management screen yes um if the slide is if you want to reshare really quick i think it froze on the last slide yeah perfect perfect apologies um so back to what i was saying basically we can see the details of the major security incidents all of the active team members etc we can browse into each child's security incident and runnable item and we can create private work notes and see all of the activity related to major security incidents as well i'm not sure how many slides i was posing on but don't worry everything that i'm covering right now will be covered again in the instance once we actually jump into that demo portion uh going back into collaboration with team members is easier than ever now when we are working with major security incidents the key factor to success here is going to be the collaboration between the teams uh some of the tasks are going to be handled from the security team some of the tasks are going to be handled from the it teams sometimes we actually do need to involve uh hr um in a case where we maybe need to disable someone's access um and have the legal liability taken off our take the liability burden off our shoulder so we also want to involve the legal team as well so the configuration into the management major security incident management dashboard allows us to automatically create sharepoint folders and teams chat channels to uh maybe transfer some of the data in a secure manner or start a chat between the individuals who are actually going to be involved into handling the task into remediating them or handling the security incident itself now the incident commander can also view all of the collaboration activities so rather than just creating these random chats and all of these folders we actually have the option of monitoring what goes into these chats and what are the data that have been uploaded to these different sharepoints so as the major incident commander i'm able to see all of that from an overview perspective now one of my favorite things about um major security incident is the ability to track all of the different tasks from this visual task board where we basically can see all of the different tasks who it's assigned to which one are in progress which one are in a draft state which one have been completed what is the percentage completed on some of these tasks so this view kind of gives you the ability to basically see what that means and um how you can maybe get in touch with someone who have been taking their free time on one of these tasks and how to basically make sure that they are actually taking care of it i'm not sure if something is going wrong with my screen here but i keep seeing that someone keep raising their hands i'm not sure if that's a question or if there's a technical difficulty can everyone see me and hear me okay yes perfect okay now lastly we want to be able to be uh to provide up-to-date uh minutes reporting to the stakeholders who are involved with these different security incidents so we have the ability to actually create these reports from the major security incident view and be able to export it into a pdf excel any format that we like we can later on share it in an email or if there is a specific maybe meeting where we are discussing that major security incident it's very helpful to have all of the major information overview information and one single document to be shared across all of the stakeholders attending that meeting now hopefully you are not lost on all of the facts and awesomeness of major security incidents but to make sure that we give the ability to see everything in real time i'm gonna go ahead and switch to my instance to demonstrate uh what major security incident looks like can everyone see my screen can you confirm yes perfect okay so now before i actually jump into major security incident i kind of wanted to walk you through um this organization who is not utilizing major security incident and what um their overview looks like so over here i have the cso dashboard which is one of the dashboards that come out of the box and security operation to basically show you all of the information or the overview of the security poster of the organization so this organization is not utilizing major security incidents and we can see that reflected in the total number of priority ones versus priority two incidents uh they have over five hundred by two one and one hundred and fifty seven priority two incidents that they are working on actively uh which is definitely not a good thing because if we have more than 600 security incidents that are considered major or priority 102 uh that means that we are not doing our job right and that means that there is something definitely going on wrong that we need to be fixing now jumping into this other organization that is pretty awesome and is utilizing major security incidents we can see how the total number of priority one and practical incident has significantly decreased now we are only working on one priority one incident and zero priority two incidents so that means that maybe all of those ones that that other company uh had were housed under or put under the single umbrella of one single major security incident and we are collectively working or assigning tasks to remediate that specific security incident okay now in this view uh this is where we basically can see all of the different uh open security incidents that are assigned to uh this organization so in this video i'm basically looking at all of the open incidents specifically uh we have a bunch of different quick filters that can be utilized for whichever reason that the company uh chooses in my case uh i've built one for phishing i've been trying to build one for critical incidents i've built one also for open critical incidents now if we see from the big view here we can notice how this specific security incident has been tagged as major security incident along with this other one along with this other one so why exactly did we feel the need to promote the security incident and make it a major one let's open the incident record to see why now the first thing that we're going to notice is this is a pretty straightforward phishing attempt it looks like sharon received an email she suspected that it was a phishing attempt so she basically clicked on report slash in her outlook um client and that basically created a new record and service now that flags that email as a phishing attempt now scrolling down we can see the work notes that have been going around with all of the teams involved but what really sparks my interest here is that i'm seeing that we have around 31 other security incidents that match the specific ones so it looks like there is basically a major kind of attack that is going on that is creating all of these different phishing attempts so me as just a regular sock user i thought that this should be promoted to major security incidents so i sent it to my system admin or the security admin in this case and asked them if we can promote this into a security incident or a major security incident which lastly leads me or takes me to the major security incident management workspace so in an incident working um incident sorry in major security incident management workspace um we can see that we have basically a list of all of the different securities that have been submitted all of the ones that have been proposed rejected approved uh what that exactly means is that for example i have this one that has been sent to me it looks like this one has already been taken care of which is the msi incident while the one that we are currently working with is the demo ransomware attack in the headquarter uh it looks like we have a priority that is critical it looks like the incident manager and this specific case is aiming it looks like the k the primary state for all of the different tasks are incontained and it looks like the person that had promoted it or approved that promotion is the system administrator uh now if we had more security incidents this is where we basically are going to be seeing them we don't have any that are currently proposed or we don't have any that are currently rejected so that is a good thing so let's jump ahead into the one that we've accepted and we actually do in fact know that it is a major security incident now clicking on it we're basically are going to be presented with the overview about the specific security incidents so leading me to how many affected assets do we currently have involved in the security incident how many affected users do we currently have that are affected with the security incidents along with how many locations do we also have um associated with the security incident uh if i wanted the latest information as the major security incident manager or commander i don't even need to get in touch with with a specific team or a specific individual to give me the latest information i can rely on servicenow because it always has the latest data and i can just refresh the data from here i can see the duration counter so the time since this incident has been started it looks like it's 222-6 days five hours and 27 minutes um what is the estimated resolution date is going to be 176 days from now now keep in mind this is just demo data so we try to keep the time as big as possible uh we can see how many active teams are working on remediating the security incident so it looks like we have two from network we have one from application security and we have one from msi reviewers now what are the link security incidents and what states are they in so it looks like we have seven security incidents that are an analysis state that are associated with this major security incident we have one that is incontained and one that has been recovered are there any trends that we should be very off with the incidents that we have associated with this major security incident yes uh looks like we have a bunch that are or one that doesn't recover and most of them are in an unnatural state uh we can see even the response tasks and how they have been um what state they are in and how they have been distributed so how many currently are assigned how many are closed completed how many are in the work in progress et cetera we can see the in-progress tasks by incident and state we can see how many that are already due how many that are assigned how many are currently in progress if there are any external collaboration what is the data available on that it looks like we don't have any in this case so that's why we are not getting any data here now if i want to jump into the details of the security incident i can jump into the details and just give it a second to load so um it looks like the number for the major security incident is um msi which means that it is going to be on the major security incident table uh we can see when it was detected when is the estimated resolution date the subcategory it falls under uh scan by email activities peer phishing large campaign the category is phishing and that is because most of the incidents that have been promoted into major securities and in this case were tagged as fishing and this was um it's coming because of the uh source that we've interested that diamond in title demo ransomware attack in headquarter the priority is critical and this is where we are seeing the uh powerfulness of the cngb firsthand so the criticality in this case or the priority in this case have been automatically assigned as critical just because of the number of individuals that are affected with the security incidents and the number of teams that are affected with the security incidents i can also see all of the different communications here that are associated with the specific security incident or major security incident and if there is a need for it i can even type any work notes and these are going to be private so only the individuals who have an eye to role who also have the access track to major security incidents are going to be able to see this versus just comments for when these are going to be available to all of the individuals who have access right to major security incidents uh we can see the active teams that are also working on the security incidents here now this is where it gets beautiful and this is where we actually can see the different tasks that have been uh distributed to the different teams who are going to be working on the security incidents so we can see a bunch that are in draft state the bunch are in science some are in progress some have already been completed um we can see in this one identify them a lower id so it's already been assigned to a specific uh team uh we can see how these tasks also have their own priority so this one is critical check the exchange server is not responding uh versus one that acknowledged for user submission and ask if they have interacted with the email i'm sure you've noticed that my screen was loading this was not um an error thing or anything like that it's just a matter of the fact that we are constantly checking to see if any of these tasks have been updated or if there are any changes associated with the major securities in general now in the collaboration tab as the commander of the security or the major security incident i'm able to actually see all of the files that have been created in sharepoint around that specific major security incidents so we have a bunch of legal docs a bunch of logs a bunch of system image i have the option of opening the sharepoint and new tab or i can move it into maybe all of these folders into one single folder if i just do so now i can also see all of the different teams that i have created here so all of these are going to actually create a team channel chat on microsoft teams to allow the technical experts the executive expert the legal experts and just general information um to communicate around this major security incident specific and they also have the option of monitoring that communication right from here uh these are all of the activity all all of the different things that were tasks that have been completed all the different changes regarding this major security incidents are reported here in real time now the status report this is where basically you can create different reports that are going to be kinda tailored toward different audiences so in this case i have already the technical save this report created if we can take a look at that let's just give it a couple of seconds for it to load and this obviously um just a quick question um earlier you um during the demo we have a question on can you give an example of a partial compliant case i'm sorry what exactly are they referring to compliance and sorry a partial compliant case i'm not sure exactly i'm following are they referring to security operations are they referring to sam um let's i'll follow up but in terms of the workspace uh we can configure it in any way there's a ui builder so for any of the workspaces built on the platform um like the software asset workspace and this one as well the security incident management the um reports and all of that can be configurable just a couple of questions in that chat came up gotcha yeah we'll definitely gonna follow up on the partial compliance case but um i'm gonna assume that they are referring to sound use case and impression compliance this could be maybe an application that needs a specific approval i mean it's not against policy to have you download it but maybe it just needs a specific approval for you to download it so this could be a partial compliance case um in the secops portion the only compliance piece that we cover in security operations is going to be configuration compliance uh which is part of variability response which basically allows you to see if the different applications services devices um have been deployed in your organization again the specific authority documents that you need to be in compliance with and what is the compliance state of that specific application assets etc right on the software asset management side in terms of partial compliance so uh in service now we break it down by each software model so depending on let's say windows right if you have project 2013 and 2019 2019 can be compliant but your software model for 2013 could be out of compliance so um if that kind of defines partial compliance i would say it's but it's broken down by version of software model there is also another question that i'm going to address really quickly which is can the task section be automatically created based on the type of incident selected this is actually a great question so you can build a bunch of different workflows that basically are going to automatically create some of the tasks based on the incident categorization or based on its priority um but you also have the option of creating them manually or in hybrid manner so maybe the case and this task i know for a fact this one has been uh automatically uh created is the acknowledges user submission and ask if they have interacted with the email this is because all of the different security incidents here are associated with the playbook of phishing and the first part of that would be to acknowledge their submissions so this task has been in fact been created automatically okay i'm going to address the rest of the questions at the end of my demonstration today i just want to make sure that we have the time to finish the demo okay so over here we have the status report for the technical uh information about this major security incident this has been created automatically uh we can see that progress is automatically created for us what is the scope within the security incidents what are the challenges uh that we've seen um overdue um what are the next steps that we're taking how what are the activities that had happened the different tasks which ones have been uh completed which one are currently in progress et cetera so all of the information that you can see from this view have been translated into a document format that you can actually utilize for other trails or you can utilize it to send it as a communication um document to the rest of the stakeholders within your organization so this is definitely a very powerful thing and i've seen this used so many different times especially when i used to be um as a stock manager i had to actually create these reports from scratch so seeing that the tool is able to create this for me um with just a click for button is definitely a great addition uh and would have definitely made my life easier now over here we have the incident impact and this is where we basically are going to look at the different configuration item associated with the security incident and understand um what is the impact that it could have to us so in this case we can see that all of these different um configuration items can be um damaged or they can maybe go offline if we don't touch the security incident in time or this printability in times so the ability to see these assets firsthand is definitely a very powerful thing and you can even see how this stretches uh on for different pages and this is again another thing where we can see the powerfulness of having a mature cng entire place because all of this information has been automatically uh imported from this game uh over here we can see all of the linked security incidents and vulnerable items associated with the major security incidents so in this case it looks like i only have nine different security incidents that have been um under the umbrella of this major security incident so if there are maybe a vulnerability associated with it or something of that sort that would also be um reflected here uh finally uh threat intelligence information this heavily depends on having uh appropriate integrations on the platform uh but threat intelligence information can actually help us understand more about the security incidents that we're working with uh one of the powerful things that we can do is maybe an integration with virustotal or crowdstrike where we're able to automatically scan the email for attachment and see if the hash files associated with this attachment is in fact malicious or not uh maybe the ip addresses maybe even the domain associated the sender email if they are malicious or not so rather than use bubble sharing between servicenow and the other tool we import all of that information through the integration and api to be able to just give you that information as soon as you access the record for major security incident and this basically sums up the demo part for major security incidents if you have any questions uh or any areas that you need further clarification on please don't hesitate to reach out uh once we are done with this webinar we're gonna send out a follow-up email you can reply directly to that email with your questions and we'll definitely make sure to address them we can also go back to um the poll we you can discuss the answers from the last question sure so the last question that we've asked was whether they currently are utilizing uh the cmdb and whether um stop closing my screen for a second so basically we asked the to see if they are currently uh have a mature cmdb and whether they are utilizing servicenow for it or not and the results are very pleasant because 51 percent of today's attendees are actually utilizing servicenow for the cmdb um the rest 32 percent are utilizing the third party tool there's nothing wrong with that as long as they have a mature scene to be the security team is definitely going to be happy with that uh finally we have 17 percent that are no um which this could be um on my end a mistake because i did not um verb the uh specific question um accurately maybe they do have a thing to be just not mature or something of that sort but those 17 percent can definitely um utilize the cmdb and more than happy to also reach out and we can discuss how we can help them uh deploy cmdb utilizing service now and how we can use servicenow discovery and servicenow mapping into helping build that maturity sounds good i did have a quick question kind of as a follow-up for one of the questions in the chat for the major security incident um workspace what sku would be needed in order to have full functionality of security incident response that is a great question now normally these kind of questions we kind of like to refer them or defer them to the implementation team just because this can definitely change significantly based on how big or small the organization is based on what they are exactly looking to get out of major security incident or regular security incident uh but for starter um one thing that i always advocate for is that the organization needs to understand their process before they are actually able to automate it or improve on it so understanding what their process is and what they want out of it is definitely going to help them be more successful to launch major security incident or security incidents in the future yeah and i think even with regardless of whether it's security or software asset management or anything else on the platform having visibility into the data and then having a good understanding of the right people and the processes is going to ensure proper success in an implementation absolutely yes and this is also a conversation we're more than happy to take offline after today's webinar please reach out to us and we'll definitely help coordinate this conversation whether that was with servicenow or we can help you find the appropriate partner to have more further conversation with regarding that specific manner

View original source

https://www.youtube.com/watch?v=pLBEhsK2eGE