logo

NJP

SecBytes (S3E1): Data Loss Prevention - Incident Response Deep Dive

Import · Aug 31, 2022 · video

thank you claudius now that we have a general synopsis of data loss prevention incident response let's demonstrate servicenow's security strategy to detect prevent and remediate the loss or misuse of data via dlp ir in this demonstration we'll be playing the persona of a data loss prevention analyst reviewing the operations portal as shown here to quickly decipher metric indicators through dynamic dashboards we're also going to uncover dlp administration that can be tailored to match those use case requirements and lastly we'll switch to the end user persona gaining insights into the end user experience and response actions that can be taken out of the box so let's go ahead and get started here we're focusing on the ops portal in this workspace we can monitor dlp incidents through a series of dynamic widgets and heads-up display indicators this gives us the ability to assign or escalate incidents to other personas as well as being able to review identify and prioritize across open overdue critical incidents and incidents assigned to end users based on levels of severity top offenders policies and scan sources so as we can see here we have our heads up display of quick filters i have a total count of open incidents when i click into my overdue critical incidents notice that it dynamically changes all of these widgets indicating the specific data set and the value as well as the formula that is going to calculate the specific metric indicators and when clicking into the incidents assigned to end users again producing and appending those same results based on incidents that are assigned to end users here's the total counts across my entire organization now when we think about critical incidents we think about severity and it's important to understand the level of severity because now we can start to prioritize and assign out those particular personas programmatically versus doing it from a manual perspective hands on keyboards is typically the way that we usually escalate or assign out our assignments but now we can do this programmatically through automation so in here we can see our top offenders based on those open incidents but when we scroll down just a little bit deeper here we can see open incidents by policies and so from a governance risk and compliance perspective we can start to assess the risk based on incident records and the total counts against these policy violations and more so we can also see the open incidents by specific scanning sources now we have native capabilities where we can aggregate information from the supported tools that we do currently have defined and built out of the box and this will allow us to again aggregate that data generate the incident record in question and then of course appropriate and facilitate those order of operations as part of the chain of custody of handling a dlp incident across the entire end user life cycle one other area and key mention to note is also the ability to look at all of those trends from a analytical perspective across a series of time so these time series based metric indicators allow me as the analyst to also see new incidents training on an average day-to-day also being able to see the differences between new versus closed incidents again on a running daily average in addition being able to see the average lifetime of incidents false positives aging versus severity and most importantly how many escalated incidents are in my environment based on that day-to-day average here this would be a quick indicator or an indication that there have been more escalations on august 30th than my previous subset days and so this might be an area of concern for me as an analyst or a manager to further investigate and research why we had so many escalations brought to the attention of our dlp ops group and our teams and of course you have the capabilities to further indicate additional information and create a threshold window of those timed point in time snapshots by specifying a start and end time to facilitate those specific data sets now that we've gone through the overview of the ops portal and further digesting and excavating some additional metric indicators let's take a look at what a data loss prevention record looks like so here i've pulled up a use case example here we have a data loss prevention record and this file is indicating that there has been a policy violation found from our semantic data loss prevention tool called payment receipt now this is definitely a red flag already because of these two keywords payment and receipt so there might be some sensitive or proprietary information such as bank statements account numbers or even social security numbers or pii from the specific users from the company that we don't want to have leaked exposed or misused in any capacity so playing the analyst i can see all this relevant information not only do i have the ability to see the file location but i can also see when this file was created last accessed and more importantly the metadata behind the file permission sets i have my user and group names as well as the level of permissions that each of these users or group names has access to this will allow me to drive my decision and justification on if i need to further escalate this to a higher tier assign this incident to another persona within my data loss prevention space or simply update the state to in review or pending further investigation for the purposes of the demo i'm going to go ahead and just create the escalation and we're going to assign this incident to my data loss prevention analyst persona chuck norris so i'm going to select the analyst you'll notice you can also assign this incident to the end user or even to someone else who might need some additional context on the use case so i'm going to select the analyst and i'm going to do just a quick query for chuck norris and for the incident pre-user response we're going to say that this is currently open and we also require some additional information why because we need to know if there is confidential data or sensitive information that could potentially be exposed in this file share and so we need to do our due diligence as a dlp analyst to make sure that we have fully assessed the level of criticality as well as the confidentiality and integrity and availability of this data so we'll select our dlp incident assessment and for our post user response we'll have this in a review state now as soon as i do this this is going to send an email to the impacted user as well as an email to the assignee in question in this case to chuck norris so we're going to assign this and you'll see this is done programmatically now i'll venture over to my email and i can see here chuck norris has received an email for this data loss prevention record there is a link to the record in question and of course just a general statement to reach out to the team if there are any additional questions now that we've demonstrated the detection and prevention of data loss incident response via the ops portal workspace as well as being able to prevent and escalate issues by doing a deep dive around our incident records let's take a look at the end user workspace here we can see the end user workspace persona that i'm playing i have my data loss prevention record indicating that it has been assigned to me and i can also see the file location as well as the current state in addition i see that i have a pending assessment that requires my attention so let's go ahead and dive into the dlp record as the end user now as you can see james johnson is the one who has flagged this violation and we have indicated this to adam gray their manager to facilitate the additional assessment we can see here the assessment is ready to be taken when accessing that we can see that it is formally greeting james based on a variable which can be configured in the assessment designer as well as further action indicating the specific file name that has been flagged by the policy violation now all this information can be captured in the actual assessment when building out your assessment rules but most importantly down below is our actual dlp assessment form here we can actually indicate specific questions that are prompted to gather some more details and context before we can further justify the next steps that would be appropriate to finally close and rectify and remediate this issue for the end user in question now this last section allows us to actually now go ahead and respond to the particular assessment indicating that we have completed this assignment and we can now move on to the next series of steps to now further escalate or in this case maybe even report it as a false positive or report it as a wrong owner these options again are relevant and available to you out of the box as part of data loss prevention incident response now that we've gone through the initial incident assessment and we've looked at what the end user experience will be now let's go ahead and take this into submitting the formal response or reporting an additional incident you'll notice when i click on the incident in question i have two options that are prompted to me i can report this incident with a specific action as shown before and i can do this quickly right here from the end user portal or i can submit a response and add some additional content and some dialogue here indicating that i have properly finished my assessment and also responded to this particular violation in question now that that's done let's take a look at the plumbing behind the scenes what we call dlp administration this is going to be indicative of our data loss prevention administrator who is going to be configuring assignment rules response due dates email templates and those assessments which we'll be going through here momentarily let's start off with the assignment rules now the assignment rules are going to be indicative of how we actually automate the assignment of those incidents whether that gets assigned to an end user a manager or even to a specific group such as our dlp ops analyst group here's an example of assigning it to a specific manager we can see here that we are conditioning this based off of a scan source and two levels of severity down below we can assign our manager based on the end user identifier of the file owner and we're using the entity field manager to appropriately fill out and assign this particular incident to the manager in question the next area is our response due dates and this is going to allow us to again specify and define a rule set based on a time based response from the impacted users so here we have an escalate to a manager this is going to now kick off an execution where after seven days from the first user notification it is going to now escalate this to their specific manager or even escalate it to a specific user group in this case we're escalating this to a specific group we can simply change this to the manager and also appropriate the maximum escalation levels so that we're not getting bombarded with too many escalated issues or incidents into those respective fields the next area and probably one of my favorites is the email templates because this is going to be what is defining the experience and the orchestration as well as the end news or notification of these violations and these policies that have been red flagged now of course we have a number of different default templates that are built out of the box but we're going to take a look at the incidents user incidents for escalating specific incidents that have been red flagged so here in this example here we have incidents that are going to be sent to the end user so we have that category defined and the type is per incident now what this equates to is when an incident does occur it will generate a new incident and send an email notification to the end user now if this occurs continuously over the course of the week or the day they'll receive separate incidents indicating there has been a policy that has been flagged for the violation now let's say that might be too much and we don't want to bombard users with more email let's go ahead and change that over to the digest and we actually have a template for our email digests and that end user digest will allow you to actually send out a programmatic email capturing variables from the available lists and it's going to say in this case for the end user all the incidents in a specific period of time the total number of incidents they currently have open critical severities high severities and so on and so forth and then of course links to those particular incidents that are tied to the target persona in this case the end user who has violated the policy and so this is another great way where we can start to use the flexibility and overall robustness and granularity of the data loss prevention incident response module and it's really simple to define and also change the criteria based on different conditions that can be set to meet those specific use case requirements within your organization now the last area i'm going to be going over is the assessments and the incident response options we're going to go ahead and go into incident response options because this is where you can actually be indicative of specific response actions that will be taken in order for the end user to then facilitate moving the state from in review over finally to the overall closure of the incidents for our analysts and so you see here out of the box by default we have a couple of actions we have one for responding one for reporting false positives or even reporting a wrong owner now we can actually show the responses to the specific persona in question our analyst and user our manager and of course these can be changed or modified at any time we've had a lot of customers and clients who ask can i create a new one something that might be more pertinent or prevalent to my environment and you absolutely can this is the beauty of servicenow's platform is the customization and the scalability of the platform can facilitate those particular niche use cases now the last area i want to focus on is the assessments the plumbing behind the assessments is extremely impactful and critical to the overall success of your mean time to remediate or resolve these issues by evidence collecting and making sure we have all the artifacts including the facts for these assessments and so by creating this new dlp assessment you'll see here that same example that we had brought up earlier looking back at our dlp assessments i'm just going to quickly navigate back into that specific record to showcase what that specific assessment look like when we're looking at this from the persona of the end user and so again looking at this from the persona of the end user here's what the end user will see they'll see the context in the description and then of course the form with the series of questions of course some of these indi indicative of being required or in this case mandatory so when we go back we see that same formatting but of course now we have access to the plumbing we can actually now create the specific description and then we can also click into the appropriate variables to pull in those subset of information in this case the metadata or the details of the specific areas we want to focus on and also present to the end user who's violated the policy so here we have the hello to our end user we also captured the file name and then just a brief description of what this assessment entails but now the fun part is the actual assessment designer this is where we actually designed the entire form that you have seen here on my screen as i was indicating before this is the visual representation and the finished polished product of our assessment and you can see here it's very easy to define and move around these different elements or controls and they give you a couple of examples that can be used to then prioritize the level of details criticality and any other indicators that might need to be required for further investigatory research so that way we can finally close out this incident record and with that that concludes today's presentation on data loss prevention incident response back to you claudius

View original source

https://www.youtube.com/watch?v=8p7XncYs4Dk