logo

NJP

Tokyo SecOps Integration & Ingestion Highlights

Import · Sep 21, 2022 · video

hello and thank you for joining this discussion of some Tokyo highlights centered around Security operation today we'll be talking about subjects such as software composition analysis and new integration capabilities within Tokyo my name is Derek Ricketts and I'm a solution consultant here specializing in the security operations space we're going to go ahead and get things started with an agenda I'm going to start with the software composition analysis support which include SCA vulnerability storage capabilities and enhanced SCA vulnerability detection then we're going to dive into integration enhancements such as new assistant toolkit capabilities additional manual vulnerability support and lastly I'll conclude with unassigned vulnerability automation capabilities so let's talk about some additional support for software composition analysis there are new updates to application vulnerability response data model that enables SCA vulnerabilities to be stored directly on a vulnerability item record and additionally there's further development of apis for the ability to recognize and retrieve SDA vulnerabilities at Large so once you're on your vulnerability item record you'll be able to see all of those key factors important to you and your organization such as the type of vulnerability the risk rating along with the risk score but if we go over to the common vulnerability exposure ID we'll be able to click and type directly back to the vulnerability item record and this apply and we'll be able to see exclusive features from software composition analysis the new integration system toolkit accelerates the development of custom Integrations by partner so we can have additional capabilities for ingesting and enriching our alerts as time goes on additionally we have support for manual ingestions of vulnerabilities specifically tailored to log j4 related vulnerabilities so we can we have the ability of creating them in our workspace and tracking them before or even before our vulnerability scanners provide for our additional findings and details related so once we do manually create these log j4 related vulnerabilities we're able to even group and categorize those into a watch topic and allows us to track those all those related vulnerabilities a lot easier and then and eventually initiating a bulk remediation effort once we narrow down the vulnerabilities our log j4 vulnerabilities that we would like to keep an eye on and manually create will even be able to have the access of tying in their um their common vulnerability exposure ID so we can then add those to this workspace we'll be able to see additional factors like this the amount of distinct configuration items these log j4 vulnerabilities effect such as an Apache web server we'll be able to see how many of those log j4 vulnerabilities are distinct so the different ones that we're dealing with and lastly and importantly we'll be able to see the vulnerability items records themselves so we'll have all the enriched information that will be ingesting or creating on our own and again we'll be able to keep up with all these in a single pane of glass and lastly we have additional options for an unassigned remediation task and vulnerability items which allow the remediation owners to automate the process of unassigned workflows so if there's a vulnerability those CR there was a remediation effort created from vulnerabilities we have the option of configuring um different automated workflows to kick those off to a certain Personnel or role based on their occurrence remediation status so here's a look into our it remediation workspace these are vulnerability tasks that derived from all of those vulnerabilities that were initially created what those new unassigned options will be able to kick off the the ones that are that are similar to or sent to a specific user and we'll be able to create a workflow for example to send those to a designated role or group so we can accelerate the remediation process of unassigned vulnerabilities and improve the collaboration include communication channels foreign I'd like to thank everyone for going through the these key features new to the Tokyo release um if you have any questions feel free to email me at derek.ricot servicenow.com or visit us at www.servicenow.com for additional related documentation

View original source

https://www.youtube.com/watch?v=DMfxcg9E2xM