logo

NJP

Tokyo SecOps VR Highlights

Import · Sep 21, 2022 · video

hello and thank you for joining me in this discussion of some Tokyo highlights center around security operations today we'll be looking into some of the new features exclusive to the vulnerability response application my name is Derek Ricketts I'm a search consultant here in the security operations space we're going to kick things off with a quick agenda I'm going to go over what vulnerability response is and then we'll dive into some of the new features which include a new season of workspace enriched by known exploited vulnerabilities with a new integration and we can see how we're going to see how we can use this enhancer mediation status tracking and cover additional areas like Cloud infrastructure and contain and improve our container visibility foreign so vulnerability the vulnerability response application allows us to quickly identify bottlenecks in areas for improvement using our unique workspace so we can use the group vulnerabilities up and categorize some better this way we can monitor and report on effectiveness of your remediation strategy better and then with our enriched context we're going to better assess the exposure accurately by containing service aware of cmdb with scanning data from our foreign Billy response scanners and other areas like our outside resources such as the national vulnerability database so as far as some new features to Tokyo we'll start with talking about the um the sisa integration so the sisa integration allows us to enrich some of the data into our typical vulnerable response workspace so we'll be able to have those our pump those uh known exploit vulnerabilities published and it's still tied to our vulnerabilities picked up from our scanner for example this way we can put it all in that unique workspace and continue to track and then eventually initiate our bulk remediation efforts so this will allow us to accelerate the prioritization decisions and prioritize remediations by the due dates as we're again we're getting further enrichment and I will be able to differentiate a lot of our vulnerabilities a lot better then we can track the status and Remediation of vulnerabilities and or a single environment with our watch topics and that's once we kick off those bulk remediation efforts and again all this will be in a single pane of glass view so we'll be able to easily and conveniently work through all these vulnerabilities even as they're continue to come in so here's a glimpse of what that'll look like this is our vulnerability response workspace with those uh the season known exploits and as you can see we have a lot of we have we can see certain metrics immediately within the overview tab of the workspace such as the amount of active vulnerabilities over time to see how we're trending and then if there's any vulnerability remediation efforts created we'll be able to see some of those quick metrics that matter to us as soon as we click into the workspace now with those those vulnerabilities of known exploits uh we can see exactly how they're tied to our configuration item for example and the the total quantity of uh distinct configuration items this way we know exactly how many of our assets this is affecting uh since there could be more than one vulnerability tied to a configuration item and we can even see that broken up into class like for example if this is just an email server is this a printer it's just an IP phone bill to see all those metrics conveniently broken up right there and then we'll be able to see some how many of these vulnerabilities are distinct so just similar to how we can have more than one vulnerability tied to a configuration item there could be more than one or there could be uh duplicate vulnerabilities but we'll be able to pick out and see exactly how many distinct vulnerabilities we're dealing with and lastly we have all those vulnerability items themselves we could be we'll have all the context enriched provided by again the sisa integration so that'll populate our summary and you can give us certain other metrics like the common vulnerability exposure ID and it's again so we know exactly what we're dealing with I'd like to thank everyone for going through some of those new vulnerability response features from the Tokyo release if you have any questions feel free to email me at derek.rickets at servicenow.now.com or visit us at www.servicenow.com for additional related documentation

View original source

https://www.youtube.com/watch?v=9I3j74SBPq4