logo

NJP

Cloud Center of Excellence(CCOE) part 2: how to plan cloud migration & manage cloud security posture

Import · Sep 27, 2022 · video

good morning good afternoon and good evening everyone and Welcome to our webinar uh and thank you all for being here as well um so today we're going to be covering how to plan your Cloud migration as well as manage your Cloud security posture and this is part two of our two-part Cloud Center of Excellence series and today's session is also part of the icon visibility and governance webinar series which we host on the third Tuesday of every month so please be sure to join us back here uh next month at the same time for and then subsequent months for future sessions and today's session is also part of the live on servicenow program which is a curated event series to help you with you know to connect you with service now experts to help you more easily adopt servicenow solutions to gain faster time to value with the purchases you know what were the products that you've purchased so we hope that you do join us again uh you know at a future session this topic is it operations management but we have topics across the platform and you can scan the QR code or use the link below in the chat just a few housekeeping items here so everyone's line is muted we ask that you please use the Q a feature to ask your questions throughout the session and then when you do ask a question please feel free to introduce yourself let us know where you're from Who You Are we'd love to know more about you and please we have three polls today so we'd ask that you please partake in those polls so that we could have a better understanding of where you're at um so this session is being recorded and we're going to share it on the servicenow community as well as on YouTube after this session is finished and then finally uh we just ask you that if you could please fill out the short survey we'd love your feedback so when the session ends you'll get a link to complete a survey it helps us improve this for future sessions and my name is Steve Emerson and I'm the outbound product manager for item visibility and governance here at servicenow and I'll be your host for today's session and as an outbound product manager I wear many hats so product evangelist customer value realization as well as sales enablement just to name a few but what I love most about my role is that I get to meet with you and hear how you are using servicenow products and then I get to share information or we get to share information about how our products can help you achieve your goals um so but our main presenter today um is ROM so ROM can you please give a brief introduction hello everybody I'm David atten part of the item product management uh uh team and I handle primarily the cloud products that's like the cloud provisioning the cloud governance and the cloud Discovery aspects pretty happy to be part of this uh webinar series and presenting my second of two sessions here around the governance uh area so thanks for the opportunity once again and very happy to be answering some of the questions as well as taking you through all the some of the capabilities that we have in this area back to you Steve all right thanks Ron so before we begin we just have a quick Poll for you to answer we would like to understand where you are with your progress of setting up your Cloud Center of Excellence or ccoe so Trisha if you could please launch the poll so our questions here are I mean our our answers are you know what is a ccoa maybe you're not don't know what that is or maybe you're thinking about setting one up or you're in the process of setting one up or maybe you have a fully functioning Cloud Coe that would be you know we love to hear your thoughts on this and we'll take about 10 more seconds before we end the poll all right I still see a few coming in so I'll just let it hang out for one more all right five four three two one all right let's share the results so it looks like most of you are really understand you know you know don't know what a ccoe is we'll cover that here as well uh some of you are thinking about it um some of you are in the process of setting one up uh but the the smallest percentage here is that you have a fully functioning Cloud Coe so good to know uh thank you for that feedback and I'll go on to our next slide here so if you think about a cloud Center of Excellence um all of the major Cloud providers have their own definition of what a ccoe is um I'm not going to read all these but it certainly takes some time to read these and you'll get a copy of this deck as well but you know essentially it's it's having a team of people that are focused on governing the cloud making sure that it that it helps you achieve the goals that you've set out to achieve with your Cloud Investments and we've also created our own definition of of what a cloud Center of Excellence is a service now um so we believe that ccoe teams should foster the frictionless adoption of the right Technology Solutions to meet the challenges of the Enterprise so they can accomplish this by sharing prior successes and best practices with project planners assisting with the creation and review of new architectures and ensuring the ongoing security and governance of active cloud services now we also have a set of products which we're going to talk about today that'll help you achieve this on the on on the technology side and with that said I'm going to turn things over to ROM to start the presentation Ron um I think you're on mute sorry thanks for that yeah uh two primarily uh products that we'll be uh covering today and the use cases that Steve mentioned earlier the new app called Cloud migration assessment another app called Cloud configuration governance right these are two areas that we'll be getting into what we notice is that several companies several customers that we are discussing with the the survey results that we just saw kind of resonates with the the world order so to say we are seeing uh many customers who are like okay what's ccoe right what's Cloud set of excellence and then there are a few customers who like moved into it or looking at it and this is a representative of uh service that have been done state of the cloud management surveys that have been done so it's pretty much the case uh everywhere so don't feel too bad about it if you're not aware of it yet we'll try to cover more as we go through this and we'll talk to you about how the ccoe becomes the cloud Center of Excellence team virtual team so so to say becomes more and more relevant as you push your organization to move towards the cloud in your Cloud transformation Journey so to say for this I'm and and continuing from you know in our previous uh webinar last month I'm I'm taking up this fictional apparel company uh the name of the company seraju just the name I came up with that has some relevance from uh from people who speak Hindi uh India Indian mother tongue but but yeah is a apparel company right and uh they are established as early as 2016 getting into high-end fashion want to get into online selling they've been a brick and mortar kind of a business with uh many showrooms across the uh across the us but they are now planning to get to be online right and uh as they have their Cloud transformation goals they're also building up a team there but they do lack the cloud skills and talent uh on the IIT side in terms of okay how to approach the cloud what are the rules and what are the things and how do you uh Foster faster Innovation while at the same time not actually engaging the company's data you know things like that so those questions obviously arise from the last time we spoke to now their uh attrition has not has not affected them or anything 67 app Dev plus devops is what they have who are actually working on the apps and actually building uh you know application infrastructure using uh devops tools and uh six member ID team that continues to be the case the biggest concerns they have are Cloud security and the cost angle right and uh their cmdb is sort of a work in progress uh they're better than last time because they've achieved the mapping and they have their application service mappings through tags and other approaches that they have set up right the discoveries are ongoing right now so all that is good now now they get into the next place where uh you know they if you look at the story so far and on what we covered uh in the last and the last webinar from their data center uh you know sort of locations which were their own uh you know Colo data centers and 130 data 130 stores across the US they are they are now at a place where they've achieve their service mapping right and uh they are now looking at you know how to get into moving their existing on-prem uh apps they're more their on-prem servers and their workloads onto the cloud right and how they want to use their discovered information how to build uh what is called as move groups and assign workloads to migration waves and all that stuff so that is where things are and and and and for this before I get too deep into the actual uh product workings and talk to you about the migration assessment uh uh you know workflow itself Maybe uh this is a poll that I would love for your inputs on is your organization currently moving workloads to the cloud in one way or the other right please take a look at the answers and give it a Best Shot yes we are moving to the cloud but we are doing most and more most mostly lift and shift yes we are going fully Cloud native building directly on the cloud mix of things our workloads will not move to the cloud maybe in some cases or have we have plans in the future so keep it uh going for about um yeah yeah keep it coming thanks thanks for the inputs I really appreciate it a few more seconds there five four three two and one and we can close thank you so much for that so um pause to reflect on the results here it seems to be a mix of cloud native and left and shift which is actually good uh and uh yeah I'll talk more through uh these aspects there uh there are a few cases where uh it's it's like pure lift and shift or pure Cloud native in fact it's almost an equal uh numbers there uh one case where their server clouds are not moving to the cloud at all and then there's future plans around that um again 50 only have participated please do feed in your results will be very helpful for us but uh let me move on here uh thanks for the inputs once again so migration assessment uh looking at your workloads looking at your apps your servers uh your processes and all that starts from having a data platform cmdb is servicenow cmdb with our Discovery slash service graph connector capabilities gives you the perfect platform for starting on that on that discussion in 80 percent of the cases are even more uh Discovery sorry uh migration projects are actually stalled primarily because of lack of data so which leads to lack of being able to take decisions so people are not able to make the right decision as to okay what do we do with this set of servers do we have the right data do we have the right dependencies in place do we have the right process information do we have the right license information all of that datas is kind of uh Missing there and this is where you know the work that Sarah has been doing and probably some of what you are also doing that Discovery information is going to be pretty uh important as a single source of Truth giving you uh the the composite data there when you get into the product we'll also see how that data comes together a single workspace and you can see more details in that in that area in terms of uh Team structure driving uh the migration story right recommendation in general uh From servicenow perspective I mean Steve already mentioned about what is servicenow's take on terms of uh what is what is the ccoe right ccoa really kind of has become this broad organization which is kind of having daughter line and virtual connects with uh the finance team from a cloud economics perspective SEC apps team from a security perspective uh regulatory norms and all that stuff and uh Enterprise architecture from a landing Zone design perspective right as you as you move to the cloud what how do you get your accounts how do you what permission should you start with and you know details like that and the ccoe team houses also app owners uh the the migration Ops Team which would be dealing from the migration perspective and actually the tools team which is actually dealing with the actual migration tools here working with the cloud vendors maybe there's also Cloud vendor Consultants also talking with you on the actual migration there with such a team in place yeah the right decisions can easily be taken there and uh we'll show you again how these themes can be included into the into the discussion uh through the migration assessment app and help you arrive at the right decisions in that area right um I thought I I saw a chat message I'm just going to check real quick if there's any uh is there is there a question that uh needs to be answered Steve no we can move on context perfect so Cloud migration workflows uh you know as as a set of functionality right the the app itself it deals with something called the analysis workbench where all your inventory data that you've collected uh by running Discovery uh both your Cloud Discovery and your so-called deep Discovery the server Discovery information get it all together in one place so it's like one place where your migration admin or the migration team can actually go and take a look at uh you know all of the information together and help to take some decisions there the migration assessment helps you to you know it helps you to plan and track your migration uh activities that are going on there and it also helps you to uh and you know kind of get a numeric uh uh you know representation of how many servers you have on-prem versus how many servers you have in the cloud and how that's coming along and the executive dashboard shows you the progress on how things are going along there in terms of the uh before I get into the app itself I just wanted to spend a little bit of time here you go from the left here on this on this slide that I'm sharing and uh towards the right right if I were to uh sort of say that this would be the right set of uh this is a sort of you know migration approach the uh the the timeline that you have to follow first you start with prioritizing identifying and marking up your server groups it starts with using the various server metadata your properties and you know details from uh you know app service mapping as well as tags and all that bring it together right group your service meaningfully and uh you know get them into meaningful so-called move groups right that's like the first step there right this could be combination of things that can happen there you can base it on the applications that are uh that these servers enable uh this could be based on a set of servers that are running typically similar workloads and they're part of maybe a larger cluster or something like that so those kinds of things could be there so those are the examples there in a figurative manner then once you have these groups defined you assign these groups into what is called as a migration task and you assign a team to actually drive that migration task this team will typically comprise a cross-functional set of people who are actually working with uh you know the architectural aspects the application functionality aspects the application code itself you know checking whether it's like uh all dot net or is it a combination of java and other stuff and there's net your your recommendation is clear it needs to be Windows you know so those kinds of things are important sort of build out the whole uh racy model so to say for each boxes on the left that you see here so that's the second part of it and also talk about how we can use some interesting approaches like having questionnaires and surveys to actually get some more details from your sort of a wider team in order to collect more qualitative information which may not be coming out quantitatively then the analysis part where you actually going to find out what your decision to go forward here you had to pick from whether it's going to be a complete rehosting a lot of people mentioned earlier it's a combination of some Services some applications going where left and ship migration some Services going via a cloud native approach uh but but you know you just have to arrive at what will be the right balance to be done there and sometimes you might just want to say okay retain it it's not an application that's going to last for very long but that whole discussion that whole decision that needs to be driven through a workflow and that's where our assessment task so to say we'll help you there and the last bit is the implementation bit where you completely migrate away and you're going to hand off at this point of time you have your server information you have your application information you have all your details right you're going to pick it up and you're going to hand it over to a migration team there maybe it could be a complete you know move into uh the cloud uh using a left and shift approach or it could also be an approach to build natively in the cloud or it could be a hybrid who who knows it could be a combination thing you could be using pass and some of the relationship migration aspects there so that's uh you know again a decision that needs to be taken and the and the action uh in in that area I thought somebody uh raised their hand uh okay if if there are questions uh again let me know so let me jump into the app and uh you know and show you some more details about uh how we intend to achieve that steps that I was talking about there Okay so the cloud migration workspace app basically you navigate to it from the workspaces right in the cloud migration workspace you have your overall environment from coming from your Discovery information there I'll show you where the discovery information lies that is more of an aggregated view so you have details of your resource concierge servers your dig down into windows and Linux all the apps the processes that have been found on these that kind of details and we also have details about uh you know let's say uh VMS on which let's say your Cloud Discovery your Cloud inventory Discovery has been run uh but you don't have more details into the individual compute uh in the in the cloud itself that's like the last column there and the breakdown uh by physical server which Cloud it belongs to all of those details are available there right so if I drill into this right it opens up your entire set of servers there of the various types that cmbb supports right when you look into the various types that cmdb supports obviously we we we support a whole host of uh you know with a varied patterns and Discovery approaches we have a whole host of servers that can be supported there right I could very easily kind of you know group these servers in in various uh other mechanisms there like for instance I could say uh let's look at the operating system right and uh so let me yeah there you go so from the operating system I can now filter it based on a certain other uh criteria here right so let me maybe choose from just uh Windows 2000 Advanced server or windows and two windows 2012 R2 standard and apply it and I can break it down and I can find out exactly those I can base it on my names for instance I can write a filter for name contains certain things right so all those things can be done now once I uh you know filtered to my set that I'm actually looking at right I can do this filtering again in multiple ways it need not be based on just this criteria I can also look at the advanced filtering option and in the advanced filtering option I can go into the advanced View and I can pretty much set up a whole bunch of additional conditions here so that I can group and arrive at my exact right set that I that I want here we have some standard rules here and I also added this one just just saw there this is a standard condition Builder kind of an approach right so you can also look at which cluster it belongs to or who created it and uh you know you can look at certain other things like uh the name is you know set up in a particular way you can also look at the server properties right what type of server it is right those kinds of details are there what CPU State you know and also attacks the standard tags that are present as part of the records that can also be taken into account here right so those kinds of details are available here and using that you can pretty much arrive at that not only that you can uh also look at uh you know the server records here right so it opens up the server record you can have some more details of the server here right as obtained from uh the the VMware Discovery uh and uh the that that was the VM instance details and this is the server details with the running processes and all that stuff right you come to this in a minute now what I've done is really I've uh started to look at a couple of cases where I want to decide what do I do what do I want to do with a certain set of servers which are running Windows 2012 as you all know Windows 2012 is pretty old operating system so so so the question is what do I do with this should I you know start to look at uh it's it's Opera for sadajo for instance for instance it's soccer Bank Rackspace in their code or Data Center and uh should we just you know migrate this over to the cloud where it can run a bit cheaper than than occupy the Rackspace on the lighting and Cooling and all that stuff so in order to take that into assessment I'm gonna add I selected both of these filtered whatever it is I'm going to add to assessment and I'll create a new assessment and in this assessment uh oh okay it's already part of uh cass1005 so let me let me look at that in a minute but but the important thing is it's already part of uh certain assessment and I can go and take a a look at that so let me um now that you know we have arrived at uh the the server group in the same manner additional server groups can be created right and then once you've created the server group you assign it to a task then it becomes a servicenow task and in that sense you can pretty much kind of get additional uh information uh to be additional decisions to be taken on that uh if I were to I'll go to the task in a minute but uh if you look at uh the additional tabs here we have additional information like what are the discovered applications so you can group it by you know certain application information and this is based on The View that's available there so what's running sap what's running uh so many other applications that we figured out through our Discovery here and uh the last bit is the part where these are just VMS that have been discovered via Cloud Discovery right uh that's about there so to going back to the you know research uh analysis that was done 80 of projects are stalled due to lack of data here we are as long as you got your Discovery working and we make it easy for you with sufficient patterns for you and uh we have your up to date cmdb we are able to give you all the additional information that you need that you can help you to uh you know take your decisions yeah now we also saw that I'm moving to the assessment dashboard where I'm going to look at my migration tasks here let's take a look at uh you know the the resources here so you find some interesting uh tasks already have been set up here I have given a short description I'm just looking at migrating my Linux machines right I'm looking at uh rehosting some of my midst to Amazon I'm looking at migrating my on-prem database onto oci right and this one is like not named that that scene we're doing some re-platforming there but it's likely looking at this it's like communities and we are trying to do a re-platforming in that case the name indicates kubernetes here uh if I go into uh back into the overview and I start to look at another set of uh tasks that are uh more or less in the needs assessment phase it it it kind of gives you an idea of uh you know what what state uh these tasks are at now I have added these Ubuntu servers here these uh Windows mids here right and it I need to yet assess what's what's going on there so let me go into this uh task real quick right if I go into this task I I I I look at uh you know some names of people I have assigned it to right so the task is assigned to a person so from a service now anger uh you know you are tracking it to say that this task is appearing in you're all uh you know overall open tasks and people are consciously watching it from your management perspective uh from a CIO perspective from a process uh program management perspective everywhere it's it's reflected very clearly assigned to a change management group and uh migration start date end date added here you can obviously change it and set it to a new thing it's though in a state of New it can move into various other states because it's a task again you can set up so much change management that goes in whenever uh you know this state change is done it can go into interview and then you can automatically say we opened up reviews for this and uh uh you know in the task you can add people to the watch list and say uh Zach right for instance and uh maybe myself right he had a few folks into watch list and you add maybe your folks into uh some kind of uh in a work notes list here I'm adding Steve right and and I can save it so what will happen here is as this task goes through the various things you can have other people notified and if they wish to provide inputs they can come into this task much like a standard servicenow task they can provide their comments here right that's where it gets a little more uh interesting so uh the the decision that we are posing towards right now from a migration admin perspective is no we want to deploy these Ubuntu machines to Azure cloud pure architecture is infrastructure as a service right and what is the urgency it's not very high so we have a migration wave of 2023 q1 that can be set up or you can even push it out later right 2023 Q2 and the disposition is basically to say we want to rehost it now this is not a simple decision as I mentioned there because you have multiple teams engaging here there could be so many decisions discussions to be had about okay is it worth first re-hosting uh if it's running some basic workloads that could be as well as available as pass like for instance um you know we have this other uh uh task here that is talking about gitlab now gitlab is also available as service directly in in the cloud for your storing your repositories gitlab offers their own cloud service so should you go to that approach right so this is another task where I've added that gitlab service which is running on a Linux box on-prem but actually starting to look at should I go towards the target architecture which is a bit of hybrid uh with the involving yes and pass and make a pre-platforming decision in that area and if so who are the teams to be involved who are the uh you know people to be working on it and what time frame should I be actually looking at right so this is another task where again similar decisions can be taken there the interesting bit again is looking into each of these servers and actually finding out some interesting details there so if I look into the resource here it's obviously a server a Linux server right and this goes back to the record that I was showing earlier right you have uh what is the file systems attached to it right and what are the size of the file systems so you want to know like when you're going to the cloud you're re-platforming you may have to spend uh to actually have this additional storage there right what is the software installations that are already present there so you can actually look at is it running some licensed apps if so moving to the cloud will you pay for the license so that discussion that question actually comes up right and uh running processes just showing what all applications are running on that in case you're just doing a lift and shift you don't want some unnecessary processors running on that right and it gets even more interesting because additional data data is available here about the memory the storage devices and most interestingly also TCP connections because this is gitlabs you know you're about to have other applications that are included in working with it there could be NFS server there could be file servers that are included and and working with it and you may want to check which are the servers that are connecting to it in a sense it's also forming your dependency mapping right uh one of the intents we do have as part of the roadmap here is to make this simpler a whole lot simpler by automatically reading the application service dependencies so that we can automatically bring it in that's part of the roadmap but at this point of time you have a lot more flexibility let's say by actually looking into this DTS here one additional interesting uh thing is when I look into this resource field I can also look at because this is on premise it's running on my VMware server I'm getting some more additional details here like for instance it's been granted to CPU okay and it's been granted uh about uh you know eight gigs of memory RAM right in reality though it's using at the maximum only 30 percent of the CPU right over a period of time we've actually gauged by pulling the data from VMware we've gauged the usage on the server to be less than 30 percent of the actual allocated space so when you're going for a re-platforming to the cloud this is some or uh rehosting to the cloud and you're looking at two CPU here you have a better advantage to actually make a choice of should I just go for one CPU here because that's all that's being used here right and when it comes to memory it's even worse it's like less than 25 percent less than one fourth of the eight gig is actually being used here so when less than one fourth of that is used again you can go for a one CPU core with a 4 gig or 2 gig ram right and you also have information about what is the disk discrete rate and write rate and all that that is actually present here right so overall you have complete knowledge coming from Discovery in one place that can actually help in your migration assessment planning that can actually help you to do a better assessment as to what decision you want to take and how you want to go about it and what sizing you want to use and TS like that right you can combine this also with some other interesting things like our platform capabilities around survey for instance right uh when you want to pull uh as a migration uh in charge person you want to pull additional information from your sort of wider team you can offer them something like a survey and again I'm not saying you have to use the service now survey you can use other survey tools that are available whatever is your corporate survey tool in your company but you can basically get additional information like for instance does This Server use data encryption this is about retiring the Windows 2012 servers and actually trying to find more information about that right and then you can also say what is the date uh you know I want to go to Whatsapp probably a bit wider there so next next year February some additional information whatever you want to add here these are servers running XYZ app whatever right and uh what's your preference because uh these might contain uh key uh key data that you might want to format uh or you might want to hand over to an external agency that is trustworthy right you can then choose the right order that you want to do right so I could say sanitize and clean up format HTT is the second option and hand over to the external agency is the third option any other additional options and then you can go and submit it and when you submit it that results uh can be pulled back into uh can be pulled back we don't have an out-of-box capability for that but can be pulled back into the task itself so that everybody's aware of that information and they can take a closer look at it in a in in let's say the weekly Cadence or the fortnightly Cadence calls that they set up there the combination of a process driven tool combined with data driven approaches that we are actually driving towards and in the future we are also going to make it very uh automation uh uh driven where you you we are able to give you even more uh straight forward recommendations for what you want to do with your workloads and all that okay so that's pretty much about uh you know the the the migration tool as I mentioned before the migration waves can help you to determine what is the timeline you want to kind of set up your applications for right so uh changing the migration wave again can be driven through a change management process and you can you can decide on how you want to uh plan out your uh your application uh moments in the future okay coming back to uh uh you know my primary dashboard here you can also see how many are jobs that are planned for the Q3 time frame how many jobs there are planned for the q1 next year time frame Q2 and Beyond right so those kinds of details are available here let me quickly also show you another capability from the point of view of service now itself where and you can easily group these application migrations into a visual task board because eventually they are tasks so just adding it and showing it in visual dashboard will be a a lot more simpler and easier for management you can also move around things easily into that okay so there you go so there are a bunch of tasks here they are not set to any migration wave that's why they are sitting here there's wave zero which is your setup of your Coe ccoe and then beyond that you have additional tasks uh which are set up for Q3 Q4 this year and all that and hey it's easy to move around things VDB I do not explain it to anybody but but yeah again the the key thing that we've done here and we received a very good feedback in some of the pocs the discussions that we had with customers and Pursuits where uh they said okay this is um super because you know I have my Discovery information coming in I have a workflow to drive it along with and uh that way I'm able to actually track how this is coming along and plan out my migrations as we go through right so that's on the on the Migration app I'm just gonna yeah um I'm just going to take a quick look at uh q a if any yeah so Ron we had uh three questions come in and I think we kind of answered them as we went out so the first one was uh Discovery information is that you know is is that from Discovery data or is it manual entries right so really it's reading from the cmdb but you're gonna get the great benefit of Discovery because it's more it's accurate data it's up to date right so please do not rely on manual inputted data into your cmdb to make assessments like this um the second question is are the counts of servers on the cloud migration workspace showing only non-retired servers yes okay yes that's that's that's also an option that you have there we show the non-retired servers uh but you can also uh you know have that filtered out if you choose to do it another way but but yeah not underwrite is the default okay and then the last question was when you refer to groups are you referring to Dynamic CI groups I I think we're referring to migration waves there is that correct migration groups the move groups uh within the migration waves yes yeah okay okay that's it as far as the questions please proceed thank you okay let me close this and uh go back to the slide here so this is the journey that sadajo is taking with respect to the cloud migration assessments and uh they they're starting to you know build their move groups assign workloads to migration waves and and they're going on on that process but as they enter the cloud it's important that in Cloud world it's a shared responsibility right AWS won't take responsibility if uh the client the the customer leaks out credentials leaks out data AWS guarantees that from a network perspective from the overall infrastructure perspective they are giving you uh they are giving you security platform but uh if you decide to let's say keep your S3 buckets open to public you're obviously uh you know uh kind of opening up uh trouble there right so take care of permissions taking care of users accounts credentials settings and also being able to remediate the open issues quickly so these are all going to be pretty crucial for sadajo as they as they get into the uh you know Cloud uh cloud cloud wave before I jump into it again another poll uh to see if you can bring it up please do you scan your Cloud resources for configuration violations example let's say the virtual machine security group is not set correctly uh as the poll come up please okay great um so please uh start to answer this if you can talk about uh whether you're doing it uh via policies on the cloud itself using tools like Prisma or third bot uh or you don't scan or uh you know where it's taken care of in a devops pipeline maybe you scan it but another team does it as part of secops initiatives or this no scanning actually happening on the cloud at all which can be a a little bit of a risky proposition but but yeah uh keep going uh wait for another uh 10 seconds here and love for uh everybody to put in their inputs here I know we did 50 last time but uh really gunning for even more this time possible okay uh last three seconds there three two and one good um so yeah that's uh let me stop sharing that and we can bring up the final results there okay so these clearly are indicative that uh you know we have uh about 35 percent who are running with the policies on the cloud providers we'll talk a little about uh what is the difference between running policies on the cloud providers versus how it is different from a servicenow perspective uh also using tools like Prisma and turbot right you know that's that's also something we hear a lot from our customers some have taken care of the devops pipeline but there are gotch has to be taken care of there which is something we need to talk about we don't scan Cloud resources but another team does it okay perfect um we'll talk about that kind of organizational setup and the last bit is the seven percent where great place to start let's start to look at how we can actually help you in that area right so let me move on here uh very quickly um to say the least right uh thanks say the least standard and best practices are not optional right you want to maintain your compliance and your consistency in the configuration uh so that uh you know your data is not exposed you don't have security breaches you don't have any anybody uh mining uh information and all that so that that that becomes a pretty uh crucial uh to consider there right and in minutes you can basically scan your Cloud configs intermediate the issues right that's a key thing there uh you know a popular uh anecdotal uh example is uh you know how are you using spell check today right sometimes just because you want to start typing in a normal editor or in a chat also you go typing and then before you press enter you want to kind of spell check it if it's a chat or even it's a Word document or something you you you finish typing everything and then you you want to connect the small typos and all that something similar to that you don't want to hold up your uh you know uh your engineers so badly right uh when when they are starting to enter into it so immediately as soon as they are deploying something just uh to the cloud you could also check it uh obviously there's another angle to it right uh checking it using policies right at the time of the deployment itself and uh it it helps to some extent definitely because uh you you go out with a clear blueprint that is certified and the blueprint uh which could be your cloud formation template or something it's using the right images it's using the right permissions everything is set but you need scanning also later point of time because some things could have changed on the cloud and things always changing the cloud right for fixing issues for getting past some immediate uh needs that let's say the the the the engineering uh wanted you may change certain things and again scan is needed at that point of time so that's where the config scans actually come in there uh you're going to be running some additional details there the the config scans basically are a bunch of policies and the policies uh one example of which is here which is checking for allowed Hardware types uh finding out those allowed Hardware types using a simple low code slash no code policy editor show in a minute and then you can go ahead and actually fix it it's a beauty of it you can go ahead and turn off certain things in this case because it's a not an allowed Hardware attack there right and a bunch of workflows that are provided as part of the cloud configuration governance app itself that is uh part of the offering here let me jump into a quick uh demo here okay sorry I need to log in again okay so if I go into the cloud configuration governance app I have a bunch of policies here so I'm in Cloud configuration governance and I'm under policies here we have various sets of policies that are doing your regular scans again as a company like sarajo who's getting into the cloud right you want to check for your VMS you want to check for your S3 buckets you want to check for uh your uh users and all that right so this is going to be a pretty uh crucial set of checks that you want to do like let's take an example of VM Hardware type here for Azure VM Hardware type I'm going to check whether the VMS are of this particular Hardware type and if it's of this particular Hardware type and if it's in either of these states like VM starting or VM running right if it's if it's off it's okay but if it's in starting or on running State and it's a belonging and it's using this Hardware type standard D2 V2 that should be reported right and and for this we actually have certain audit results I just click on test policy I can get so by looking at it real quick this is a policy that works in this manner it underlying it would go out to the cloud get the additional details that are required here for each of these checks like for instance for uh SC bucket encryption details are being checked for uh certain VMS additional details are being checked in all those cases uh you know we are finding out and we are coming back and saying okay this is the VM this is a resource and for this resource we found that there's a violation there I can click on the resource I can look at the additional details of the resource here there's a bunch of details that we are covering that you know well it's over and about What discovery offers it's it's it's it's it's it's a mix of things and there's also Discovery information but there's also additional information here that's actually being brought in here and the beauty is this gets linked with the actual CI also so the identifier is already already available here so it gets linked to the CI there so that way your CI is sort of enriched with additional attributes here and uh I can I can once I've run that policy I've come in here and I've actually been able to uh you know find out what is a violation Hardware type not compliant and now I can select this I can go ahead and remediate it and when I go ahead and remediate it I have a set of remediation options that are available there so clicking on this I can see like a catalog item I can pick the right one and then I can go ahead and click it of course I'm not going to turn off the machine but I can I can very much remediate it and I can also find for the same violation here for the scans that I've run I found a bunch of other VMS that are not Hardware compliant the the earlier thing you saw and they can run permutation mass and mass with uh you know with all of these details and I can fix the problems once once and forever right right here right the remediations are also very very interesting in that sense if I go to my violation definition here right so in my violation definition uh I can also find a just give me a minute here so I'll go directly to my recommendations rather than my violation if I go to my remediation it also tells like okay for running each remediation what is the action that's being run and what is the permission that's needed for that right so that way you can also inform your Cloud team to say hey we are running these scans and the beauty of it is when you run these scans from a servicenow perspective you have the linkage with cmdb you have the ability to run the actions in cmdb with change in place with approval in place right which uh you know sort of gets entirely missed out if you're doing it directly in the cloud here we could check whether you know uh for this turn off ec2 instance subflow before running it on a particular CI you can actually check if the CI is impacting certain services and if so you can plan for it accordingly and do it but we're going to directly do it in the cloud just out of you know a rash decision to go and go and fix it there you might be inadvertently affecting some actual underlying uh you know enabled service there right so that way uh again to the uh mentioned earlier in the in the survey results that people are saying hey you know uh we let the cloud policies take care of it yes Cloud policies are good but they work uh in a in a sort of a siled manner so it's important to kind of keep this uh perspective here that's a an angle to consider there using the policies that I showed earlier right I can basically create a policy group and uh policy set and that policy set in turn can be assigned to a scan configuration okay so the scan configuration is somehow like a discovery scan right except that it's going to run each of those policies in that policy set that I've assigned there so going into this and and as you can see it's a very traditional kind of a servicenow app with all lists and forms at this point of time we do have a roadmap plan to move it into workspace and give you a better user experience on that functionally the product is you know pretty cool uh already doing the stuff that you want there here we have actually had a you know AWS policies added into that like the bunch of policies that I showed earlier the cloud provider type obviously is AWS it's a daily scan that's running I have a schedule there where I can set up how I wanted to run I have assigned a service account to it and for that service account what is the data center that I'm interested in I can add more data centers and I can execute it and run it and I can also set up some filters so that it runs on specific VMS only so specific sorry objects only not necessarily VMS S3 buckets all of those user IM users so for all of that you can actually sort of you know see the complete details and you can also set up filters based on tags right adding adding attack here you can add as many tags as you want so you can only search for the tags of your concern whatever value I like you can restrict it that way or you can also use it free form to only run on certain certain objects by giving their air ends the instruments IDs are there right so simple uh story there click on execute I can run it ad hoc right now and it can just continue to run there once I finished running I get what is called as a scan run right so we talked about to recap a little bit and talk about the policies and what the policies do we are shipping out of the box policies you can create your own policies they are set up in in multiple ways we'll see an example of how the you know another bu another uh products bu inside our own servicenow organization has built a whole set of new policies that can help you in a different way talk about in a minute but uh the policies group into policy sets and policies have remediations assigned to them right actions are part of it and then you group them and you run them as a scam and in your daily scan you can when you run the daily scan you can basically get the the results of the scan now you can basically say uh like how many resources were monitored through this uh what are the scanner unlocks and what are the audit results here right clicking on the audit results show order results I can basically see okay these are the problems I have right and uh you can basically run limitations for that let me take another scan run for let's say AWS here right yeah almost done here so if I go and click on audit results here I have a bunch of varied audit results here some of these are like uh sorry for the geeky evaluation definition names here but uh they they all point to actual objects here and you can actually find some actual pretty serious uh information uh that's actually violated uh here Security Group is wrong or this is a a user account with a password enabled but no multi-factor authentication for AWS account and uh you can actually have remediation done for that so that you can set the right profile there so if I choose this and this let's say saying the user has this violation the virtual MFA is is not there I can basically provide a whole bunch of remediation here so click on this okay there's no there's no limitation in this particular context but but yeah you can actually provide uh any action that you're interested in now the last bit is the uh policies that I was talking about earlier you have a apart from the defaults that we ship here there's a whole bunch of other policies uh if I sort it again I also find a whole bunch of other policies with a specific naming here these policies help you to identify whether you're compliant to regulatory Benchmark CIS for AWS and CIS for azure as part of our second Ops offering we call it the cloud security posture management cspm offers you these policies and uh just having these set of policies can tell you right away whether you're compliant with the CIS norms and thereby you can measure your security posture and raise it upwards to say hey guys we are not actually meeting the posture that we are expecting here we are below CIS Norms let's work through that and using secops configuration compliance you can go ahead and plan your Corrections in that area okay so again long and short of it Cloud configuration governance can take you through various types of uh policy enforcement for your Enterprise Norms as well as for regulatory norms and help you to remediate the issues also okay any uh questions open at this point of time I guess not uh I mean are we okay I guess I closed right on time any questions uh feel free to bring up in the over the audio yeah if you guys have any questions please feel free to put them in the Q a um I'm going to take back over sharing of the screen then ROM I stop yeah please go ahead please um all right so once again um this will be posted to our community Forum so you haven't had a chance to watch the full thing or if you just want to you know want to watch it again certainly you can go there um you know our product roadmap is driven you know a lot of times by our customers uh we do encourage everyone uh to submit their ideas on the idea portal uh which uh will and if we have at least 10 unique customer accounts who have submitted an idea this will be reviewed by our product management team for possible inclusion in the future so please consider you know submitting an idea on the idea portal or searching for one and and clicking the upvote icon which you see there on the screen so our call to action here for you all today is are five things right we want you to Champion the creation of a ccoe with inside your organization if one exists already great um you know somehow see how you can have servicenow play Within that technology uh you know to help that team better manage your and you know and govern your cloud number two is you know we'd like you to start using these products in sub production right try them out see um if you feel they'd be of value to your organization and then of course once you try them out we want you to go ahead and showcase what you've you know that value back to your stakeholders right get them excited show them how these products can help and you know help drive better you know management of you know for your ccoe and of course we are here to help as well so drop your comments on the Community page reach out to your servicenow account teams have you know RAM and I as well as many others here at servicenow are happy to help and then finally you know we'd love to hear your success story uh and it's not just about the products we've shown here today any products that you are you know seeing value with that you want to talk about whether it's Cloud Discovery tag based mapping tag governance Etc please let us know and we'd love to you know you know to reach out and have a deeper conversation about that um so as I mentioned earlier in the session today we do have sessions planned once a month on the third Tuesday of every month we're going to be shifting gears next month and we're going to be focusing on it Asset Management how itom visibility products will help you streamline that and we have a panel of presenters here to help you better understand how our products can help you in your asset management Journey but with that said I don't see any further questions in the Q a so I just wanted to thank you all for attending today and please attend you know future sessions let us know if you have any questions and we look forward to seeing you again in the future thanks everyone

View original source

https://www.youtube.com/watch?v=pXRk_NbnunY