Optimize and Orchestrate Enterprise Security Operations
hello today we'll be looking at how servicenow helps security incident handlers tackle their work far more efficiently and effectively than ever before we'll start with the big picture and then dive into the key elements of the solution it is typical to see a 40 to 60 percent reduction in time to resolve security incidents when converting from more manual and disparate handling processes when results like these are achieved our customers can use dashboards like this one to report upon their status first we'll be assuming the role of the ciso of our organization Andrew Lim the security operations efficiency dashboard here is one of several included with security incident response here we can see big picture Trends and break them down by aspects such as analyst efficiency and group efficiency and here on detection and response Effectiveness tab we can see true detections versus false positives or by incident source or what business risks exist over time here on the incident risk score analysis tab or perhaps by incident stage here on the security incident stage analysis tab for example mean time to analyze contain eradicate recover or review of the incidents are automatically tracked and displayed here users can also create their own reports and dashboards too our customers appreciate the ability to build dashboards for their teams in leadership this custom dashboard is a great example of what can be rapidly built using our GUI base report engine and drag and drop dashboards one of the advantages that servicenow has is the ability to bring together data from many groups to provide holistic insights across the board on this overview tab we have information from teams across risk policy compliance configuration management vulnerability response and security incident response dashboard tabs can be created to organize the data in this example the incident handling tab provides extra detail for different groups but they can be arranged and styled however any individual user prefers the now platform is now fully integrated with a miter attack framework for threat intelligence which can provide valuable insights that Security Professionals need to get work done better every day miter attack can assist Security leaders in managing Security Programs by helping them understand how the various defense systems are performing and identify where there may be any gaps the miter attack heat map and Navigator can provide immediate visibility into patterns where the department is seeing any concentration of incidents or is dealing with any relevant vulnerabilities it also provides a quick visual of the current security posture for detecting and defending against each of these attack techniques all of this helps the CSO understand where Investments of time and resources are most needed like we see here with regards to compromised software supply chain initial access issues here we're going to set up a filter group to show how the heat map and Navigator functions and the changes that occur as we set those filters watch the Heat Map change as we do so we're going to select display technique IDs display technique detection coverage and display technique mitigation coverage this is an extremely valuable resource when it comes to thwarting the attack patterns that impact and threaten the organization the most such as those from Advanced persistence threat groups like apt-29 during the solarwinds breach you can see as we add in this final data point of the known adversary group it draws in all the known techniques of this apt the CSO can drill down into each of these but moreover this shows the current organizational posture and defense against this known apt remember earlier when I mentioned supply chain now we can understand our detection coverage and our mitigation coverage for that particular TTP so you can see that we're getting everything in one place but you may be asking yourself how did we get here it all starts with Integrations there are out of box Integrations with security sensors and Sim platforms such as Azure Sentinel qradar arcsite logarithm Splunk and Splunk Enterprise security threat intelligence platforms are also very helpful for security incident handling saving analysts time with automated threat lookups customers can request these Integrations for their instances right from the store shown here for example we have our crowdstrike Integrations once installed these applications can be configured inside your servicenow instance by going to conf integration configurations some simply require API keys such as Showdown here while others have more options like setting a schedule or adding filters to the data that we want phishing emails come in a variety of different forms and often they include a malicious attachment analysts can now submit malicious attachments for in-depth malware analysis using the crowdstrike Falcon sandbox integration the integration allows for both manual and automated submissions as well as a variety of other settings this provides the possibility for the sandbox submission results to be completed during the triage process and ready when the analyst first opens the security incident let's see how the platform helps incident handlers get work done faster and more effectively every day now we've changed our impersonation from our CSO to Adam Long our security incident Handler from here the analyst sees incidents that are signed to them or their team with customizable filters they're able to quickly navigate the pool and review automated triage details it looks like there's a new incident the analysts can take a closer look with Peak View this one has a high business impact a confirmed threat indicator and machine learning analysis requiring this incident be triage with a confidence score of 85 out of 100. clearly this one's important so the analyst opens it in a new tab and they can keep multiple incidents open at a time if they need to multitask while automations run it looks like this is a phishing report from Robert Smith in the old days the analysts used to have to watch an inbox and do all this triage threat analysis and calculate math risk manually but now when they log in all of that leg work has been done for them employees can simply hit a report fish button and their mail client or forward in a suspicious email and servicenow will do all of that work automatically in the overview tab the analyst has their favorite widgets arranged to do a quick look into the incident every analysis can personalize this tab and move them around as they see fit one of the analysts favorite tools is this similar security analyst widget which shows all security and Insulin incidents that have technical similarities to this one such as the same URL IP address file name file hash or email subject with the explore tab the analyst can dig into any of the details in the security incident such as who is affected by it in this case Robert Smith the first person to report this phishing email the analyst also benefits from deduplication in this case the email has been reported by a number of individuals seen here optionally do you duplicated reports can create child incidents instead if you prefer of the email headers are parsed out as structured data as well and these can be used in automation next the analyst takes a look at the email that has been reported and sees a familiar pattern go to investigation search email and deliverables these covid themed phishing emails have been coming in a lot lately parse observables end up here along with whether or not they are deemed malicious from threat lookups that have already run upon creation of the incident running these manually is also pretty trivial and the analyst doesn't need to be an expert in dozens of products to leverage all of his organization's threat sources thanks to the Integrations with servicenow here on the right we see the Playbook pane the analysts can see where they are in their team's security automation playbook for phishing response security incident response comes with dozens of flows like this one and these are configurable via a graphical editor and flow designer when tasks are created they end up on the right over here we can see where automated lookups were executed and completed again steps and any detailed guidance here are completely configurable making it easier than ever to architect and use security playbooks for example the threat intelligence orchestration we discussed has already taken place the person who reported the fishing incident was automatically contacted via email to thank them for their submission sometimes this type of work is less predictable so of course any of the automated steps we show can also be done manually in the UI in the case of sending an email we save time by creating templates like these to help facilitate this type of communication servicenow can send mobile app notifications text mess text messages and also integrates with messaging platforms such as slack and Microsoft teams now with these first automated steps have been completed and the analyst only needs to review and confirm the findings once they do the Playbook will take care of the rest finding and deleting these malicious emails across all users inboxes performing firewall blocks for phishing URLs and searching Sim and log platforms for any other potential victims these following actions are documented inside the child task the analyst agrees with the automated analysis so they complete this task to fire the second half of the Playbook well these steps are being automated in the background let's quickly peek at how they are done manually to perform a firewall block request we pick an IP or URL or other observable check the block next to it select block request and hit run we can select the tool that we wish to use this works the same way with citing search to find any matching logs and we can search for matching emails and delete them like this then results can be viewed here the only thing left for the analysts to do now is complete the post incident review here they can close out the incident they can use the proper close code foreign and add any relevant note these reviews allow analysts to provide additional data points into the post incident review which is automatically constructed and visible here on the timeline tab this can also be produced in a PDF form today we've looked at how servicenow is helping security incident handlers by providing a single system of record in action automating manual tasks orchestrating security processes improving prioritization with integrated threat analysis and business impact triage enhancing collaboration between security and I.T and providing big picture analytics necessary to track and improve kpis
https://www.youtube.com/watch?v=BD1C4JM3GzI