logo

NJP

Platform Privacy & Security Academy: Introduction to ServiceNow Vault

Import · Oct 26, 2022 · video

all right good morning everybody we are uh we just opened the webinar so we're letting a few people uh start to flow in here so we're gonna go another minute or so before we get started on things see this is that awkward period where people are joining and uh I don't know like we should have Mike and for cot like beat boxing or something just to let people know that their audio is working that's right some low-five beats or something yeah right Mike is good at that okay that's right all right it's 1101 and I do want to start things on time uh we do still have some participants that are coming in um and um but you know we've got a little introductory material here at the beginning so I think it's okay for us to get started now so good morning everyone my name is Kevin Thompson and I'm one of the outbound product managers for the platform privacy and security team here at servicenow I've worked in the cloud security space for about seven years and I'm really excited to be talking to you about our new product offering servicenow Vault Vault adds a lot of cool new features to help you meet your privacy and security compliance requirements and prove that compliance to your Auditors I'm based in Minnesota and since I'm surrounded by all this natural beauty I spend a lot of time outside with the local Boy Scout Troops and I've brought along a couple of friends to do most of the heavy lifting for this webinar so with me I have Mr Mike Salem Mike Salem is an outbound product manager on our platform privacy and security teams he spent more than a decade working across delivery solution Consulting and product management in the SAS industry and whenever he isn't thinking about the latest enhancements in privacy and security you can usually find him somewhere in the Rocky Mountains snowboarding hiking or just generally being outside and for Kat Salim is also an outbound product manager on our privacy and security team he's been working in the SAS industry for almost a decade and is primarily focused on AI machine learning conversational interface and security related domains and you can typically find him hiking running playing soccer or on the tennis field so we have a very outdoor focused group of technologists here let's go to the um to the ever present Fair Safe Harbor slide here so so as always we have to start by reminding you that we might talk about things that are on the product roadmap and since we are a publicly traded company There are rules about making forward-looking statements so we just want to remind you to please make your purchasing decisions based on the product as it exists today all right let's have a look at the agenda here so in a moment I'm going to hand it over to Mike to do an introduction to Vault and the various components involve highlighting each of the respective elements of solution we'll work in a demo of some of the Vault Suite features and talk through customer engagement channels and while they're doing this I'll be watching the chat to see questions coming in and we'll have a little QA and Survey at the end of the webinar and so with that I'll turn it over to Mr Mike Salem to take us through the Vault Suite Mike thank you very much Kevin uh so we're going to look at an overview of what servicenow vault is uh we'll give you some high level information about why we created something like Vault and then we'll get into uh some conceptual examples of what each of the components within voltar and how they work so why don't we start with the why um there's always been a sort of tug of war between security and usability within the SAS ecosystem in the early days of software as a service you know people were just wanting to put any data in the cloud you know where to even start what's that first project or the first way to think about moving workflows to the cloud uh and then as people started to experience the benefits the scalability the efficiency Etc they wanted to start to do more with SAS and what they found is that as they wanted to do more with software as a service they also needed to have a tighter eye on how that data was being protected uh how it was being secured what privacy controls they had in place and more and in many cases the types of data that customers of ours are now wanting to do uh now wanting to store with servicenow are also protected in different ways you know maybe it's by certain government regulations or certain industry standards or even internal I.T policies and so that means as a company we service now are at an intersection of providing Advanced capabilities for sensitive customer data while also continuing to deliver on the functionality that they need from us and so that's what brings us to servicenow Vault you can think of it as our Marquee security enhancement Suite that's intended to provide additional layers of security and privacy capabilities for the now platform and it consists of five key security elements the first is platform encryption which allows organizations to comply with mandates to encrypt sensitive data and we provide a native standards-based data address encryption capability with customer controlled key life cycle the second is data anonymization designed to help customers ensure data privacy by classifying and anonymizing specific data fields containing personally identifiable information the third is Secrets management which is used to securely store and control access to credentials Within servicenow the fourth is code signing and you know some of our customers employ a mid-server to run sensitive operations on their Network behind their firewall and anything running behind the firewall needs the highest levels of trust and with our code signing feature customers can ensure that programs running in their digital safe space come from a trusted Source from us and haven't been altered you know even if they are experiencing some sort of of uh change in the scripts or the the configurations that are running across that mid server and finally we have the log export service which improves security threat monitoring from servicenow with easy integration of our system logs our audit logs you know our transaction logs node logs Etc uh into those larger Enterprise security analytics systems that many of our customers are using today so those are the five components of vaults we went over you know high level conceptual of why we're coming out with a bundle like this you know as customers want to do more with servicenow they're also having a a tighter eye on how that data is being protected and managed in the cloud as they move new workflows and and uh you know new types of processes off maybe Legacy systems or other types of systems into a cloud environment like ours so between myself uh and forgot we'll go over a couple of these components uh in more detail we'll also see a quick demo of how to think about these various components within different types of workflows we'll look at a financial services operations workflow and then we'll get into some of the Q a that Kevin talked about at the beginning so I'll keep going with the first couple components and then you'll see me transition it over to for Cox the first component that we'll start with is platform encryption and so this really addresses the key customer need of balancing how customers protect and share data in the cloud by ensuring that servicenow data is encrypted at rest also with only authorized users who can access it it consists of two encryption products Cloud encryption and call level encryption Enterprise otherwise known as CLE Enterprise for short and we'll look at some of the underlying fundamentals to understand you know where the value lies and some of the differentiators are for platform encryption specifically so you know very high level in general we can think about how customers use their devices to log into a servicenow instance and they do this over the internet and an instance is generally comprised of applications which are all storing data in a database and so when we think about encryption encryption can generally be applied at either the application layer by a proxy of some kind or the database layer or both and when we think about public Cloud infrastructure companies they're usually providing encryption only at the database layer they only support you know what's considered behind the scenes that end users aren't directly interacting with like a database for example and the problem with applying encryption only at the database layer is that when the data is passed from the database back to the app to be used by actual people it's decrypted you might also hear this just being described as transparent uh and you can see in my instance that I have up on the screen here that we can see all of the data this can be a problem for customers end users that are concerned about the security of their data when it's actively being used and not just when it's sitting in the database by itself there's also third-party vendors out there that have app layer or you know proxy level encryption Solutions but an industry-wide issue you know with some of these third-party vendors is that encrypting the data in the application results in Breaking automated functionality that needs to work with that encrypted data in that application so let's take another look at my instance that I had brought up a second ago and think about it if you're if you're running a report that needs to group records by date and maybe it's a customer service app and you're trying to proactively reach out to all customers in a certain region but the address fields on the records are encrypted then the report won't know how to accurately group that data this is an example of how sometimes that app layer or proxy based encryption can break the app functionality and so servicenow is actually in a unique position to offer both app layer and database layer encryption that doesn't break functionality this is sometimes where you'll hear from us talk about how how our platform is encryption aware you know we can work with the system and the logic behind the scenes while also giving it the necessary protection that we need to ensure only authorized users are able to work with this data or not so let's look at how Cloud encryption and also CLE Enterprise provide the capabilities in an example like this one so Cloud encryption works at that database level meaning that all data stored for the customer instance at this level is what we call encrypted at rest the protection this is giving is similar to our older products like database encryption or full disk encryption and that means that if a hard drive was you know let's say physically stolen from a Data Center and if someone tried to plug that hard drive in outside of our data center then that data would be encrypted and unreadable and so this is great for protecting the theft of a physical piece of hardware however it does not give any additional protection inside the app itself if somebody is logged in and so that's really where CLE Enterprise comes into play it encrypts data within the app can customers can configure who should see that encrypted data or not so if we look at my instance again we can see in this green highlighted section that certain information has encrypted in parentheses if you look at those field names this means that you know I'm currently logged in as a user that's explicitly been given higher level privileged access to this data in the app but other users that haven't been given that explicit higher level access would not be able to see what we call the Clear text value of this information the additional benefit of Sealy Enterprise is that the data stored in the database is also encrypted so customers of servicenow uh they're using CLA Enterprise get the value of app level and database level encryption when they're using a single product like CL Enterprise the difference here though is that the benefit is only for specific fields that customers have applied CLA Enterprise to like what you saw in my instance example it's not all of the data like what we get with Cloud encryption but it does provide additional controls to restrict what information can be seen by people logging into an instance and in many cases even by our own servicenow employees and so this is called a layering or a defense in-depth approach by applying both Cloud encryption and Sealy Enterprise together customers get the benefit of protection for all data at rest in their database with additional app layer protection for those extra specific extra sensitive fields and for where they're additionally concerned about who from their end or maybe even our ends can access that data both of these also have customer managed encryption keys that they can control from right inside their instance with no need to interact with anyone from servicenow and finally remember that another differentiator for Sealy Enterprise with servicenow is that we can do this app layer encryption while still allowing those encrypted fields to work with app functionality so now let's get into Secrets management which provides Advanced protection for credentials on the now platform Secrets management reduces risk and increases compliance with tightly controlled access and Secure Storage of credentials but to get a better understanding of what this means and why it's important let's take a look at what secrets are and how they're used customers use servicenow for a variety of business and Mission critical reasons and they also have other systems doing important work as well and typically users want to integrate servicenow with these other systems to drive productivity and collaboration and to share data back and forth and we can do this using tools of ours like automation engine or the mid server and to enable these Integrations this is where secrets and also apis come into play an API or you know application programming interface is a piece of code that allows two different systems to communicate with one another to share data essentially and a secret is something that allows one system to authenticate into the other when you log into servicenow for example you typically have a username and a password and those would be considered secrets well when service now has to integrate into other systems there's a similar process in place to allow servicenow to authenticate into these other systems and so a secret is what allows servicenow as an automated system to log into these other applications they can be things like privileged account credentials think of admin level usernames in this case they can be passwords certificates SSH Keys API keys and more and this is really convenient to have stored in the cloud because it makes the Integrations seamless and it's the underpinning for what drives a lot of productivity at the system level but a risk you know of the cloud in general and this goes for any vendor any piece of software is that if the concept of least privilege isn't explicitly enforced then an otherwise authorized user inside of a system could potentially go and read credentials directly and then use those credentials to go log into other systems also directly which in theory would allow them to bypass the SAS provider altogether that SAS provider that legitimately needed those credentials in the first place for that application that they were working with and so this is an example of where you know in the cloud we get the concept of Secrets leakage meaning if those Secrets got out then the systems that they're used for are also considered more vulnerable and this is where security teams that we interact with on the customer side will highlight that sometimes there can be a conflict between app functionality and app security they want to know how do we drive productivity while also ensuring the right controls are in place to keep things secure and if you think about how many apis and Integrations and secrets exist in the world already you know we wouldn't fault these security teams at all for feeling somewhat nervous about wanting to ensure that they have the proper Secrets Protections in place because without these protections this is where we can see security teams sometimes blocking Integrations and you know even these perceived productivity gains because they don't believe that the proper protections have been put in place to enable the types of productivity that end users actually want which brings us to the value and overall differentiator for servicenow Secrets management so when using these types of features customers can encrypt item discovery and integration Hub credentials ensuring only elevated and privileged users have any kind of access to that credential they can configure granular row level access controls for the secrets which this might seem like not as big of a deal but it's actually a new area of enhancement for access controls with servicenow we can use what we call secret groups to enforce least privileged access to Secrets this means that customer security teams can segment for example who's managing the integration credentials uh for an HR System like maybe workday separately from who is managing the credentials for procurement and Erp systems you know another new area that servicenow is moving into and so customers store quite a bit of very sensitive credentials within our platform and this solves a long-standing customer security ask of us to provide even deeper levels of access controls for the secrets stored on our platform and finally they can also ensure proper management and protection of the encryption Keys themselves by using our Phipps 140-2 level 3 validated Hardware security modules or hsms this means the hardware that we have in place to manage encryption Keys is tamper resistant and requires identity verification before any maintenance can take place this ensures that the key is customer used for encryption with servicenow are safe and finally we have an industry leading capability for item discovery customers also have the option of using client-side encryption of the credentials before they send them to servicenow the takeaway for this is that customers who want the absolute maximum level of control over their encryption keys that they're using here basically ensuring that you know servicenow or or anyone else is never in the loop of helping customers to manage them can do so for their itom Discovery use cases so to recap on Secrets management uh you know a password is just one example of a secret also known as a credential that are used to authenticate the right people and machines and since Secrets give access to apps and data securing Secrets is a big part of securing access to data which is always top of mind for our customers and with our secrets management product it not only enforces the policy at least privilege for example users only have access to the secrets that they're entitled to it can completely remove all risk of the secret ever being exposed to servicenow which is also top of mind for many of our customers so the last component that I'll go over before turning it over to forcot is code signing and code signing allows customers to configure digital signatures for data and operations and so this means that customer admins can maintain software integrity and ensure there hasn't been any software tampering of any kind and they do this by verifying the code that gets run on the mid server and ensuring that it's coming from a trusted Source you know from from us essentially this improves the overall security posture of servicenow in our customers eyes and so to understand why this important let's look at how the midserver works today a servicenow mood server is an application that's installed behind a customer's firewall in their I.T environment and it communicates with a servicenow production instance in the mid-server's benefit is that it allows servicenow customers to manage parts of their it operations and assets using their servicenow instance as that management Hub so an example of this could be a customer issuing a command from a servicenow instance to go and discover IP addresses for it assets connected to their corporate Network the command could come from servicenow travel to the mid server and then the mid server would perform that action in this example reporting IP addresses for it assets back to that servicenow instance so this is great from a scale and efficiency perspective but customer security teams you know can sometimes understandably be nervous about this capability because what if somebody accidentally or even intentionally sent a command across the mid server that could do damage to a customer's environment in some way for example if you follow this red line a command to drop a table from a database would most most likely result in some sort of data loss which could material affect customer operations and generally you know just cause Mayhem within an I.T environment you know as they work to bring that table back and so this is where code signing can help let's look at a quick example of how the process works we'll start with our trusted customer service now admin there at the bottom uh and a sub production environment there on the top left and so this subprod is one that should be specifically protected um to be used with this code signing feature specific protections might include things like restricting the number of admins that can access this instance it could require adaptive authentication features from the now platform it could allow only approved IP ranges you know and and more all kinds of things but but really it should be considered special and strongly protected by the customer to support these code signing features and so with the code signing feature the The Trusted admin can load a cryptographic key into this trusted environment the co-signing process with that key would also create a digital certificate that gets stored on the mid server and you can see the certificate Illustrated in the top right hand side here and the certificate basically is a way to check and compare the trusted admins identity and that cryptographic key so this creates a trusted link of sorts and I'll give a high level explanation of how all this works in mathematical terms let's say that the combination of The Trusted admin's identity and that cryptographic key equal to value of 0 1 0 1 1. the certificate that gets stored on the mid server would also equal zero one zero one one so then When an Admin wants to send commands uh to use our you know our Discover IP address example from earlier our code signing feature essentially adds the zero one zero one one to that discover IP address message and again these are just you know conceptual examples to explain the concept so this is what's known as signing we're digitally signing the message to have information showing that it's coming from a trusted source then the message can be compared with what the receiver the end with the certificate is expecting to see if the value received matches the expected value then the message is considered value with the con or valid excuse me with the contents of the message being verified as unchanged since the message was sent by a sender and then after it's been uh verified the message itself can continue to its destination and in this example discover IP addresses but if the digital signature was missing or was different from what the receiver expected then the message would be blocked and would not allowed to be run a mismatched or missing signature could happen if the person sending the message is different from the intended trusted sender or if the message has been changed from when it was first sent or or even if the message was sent from a non-trusted environment one that lacked that initial cryptographic key loaded into it for example so then we can look at how this concept actually works within a customer environment working between subprods and products at the top here we have our sub production instance with that cryptographic key and then we also have that production instance that is connected and Performing operations with the mid server if you follow the green arrows you can see that the trusted admin inserted a discover IP address command into that subprod environment it's been signed with the cryptographic key representing both a trusted person and source and it's now traveling through the production instance to be sent to the mid server and because the mid server can validate the signature with its own certificate the message is allowed to pass through to take the intended action in the customer's environment and discover IP addresses of end users computers but now let's look at what happens if a non-trusted admin or worse a malicious person of some kind tried to send a destructive message across the midsummer returning to our drop tables example we can see a non-trusted admin inserted a a drop table command to be pushed to the mid server and there's a couple things that are initially wrong here first the sender is not a trusted admin um and second since the production environment lacked that cryptographic key there's no way to sign the message so when the message arrives at the mid server it's unsigned there's there is no signature so there's nothing to compare that certificate to and the message is blocked If the message came from the production instance and had a signature from the cryptographic key the mid server would still block the message since the person sending that message was not one of those trusted senders and if the message had been changed after it was created before it reached the mid server um you know being exposed to tampering of some kind then the message would still be blocked as well and because the signature and certificate don't match then that the malicious or altered or tampered code in some way that was trying to be inserted into the mid server wouldn't run and so this is an example of protecting the customer database from that drop table command so we've reached the end of the co-signing example in this introductory introductory overview and we've seen how co-signing can be used to maintain software integrity and ensure that there hasn't been any tampering we would do this by verifying the authenticity of the person and the message that's being sent to run on the mid server and this improves the overall security posture of servicenow in our customers eyes so that was a a quick overview of three components of alt we went over platform encryption we went over Secrets management and we talked about co-signing and now I'll turn it over to for cots to cover the last two components thank you Mike Awesome I like to share my screen and let me know if you guys can see it everything's clear Mike uh yes we can see it okay thank you in this session I'd like to go over servicenow data anonymization and why service now data anonymization is important as well as why it's different from the other three major components of Vault bundle that might explain earlier as well so first of all I'd like to explain why and what is servicenow data anonymization serious not data anonymization provides a tool to enable data privacy by classifying and anonymizing specific data fields like pii for example to ensure the privacy of confidential data and increase Regulatory Compliance now let's get into data anonymization which gives you the ability to redact sensitive information in your instance take a look at these two different version of mobile app the image on the left has original data as it was saved in the app and the image on the right has anonymized data and there are a few benefits and Main use cases as well foreign there are a few reasons why we need servicenow data anonymization first and foremost minimize the risk of information leak as we all know companies are organizations are growing their businesses with customers and they use more application and customers data to run the business with better customer services at the same time they tend to collect more customer data which might contain some pii and other confidential information that shouldn't be exposed to public servicenow data anonymization really helps customers an organization to classify and anonymize sensitive data within servicenow instance to minimize the risk of information leaked to outside the second benefit increased complaints there is an increasing number of sensitive and the Privacy regulation being created and managed by governments and organization around the world according to statistics 71 percent of the countries have legislation and nine percent of the countries have already drafted their legislation to ensure user data privacy to comply with right to be forgotten request for example gdpr one use case is for gdpr right to be forgotten request let's say an employee leaves a company or a customer of ours has their own customer think customer service management for instance where they need to anonymize customers data with servicenow data anonymization tool you can select the user and anonymize pii associated with that user in a production instance and of course this is low code and no code environment as well the third benefit optimize security for Developers delegated development in a customer's software development life cycles or sdlc the production environment has all the real data including pii and in order for these other instance to be used properly they also need data most often copied from production in order to provide the most realistic way to test new configurations but if we copy information from production that usually means we're also copying pii and other confidential information and exposing it to development teams that may not need to see it or that actually shouldn't see it these Dow team in these other environment can be ftes of the company themselves where they could be third-party contractors working outside of the company or even the country that the development is occurring in and so working outside of the company or even the country that the development is occurring in and so uh the customers can use data anonymization to natively de-identify the pii associate with the information they're pushing down into these lower environments this ensures that these subprods have the legitimate data that they need for configuration and the testing without exposing information they shouldn't be exposing outside or production environment the fourth benefit elevate your brand which means increase trust with your customers by ensuring security and the privacy of the sensitive data the last component of Vault bundle as we call a servicenow log expert services you know what is servicenow log expert services or we call it Les servicenowlog expert service is a servicenow tool that allows users to export various types of logs quickly effectively and safely to other systems for monitoring new now platform security posture uh user experiences and performance with your Enterprise analytics solution it has three main benefits and other use cases Associated as well the first easy to set up with no additional coding needed the second highly scalable and near real-time integration with Splunk and the Kafka connector the third reduce complexity and increase efficiencies by exporting only the data needed and there are three main use cases why we think Las tool is B uh applicable the first the tax service now security threats and analyze security incidents second troubleshoot and optimizers now add performance the third Monitor and optimize service now user experience let's look at what life was like before and then with log expert services before log expert Services if we take a look at for example on the top left we have service now instance with all different logs like system logs transaction logs and note locks and all of them are terabytes of volume in the bottom we have local manual machine where we can export the data on the right top we have our analytics tools like spline where we performed the analytics process so the old way to do it is basically we need to use our local machine through the servicenow instance to export the data and the load the Joby environment and then re-uploaded it to the analytics platform like a Splunk in order to conduct analytics process because these files are being stored on the customer's computer or networked file server they have to usually write some sort of custom integration to automatically insert those logs somewhere else the custom integration had to be monitored maintained and upgraded and usually customers have challenged finding otherwise busy resources in their organization to create these or they have to pay system implementers to create these as well and extra costs aren't ideal or maybe the format that service now generates the logs in might not be the same format that is needed elsewhere so a customer might need some sort of additional tool to alter the format in some way before inserting the log data into the other application this is known an ETL process extract transfer and load all of these issues result in added overhead for the customers to manage with increased probability for uh ears wasted time and money and outdated information as well the outdated information is a huge problem because the customer's security team feel routinely in the dark about what is going on in their servicenow instances they don't need to they don't have the right information at the right time to be able to connect to the dots across their entire I.T landscape and how servicenow is being used or is affected by the other system they have in place which bring us to our log expert services on the right as we see with the service now log expert Services we have a similar uh the the example here for example we have servicenow instance with all different logs and also we have a customer Kafka based tool like Splunk so with this method instead of customers downloading logs locally to their environment and them figuring out what to do with them next customers can simply figure a configures log expert services from their instances to publish logs in near real time as they're created after servicenow is publishing logs then they can configure their tool on the other side to subscribe to those logs and since Splunk is one of the most used log analytics platform we are using their pre-built connector for Kafka and we plan to connect to more application in the future as well this new approach solves for the pain of the old way that Les can be automated instead of requiring manual steps it's near real time instead of having at least 24 hours delay and it is scalable for customers who wanted to export terabytes of data continuously with that I'll turn over to Mike for for the demo awesome for God can you just go one slide forward one slide past and I'll share my screen here in a second sure thank you um so we typically you know after we go over the high level concepts of what's included in servicenow why or in service not Vault why we built it uh Etc generally people want to see it being used you know within an application of some kind and I showed a couple screenshots earlier in my platform encryption example uh but what we found is really you know the the value of servicenow Vault is how these components are woven into uh you know a workflow or a you know an application you know through its DNA um how the servicenow Vault components augment uh or better protect you know other things that customers are doing with servicenow and so to show an example of this we'll actually look at a financial services operations workflow uh specifically we'll look at a client onboarding process and we'll look at how those three components that are highlighted in Green platform encryption Secrets management and data anonymization can help you know uh supplement this client life cycle onboarding process within the fso application and that's really what we want to have the takeaway be for a lot of these types of demos is you know the value of these components is how they support the other things that customers are wanting to do with service now so we'll look at those top three and let me share my screen thanks Mike yeah okay for cut can you see my screen on the left okay yeah perfectly okay so just to kind of set the stage here I'm logged in as Evelyn you can see there in the the top left I'm logged into a financial services workspace uh Evelyn is a relationship manager and I'm going to start onboarding a new client so I'll go ahead and click on one of my cases that I want to work on and my first task is to create this client within servicenow uh you know in the past I would probably have had to go in and fill all these fields in manually um but rather than manually entering all this information for now I'm also going to use our powerful integration Hub integration to populate this relevant information uh from an external Source instead of having to to manually type it in all on my own so I'll go ahead and click get CRM data and then since integration Hub is pulling in lots of of sensitive customer information like pii um you know my security team wanted to ensure that these Integrations are protected so first let's look at the columns within this add customer information form we can see that the left hand columns have encrypted in parentheses and this is showing that our platform encryption features are in place protecting the sensitive information ensuring that only users within you know the company like myself who've been granted access to see this data can see it while also allowing this information to still work with these Integrations and so the data is also encrypted inside of servicenow and this is providing an additional control point for customers who could be concerned about who either on their end within their instance or even on our ends might be able to have access to this information so this is just one quick example of augmenting or supplementing a client lifecycle onboarding process encrypting the data as it's being passed into servicenow and also showing that we can use we can work with integration Hub and Integrations while also encrypting this information within the app but now let's also look at a difference a different person's point of view I'm now logged in as a different admin who's responsible for configuring things behind the scenes you can see that my screen is is highlighted at the top with the red bar indicating that I have elevated privileges in this instance and so uh you know as an admin I can see a list of clients that Evelyn had just recently created uh the reason you're not seeing any data in these columns however things like first name last name date of birth Etc is because this particular admin doesn't have access to view that encrypted information within servicenow and so this is an example of how with column level encryption Enterprise we can start to implement separations of Duties we can start to segregate admins from being able to do the configuration and testing that they need to do without also being unnecessarily exposed to sensitive information so now let's get into the second uh product that we'll go over the second feature within servicenow vault which is Secrets management and I'll I'll get into this by showing an example from Flow Design so here we see flow designer where we've configured that integration Hub data that's been coming in Secrets management is providing better protection for that pipeline between servicenow and that external CRM spoke and you know again we'll sometimes we'll be asked what do we mean by a secret well if we think about you know passwords Integrations between machines have digital credentials including things like certificates and keys and all of these need to be securely managed to better protect these third-party systems so let's look at how that gets configured and I'll just flip over to a different screen here this screen is where customer admins manage What secrets or credentials they want to protect related to that CRM integration that we saw being automated through flow designer and what we're actually configuring here is to protect the authentication key in the auth 2.0 credentials table and we want to use the secret group for the authentication keys that have that name CRM in them so we can start to set different protections around different applications of Secrets and this is also how we can start to implement the concept of least privilege with who can see and manage these secrets you can start to set up secret groups you know for people that are managing the let's say the HR Integrations as compared to people who might be managing procurement or customer service Integrations Etc so I'll just go ahead and click submit to send this one through and the last feature for this quick you know high level demo that I want to end with is data anonymization so to set the stage here we've switched back to Evelyn Johnson our relationship manager and instead of onboarding a new customer let's say that that same customer Mike Salem has decided to off-board from their service and so they've requested that Evelyn's company remove any personally identifiable information associated with his account to start this off-boarding process so Evelyn can go up to all if I can click on it and she'll find her data privacy application her data privacy module and she'll go ahead and click on anonymization and because Evelyn has servicenow Vault she can easily run a data anonymization job she can go ahead and click on the pre-configured gdpr right to be forgotten job and when she clicks on schedule job all she really needs to do is put in her description when she wants that job to run and who this job should be for in this case it should be for Mike Salem because he's the one requesting that that data be anonymized as part of a softboarding process so then Evelyn can click schedule job and just like that Evelyn has used servicenow Vault to help de-identify the pii related to this customer who has left their service and so this can similarly be used uh in sub-production environments clones uh to quickly automate the replacement of any sensitive or classified data from any sub-productions or you know third parties or development teams that shouldn't otherwise need to see it so that's an example of how Vault helps customers give more privacy and security controls over the data in their cloud and I'll just pause there Kevin do we have any questions or anything in the chat as I switch screens uh let's see um so one question was uh will this recording be posted anywhere uh that one just came in and uh for Kyle I'm gonna ask you do we I know we are recording um do you know how we're going to distribute that recording yeah I will I'll just hear my screen and just kind of like go over that what is available for us right now uh how we will be reached out as well let me share my screen and just go over that thanks thanks Mike for the demo thank you so to that question so what is available right now so we have social media platform uh we have YouTube channel uh on the platform privacy and security where we will produce all the contents and upload all of them uh including Academy session uh not only this but also all uh the incoming Academy session as part of YouTube channel as well so if you're having trouble to find it just basically type service now and then you will have I think to the three different channels pops up and then just you'll you know just uh or just kind of like put uh platform privacy and Security Vault demo and you should be able to see uh uh all the the content that we will be uh adding as well so that this particular session might be uploaded within two to three uh business days by Friday and then uh hopefully you'll be able to see that as well so the second one that we have is just uh the registration link uh that we'll be sending you through email uh this recording will be part of that uh the the email as well that after this session I will do follow-up email to just send you the recording where you can find it and then how will you just benefit through this as well and we have a developer content sessions coming up as well so we will have different team uh who will be conducting some developer content section session for uh how some of the technical enablement works for Vault and some of the area that we need to be careful in terms of what you know Mike has just demoed on all the you know the world components for platform you know uh uh encryption as well as data anonymization or some of the secret management co-signing as well as log expert Services area that we have technical uh kind of like discussion sessions coming up as well you'd be reached out to that through email at the same time time that'll be posted to our YouTube channel as well third one the documentation side we have a product documentation where you can find all the plugin features for how the world specific bundle works and some of the you know kind of out of the box plugins or some of the uh the plugins that are required for you to install manually so we have a step-by-step you know well-documented process there on the product documentation site I know we have a platform security uh the community site that we're currently building and it should be ready by uh next week and then you will see all the agenda item uh in terms of Vault and overall the platform security team what are the sessions which is coming up with agenda and then you know kind of like the uh the date that we're hosting each session with all uh the registration link uh uh uh the uh as well so the last but not least we have service now.com website where you basically just log in and then uh it kind of uh just uh find Vault components and some of the uh useful information there as well so these are all um you know what we have so far uh in terms of how you will reach out to us what is available some of the documentation resources that we can share with you does that answer the question Kevin I believe it does yes and now we can uh while we're uh just having NQ a just if you have any questions feel free to post your questions on the channel at the same time we're prepared uh a quick survey for you to conduct that uh if you don't mind I'll send you the link and then just click that there's just very three questions that for you to answer in order for us to just perform better as this is our first Academy sessions uh that we're going to be conducting more in the future as well so that will help us to just uh kind of like uh uh take advantage of some of the area that we've done really well and some of the things that we missed as well for our incoming Academy session as well I'll send you a link uh on the Q a in session all right and in the meantime I do have a couple of questions that I uh composed to for cot and Mike so one of the questions that's come up is we have a fair number of encryption products here at servicenow right between Edge and we have a product called database encryption can you explain just a little bit what is the difference between the platform encryption bundle versus say database encryption because you know the name database encryption just seems to imply that that's that's everything I need what is platform encryption bundle bringing to the table that's different yeah that's a great question um you know the name database encryption is both sort of like uh where it sits in the technology stack and also the brand that servicenow had just happened to us given that product uh historically but really what what platform encryption is providing is that layered approach with two different encryption products aimed at two different use cases so platform encryption being a bundle in and of itself provides Cloud encryption which is servicenow's newer more modern uh version of what was historically being offered through that database encryption product uh it provides customer controlled Key Management from within the application um and has some additional benefits as well and then platform encryption also provides uh you know through that bundle the entitlement to the column level encryption Enterprise product and so that's where we get that additional layer of of control point in the cloud for protecting not only the data within the database level but also in the application itself so this is primarily used for extra sensitive Fields where customers want to make sure that they have more control over who can see it when they're actually logged into an application not just you know is it being protected in the right ways while it's sitting in our data center and so really that's the difference between just that database encryption product and then that database encryption product is only providing one of the two things that platform encryption provides uh and it's it's from our perspective you know the the older version of it that doesn't have um the enhancements that we put towards Cloud encryption and I'll pause there yeah absolutely so um a couple questions about data anonymization so uh you know kind of an obvious use case for data anonymization is in the sub prod environments where we don't want the you know maybe sensitive customer identifiable information getting into subprod where you might have lesser controls or anything but um can that also be used to redact information in prod as well or is data anonymization only for sub prod yeah it can be used in prod as well so uh the one product from servicenow can be used to redact information both in prod and in sub prod and that's something that we've been you know pretty focused focused on from a value perspective because what we've seen in the market is that you know other other SAS companies that are out there depending on what type of environment you might be working in whether you're working in the production environment or you know some sort of lower lower environment you know different companies call them different things um that you you actually need to buy different products there's other companies out there that have different products aimed at depending on which environment you're working with and so a differentiator for for servicenow is that we have the one product data anonymization and you can use them across all the environments that you have okay uh let's switch well yeah I got one more data anonymization question do we have any plans of offering data anonymization um a la carte for say our self-hosted customers and um so there's kind of two pieces there right are we ever going to sell these products a la carte and number two how well do do these fit for self-hosted customers and I think data anonymization in particular is one that is uh particularly relevant for self-hosted customers I would say that right now we don't have plans to do that and that doesn't mean that we won't ever do it it's just you know this this product has now been um you know GA for a month so we haven't really uh worked into where we would put that into the product roadmap or anything so um but I will absolutely take that feedback back to our product managers as a thing that people are interested in but at this time we don't have anything on the roadmap to offer data anonymization a la carte for self-hosting customers um I'm gonna switch I got a question here so you can export logs using a mid-server and so one of the questions I have here is just kind of talking about the difference between exporting logs using the mid-server versus the log export service in Vault can you talk a little bit about that difference uh that's a good question I can see who asked it and you know there's some some nuances and some different details versus how you're working with the mid server versus the other ways that we can export logs so for this particular one I just want to follow up with the the asker um I can get some more information myself and then we can make sure to get the right answer and then another question was how do we who do we engage with to do demos of this offering is this available for SCS to demo uh it is um so you know there's there's various ways that you can demo it you can solve from you can see from some of the examples that I gave um you know a demo could be focused on the configuration and setup of a feature uh sort of behind the scenes from an admins perspective or it could be demoed from the perspective of an end user um you know like we saw with Evelyn uh in the client lifecycle onboarding app and kind of seeing how these various fault features are sprinkled uh into the narrative that uh that she's demoing so we do have resources internally if there's SCS that want to learn how to demo this stuff feel free to reach out to us we can point you in all the right directions hey we don't have any more questions that have come in I do want to remind everyone to please click on that link and do the survey so that we can do a better job on these in the future make sure that we're delivering the kind of content that you want to see the kind of content that is helpful for you that is how we can make these better so please by all means click on that survey and I want to say thank you on behalf of myself on behalf of Mike on behalf of for thank you so much for giving us some of your time and some of your attention to talk about this product and I hope you all have a good day with these uh extra four minutes that we're getting done early here um I appreciate all of your time and attention thank you thank you all appreciate it thanks Mike thanks Kevin

View original source

https://www.youtube.com/watch?v=Q8jkuy7VVsI