logo

NJP

Transform Security Operations with ServiceNow

Import · Nov 30, 2022 · video

foreign [Music] hello everyone in this video I will share some of the exciting things that are going on with servicenow security operations products one of the many ways we help our security customers is to provide real-time cross-functional visibility into their security posture security analytics are available at all levels of the organization providing operational insights across the breadth of the organization and we'll dive a bit deeper into this dashboard later on we also provide a broad array of everyday Automation and case management capabilities that serve to greatly improve security for the organization reducing Risk by moving faster and smarter is serve as now's core strength when it comes to the platform it's why most of our customers use our security operations products servicenow can help you make your organization security posture be more efficient automated and easier with tools like security incident response threat intelligence major security Incident Management and vulnerability response that work in conjunction with your security software and Hardware this is the major security Incident Management workspace major security incidents are different from everyday security issues due to impact criticality or severity and they require a great deal of cross-departmental collaboration the major security incident manager can coordinate and direct organization-wide incident response workflows from this workspace they also have access to the entire collection of tools and Integrations ranging from correlation platforms to DLP sensors this gives them the ability to see every aspect of the major incident quickly and easily creating a virtual war room to direct the battlefield this can result in reducing the average time it takes to handle incidents by up to 85 percent here we can see a new ransomware incident affecting the organization widely the overview of the major security incident workspace contains metrics that provide a quick live look at the major incident and its related components such as tasks duration incident impact and collaboration clicking on the details tab we can see records from both outside and inside the platform can be viewed and analyzed by teams working on the incident including which devices are impacted the linked records tab similar or related incidents can be linked to the major security incident as well as relevant threat Intelligence being supplied to the organization as well integration with file sharing platforms like SharePoint automatically create a centralized repository to store all the pertinent file artifacts for the major incident managers can perform a variety of file operations here such as creating or deleting files and folders and adding or removing user access live integration with chat providers such as teams helps everyone get connected and engage in whatever channel is most productive for them protected chat channels are automatically created for each major security incident moving to the status reports we can see that status reports can be dynamically crafted to keep leadership updated with minimal effort freeing up more time for working teams to address the threat instead of spending time on administrative tasks on the tasks tab we can see what each team is working on in security and in other departments for example our firewalls have already been configured to block the attacker worldwide analysts are reviewing threat intelligence legal and public relations are working on a disclosure statement in an effort to patch related log for Shell vulnerabilities is a work in progress a critical goal in this major incident is to ensure that there aren't any more systems that might be vulnerable to the specific attack servicenow's vulnerability response application empowers organizations to do just that many organizations still use emails and spreadsheets to perform the complicated and massive function of continuously coordinating vulnerability response between security and I.T and it can be an intensely manual and slow process by automating these processes we've seen customers reduce their total number of open vulnerabilities by up to 50 percent within six months of going Live While improving the experience of everyone involved here you can see the task from our incident to fix related log for Shell vulnerabilities vulnerability teams can set up Dynamic watch topics that focus on areas of interest and help coordinate remediation and Mass servicenow vulnerability response helps security and it teams work on vulnerabilities at a massive scale making it easy to find what matters and act on vulnerabilities in bulk the vulnerability response application provides a single system of action and engagement integrating with a wide selection of vulnerability scanners threat intelligence platforms and Patch management platforms to help reduce exposure and business risk quickly and effectively this includes remediation support for infrastructure container and application vulnerabilities as well as penetration tests your organization can also see all of the vulnerable items and the configuration items that are related to as well let's go back and look deeper into how we're doing in the related log for Shell patching effort and Remediation there are a lot of vulnerabilities to work on but here remediation effort has been started these efforts automatically route work to I.T saving a tremendous amount of time for the security team while also Expediting fixes once work is routed to I.T it is broken apart into these remediation tasks and large organizations this work can be shared across hundreds of different individuals or teams from there Ops teams have simplified views providing precisely what's needed to Target and deploy fixes or request exceptions even better we can now automate scheduling and delivery of patches through Integrations with Microsoft titanium and big fix moving things along even faster across security and operations we're making it easier to get important work done every day once the dust settles from handling security challenges both major and minor organizations can leverage our analytics to improve their security program our customers appreciate the ability to build dashboards for their teams and Leadership or use our out of the box content and pre-built content this CSO dashboard is a great example of what customers can build rapidly using our GUI base report engine and drag and drop dashboards as I mentioned in the beginning one of the advantages that servicenow has is the ability to bring together data from many groups to provide holistic insights across the board on this overview tab we have information from teams across risk policy compliance configuration management vulnerability response and security incident response dashboard tabs can be created to organize the data in this example the tabs provide extra detail for different groups but they can be arranged and styled however any individual user prefers here we can see this CSO likes to keep track of how incidents are being handled how well the it infrastructure is hardened and secured what are the biggest risks to the organization policy compliance and performance and costs and return on investment for the organization this gives your organization the ability to watch Big Picture Trends in their day-to-day work as they strive to keep your organization secure today you've seen a brief overview of several capabilities that servicenow has to make your organization's world of work easier in the vital area of keeping your people processes and Technology secure from optimizing and orchestrating security operations to hardening your attack surfaces and keeping leadership informed our platform is here to help

View original source

https://www.youtube.com/watch?v=J9-uzuocKuc