logo

NJP

ServiceNow Federal Tech Day: Zero Trust Architecture

Import · Dec 15, 2022 · video

good morning everyone my name is Michael Greco I'm head of security solution sales for servicenow and on behalf of servicenow and Accenture we'd like to welcome you this morning to this presentation on zero trust uh just a quick overview on the agenda today we're going to start shortly with a keynote speech on zero trust at 9 30 we're going to have a fireside chat um with some uh servicenow Security leaders and Accenture we're going to follow that at uh 10 15 with a panel discussion um so hopefully this will be a very exciting agenda for everyone um just as a note later today we're also going to be running a security challenge for a number of our customers and Prospects within the federal agency and we've gamified our security products um for competition and education and so that's just another aspect of our service and offerings uh by servicenow um before I introduce our our keynote speaker just a couple of couple of items you know feel free to take advantage of the food and coffee outside just ask that uh everyone turned their mobile phones off to or mobile phones to silent just so we don't have any uh disturbance I know many of you probably have already done that already but just a reminder um again I'd like to say thank you to Accenture for participating with us in this event um as I Was preparing to introduce our keynote speaker and and learning about his background uh I was reminded of something from my past and uh I was working for a company uh it was a division of uh British Telecom and and British Telecom decided uh that they wanted this company to be very different pretty different from the other parts of a British Telecom and so what they did was they located this company in the U.S and they created a very different structure outside of British Telecom a different culture and one day the CEO was being interviewed and they said his name is Jerry Thames and they said Jerry you know this is a very interesting Prospect what you're doing here with this company and this culture and he said you know how do you how do you find people what do you look for in people when you're forming this culture that you want to be very different from anything else and Jerry said I look for scar tissue I look for Scar Tissue he said people with scar tissue have lived and breathed have learned have failed and it's that scar tissue that's going to make us successful and when I was speaking to our keynote speaker and learning about his background um that came up to mind because I think he's got a tremendous amount of scar tissue that makes him such a valuable resource and perspective within the security environment a little bit more about our speaker um he is the Chief Information officer and the assistant Inspector General of information for the Department of Health and Human Services more than 24 years of I.T experience starting and and probably forming the foundation for a lot of what he does he started in the army I think what makes our keynote speaker um particularly relevant for this is he's got experience in zero trust not as someone who's had to implement zero trust as a mandate or a directive but someone who's been an evangelist for zero trust from the very start he is co-chair of the cio's in Innovation Council for zero trust as well as a co-chair via the atar or zero trust working group so this is a um you know very exciting uh person with a great perspective and with that please join me in welcoming Jerry Karen foreign this is not product placement it's just I'm not a coffee drinker and I drink soda first thing in the morning so thanks for having me thanks for the introduction uh pleased to be here um so gonna go a little bit through what our journey looks like at hhsoig probably talk about some of the stuff that we're doing in some of the working groups as well um I know the um working group at the federal level that I co-chair with Sylvia burns from FDIC and alpia Kerman from the nccoe we're looking to have a summit coming up um but be probably a day or two of government only and then a reverse the industry day where we'll be having some vendors as well and some practitioners to get some feedback on what the industry is seeing and things like that so a lot a lot of things going on a lot of good groups out there um so we'll talk a little bit about that hopefully too so this is this is my attempt probably about seven years ago at this point of putting zero trust on one page because it was frustrating I um before I left my last job I was the eviction and Remediation person for the Department because I was in operations I have not come up through the cyber security ranks but I come up through operations the result of or the advantage I had from where I was I was basically the infrastructure person running Network active directory all those things at the at the Enterprise level so somebody was doing I.T in the organization they leverage my infrastructure so I kind of knew what was going on and you know you you learn a lot of things if you're observant and everything so after being through some events and going to something like RSA and hearing the John kindervad and things like that when that started and he started talking about it many years ago that it started making sense to me so I like to say I was cool before the everybody else got cool talking about zero trust and really understanding it so put it on one page now do I expect you to read this no but try to make sense of it so we could put it and I have it on a plotter size paper so I can put it on the table in in the executive conference room and say this is what we got to be doing this is all of it the thing about zero trust is it's not a tool it's not one product it's not one solution it's an architecture and everything on here has to work together and it all revolves around that Center which is basically at the end of the day we're trying to protect data now I've had arguments about that identity I'm trying to protect identities but it's right dated to the right people at the right time if you got compromised and I'm the cyber security analyst probably my first two questions are you going to be what did you have access to in a Xerox Phil what am I asking about at that point I'm asking about data right that's what I'm trying to protect now identity is very important we do have to protect identity because it's the right data the right people at the right time very judicious but try it at the end of the day we're trying to talk about protecting data so I am also forced to certified I always go back and you know there's you know DOD just released their strategy there's eight 800-207 out there and everything but go back to the principles no matter what you do you go back to the principles and these pretty much align with forces principles trust no one especially if you're an X-Files fan you know about that you trust no one know your people and your devices so what do I have control of what's within my realm of control validate identity at every step design system assuming they're a compromised so assume breach distrust everything so when a breach happens you're as protected as can be stopping lateral movement things like that use Dynamic access controls access to Services must be authenticated authorized encrypted at all times it can be revoked during a session so make decisions it's not one time through the door you are dynamically checking all the factors all the time and if it reaches certain thresholds you take an action it's not come on in have a nice day happy you're here you're always checking all kinds of factors constantly so you constantly evaluate that risk and then you do the right size protections over the things that mean the most I like to use the analogy and it's probably a terrible analogy the crown jewels if you lost the crown jewels that's it right but if I lost my bologna sandwich there's plenty of bologna and bread in the world I'll make another one am I concerned yeah because now I'm a little frustrated but can I answer the question on my crown jewels still protected my sandwich got compromised but my crown jewels is still protected if I can answer that question that's good I've stopped lateral movement I like to use this analogy because and it helps set the stage with Executives because they kind of get that there's been football analogies baseball analogies I like to use the movie theater I go to the Multiplex movie theater and I enter the lobby I have a ticket I enter the lobby they where do they check my ticket they check it when I enter the lobby door now I have access to the concessions I have access to the restrooms all those things that you would expect to have because I'm allowed in the movie theater but the movie theater I go to usually or one of them I can go into any movie because why there's no ticket takers at the door there's nobody checking my ticket again at that door I can go into every so movie being the data I can move laterally all day I can go in one movie hop out go to another movie so I'm moving laterally throughout the movie theater that's kind of the way we're doing it now or or we've done it I call it the Tootsie Roll pop some people call it the castle Mo hard outer shell soft gooey Center right so we got to get away from that castle alone so what do we want to do is we want to check am I allowed in the movie theater chat check my ticket but I'm putting ticket takers at all the theater doors now am I allowed in that movie some of them now you have reserved seats now I reserve a seat in some of the movies but there's nobody that ever comes to check to say are you in the right seat sir we have to do that with zero trust that's kind of like talking around the authentication and the identity part right but what are the other factors in that movie is this is the movie showing on the screen are the lights low are the exit signs lit are the lights that on the floor lit are people in their right seats there's many factors that we have to understand and check constantly so that Usher has to come in constantly and check those factors to make sure that everything's okay because if one of those factors goes wrong what has to happen threshold is met action needs to be taken again the core principles all revolve around data at the end of the day that's when I'm worried about protecting now yes if you read the 800-207 or the DHS materials they have seven pillars or five pillars which are data applications Network endpoints and identity if you read the dod document which I've been leveraging uh some of that documentation for for a long time now is they have seven I I actually have had added an eighth pillar as well so there's orchestration and Automation and there's data and analytics and then I also say governance because governance runs throughout and that's the non-technical aspect of this that is your risk thresholds that is your policies that is your tolerance that's all that non-technical stuff that has to govern through all those pillars because all those pillars have to work together at the end of the day can't just do like some people's like we're doing the identity pillar and they can do a great job at the identity pillar but I always warn understand the dependencies between your pillars because why what happens if you have to do something you got to re-engineer nobody especially the financial folks don't like free engineering because it costs you more money and more time so we'll talk about a little bit about what we did so step one uh so we identified the sensitive data so we're taking a data inventory understand where your data is and not just where your data is where's your data flowing so one of the projects that um I'll mention again later is we're mapping our data flow so we're going to take an application has a lot of hooks and do a lot of things and we're going to map that data flow I got to understand what my data is doing if I'm going to protect it because what does normal look like because when abnormal happens I got to do something so macly accessible route the acceptable routes make sure that's right right so we have to work with the system owners or the data owners and and the choice transaction flows then architect our zero trust micro perimeters so that data I don't we have data warehouses we have data Lakes now we have the boat the the boat houses or what whatever they're called now where those two come together um so we want to put perimeters around different parts of data because why is that crown jewels and baloney sandwich if I put them in the same database the crown jewels the baloney sandwich gets compromised carbon Jewels go too now I want to do micro segmentation around my data so I want to segregate those things I want to monitor monitoring is very important I talked about all the factors taking in all the factors all the Telemetry I can get to feed that Dynamic risk score so I can make decisions and and understand what data I can leverage to make decisions off so one of the things um talk with one of the Consulting companies talked about cyber mesh so he kind of talks about after zero trust you do all the technical things there's What's called the Cyber mesh and that cyber mesh is basically taking Telemetry from many different tools that you have available adds up to some kind of score and then is that what is that what is that score and based off what my thresholds are all right this Factor this Factor this Factor adds up to this okay um you may log on with a PIV card fully managed machine that I'm managing I have a good Telemetry on that coming from a network that I know you're a government employee and so I have some good assurances around some of those things so the risk is and you're trying to access this depending on what that Target is that you're trying to access okay I'll let you access that but in the realm of things sometimes some tools are slower than others now I'm checking that computer you're missing some patches my risk threshold might change as a result while you're working and I may have to downgrade you to read only or kick you off depending on how critical things are or conditional access policies get trip so leveraging the cloud as a factor as well and the things that it provides as well is very big in this because a lot of people say well what about the cloud cloud has great tools leverage them understand how to monitor them because even though it's fed ramp you got to understand how to monitor the cloud because why it's still your data so understand the things that it makes available and how to monitor it Embrace security and automation it's got to be automated how many times have we heard about events and usually what happens is something looks odd or a customer report something odd and you know when a customer reports something on we're not monitoring somewhere probably right but red blinky light goes off what usually happens hey you see this what do you think that means what should we do now that sets off now now we start talking about it we start thinking about it and everything what's happening if it is malicious time right it's taking time and everybody's seen the stats on you know from the time and malicious act actually happens till it's discovered and then action is taken and everything it's days um and they're green in a foothold they're moving laterally and things like that so Automation and making decisions as real time as possible is very important in the zero trust if you have seen the dod strategy that came out um I've we've been using this for a while but you'll see something like it I've added a couple things actually um under a couple but these are the pillars of course it aligns with the DHS um pillars you have data you have endpoints you have Network you have applications you have users but then there's visibility Analytics I need that to make decisions that's the Telemetry all of those things that I need and then the automation orchestration which I just talked about and of course across your policies your thresholds your risk tolerances governance it runs through the whole thing now this is how we use this so my over a year ago when I first came to hhsoig I introduced zero trust I had to train my staff on zero trust they were not thinking about it they were not hearing about it and this is before the executive order came out the that year so I had this I said if I did not spend another dime what can I do and how am I how are we doing at it so we took the DHS maturity model after we inventory tools that I could take advantage of these functions are we doing it are we not doing it if we are doing it how good are we doing it based off the the concept of that the maturity model and we rated ourselves now if I wasn't doing it did I have a tool that could I could leverage to do it because why now I'm knowing what my gaps are what am I what do I need to work on so now I got a good picture and as you'll see here in a second it's something I can show Executives that's kind of easy to understand because we use simply red yellow green right green we're doing good red we're either doing bad or we're not doing it at all in yellow we got some work to do so um if you're a vendor and you've talked to me or if you have been in our ataric working group this is your homework you want to talk to me about zero trust which everybody wants to do it seems all the time I need to know what functions You cover and if that's a function that I need so this is their homework but I also ask them not only what are your primary functions but where do you integrate because why this is an integration exercise this is an architecture so integration could be one of two things it can be we integrate and provide you Telemetry so you can calculate your risk score through apis or if you want to use our tool you need some kind of authentication of something so we need to integrate with your authenticator of some sort so you can access our tools so two kinds of integration but what do you do primarily and where do you integrate so the result of our inventory and this is just an example this is not the way we look ours is probably more red but uh um actually but this is what it ends up looking like green we got it check yellow needs some work we can improve we're not at the maturity level we want to be red we're not doing it or we got a lot of work to do now I know my gaps so now I know kind of what my as is was so moving towards zero trust talked about you know the Tootsie Roll Pop security pirate outer shell South GUI Center then we moved to macro segmentation macro is Network you know vlans things like that micro is getting down around the data aspects and then moving to zero trust so now everything has its own little perimeter around it we just don't have that one big perimeter of that castle remote concept one of the things that I did this past year and I think is very important and everybody goes in and they say zero trust it's the it Pro Shops problem and so we do it in that Silo not us we have educated our users on zero trust why are we doing that because eventually things are going to change for them how they work so I look at zero trust as being an opportunity to modernize as well why we're looking at sassy what's great about that I don't like vpns they're secure way to deliver a malicious payload is is how it was described to me and I agree now there's Technologies rather than hair pinning them back to one of my on-premises data centers and just to send them back out to servicenow or some other cloud or the internet how inefficient is that so send them more direct boom great performance did it in an overseas location once 80 performance and some of the sites that they were going to I'm still getting my security Telemetry and meet my tick requirements because it's still secure too in different ways but I'm providing them a benefit but I'm also asking a couple questions as we go through this journey not how do you work how do you want to work so we can build those requirements in and how they want to work in the future do they want to be more mobile do they want to be able to do everything from their phone from their personal phone from their GFE device also what's the data they need and when do they need that now I'm helping with my inventory of that data the thing I'm trying to protect so now I'm building those personas which are very important and how's this going to help it's going to make it much less frictionless when I start making changes eventually to how they work because why we're including their requirements and we're taking them under consideration so we're modernizing it's not we're not just layering on security so a lot of benefits so our zero trust roadmap I showed you kind of like what our gaps are what are as is um so we have the five pillar we Five Pillars to keep it aligned with DHS and I have basically five uh six um foundational projects that I identified initially one is a sock I'm small I have a person that watches tools but I want a 24 7 sock so as a service is great doj provides sock as a service and tools to help um they have endpoint tools they have sassy tools they have some other tools great help so definitely look at as a service options shared services is a great Advantage because now somebody else is managing that and I don't have to worry about that mapping data so we're doing a proof concept we're mapping data we're going to understand how our data flows where it is where it resides and who's accessing it and make sure and so that we can understand what it is we're trying to protect maturing our identity management we have some manual things that are going on I want to automate that as much as possible we have digital identities of course you create a new application what happens you proliferate a new digital identity probably so we want to Reign that back in and heard those cats in secure web access we've talked about that using sassy going more direct to your destination still getting that security Telemetry but sending our users more direct to where they need to be doing asset Discovery creating that cmdb what do I own what do I control what is what is in my realm of that I can change and monitor and then data integration doing a risk operational risk dashboard it'll probably be more static than what I've talked about being more Dynamic but I gotta start taking the tools that I have advantage of and start integrating them making those relationships normalizing that data understanding what I have access to and understand what my gaps are so I'm starting to do that integration we're going to start small with things that we know objects that we know like a bunch a group of laptops what is all the information I can understand about those laptops what who the users of those laptops what is the software on those laptops what is the hardware and then move out from there and build off that so our roadmap we have some gaps so we have uh for each of the pillars uh we have our roadmap for the next few years as a result of doing the work that we've done we understand our gaps we are our current state we have identified our FY 23 projects in addition to those projects that I just showed those foundational projects and we know what we got to do in 24 as well we're in two-year planning Cycles but this work is allow us to tell us what we're doing and we have some things probably goes beyond fy24 it's because it's a big undertaking it's a lot of work we have a lot of prerequisite things that we need to do so there's a lot of work ahead but when I introduce zero trust to my staff they started looking at it it's like man we've been doing it this way this actually takes care of a lot of our problems if we do these kind of things so introducing them to the art of the possible new ways to do things it's a different way of thinking still wrapping their heads around but some of them have just grabbed passed on to it and they see advantages for them as well going forward other thing I would caution as don't make it overly complicated so why I say that is you know we have this now I can probably go out and buy there's a best of breed tool out there for every one of these functions now if I did that I'd have the best tool to do every one of these functions can I sustain that no that's over going to be overly complex I'm not going to be able to sustain it so keep it as simple as possible for sure now that's my pitch hopefully that sets off the rest of the day well on the subject um I'm always available like I said we have the atarch working group we have about 70 vendors in that working group uh we had phase one where we basically allowed each vendor 75 minutes to do their pitch they did their homework showed us what they're gonna do we gave them use cases now phase two which is going to be really great is we're saying team up integrate show us here are 50 news cases they're going to run through those 15 use cases we're going to have a pre screening board to make sure that you know they aren't taking too many Liberties they have an outline this is what we want in your presentation it will be for government only and they will show us an integrated active lab and actually show us that they do it not just tell us through slides and things like that so we're looking forward to that we expect to have a bunch of labs setting up for that after the first of the year the nccoe of course is doing their project as well with certain vendors um but we're pretty open to a large number of vendors we're not selecting but we're just telling them now you got to team up so some of them are bringing in their integrator Partners things like that we may see the same same solution in five different Labs which is perfectly fine um but now we get to see how it works with other Solutions and things like that so we're very excited about moving to this phase too it's a heavy lift a lot of logistics to it getting people on the same page we got the Presa the pre-screening board ready to go as soon as the first ones come through and then you know if there are some deficiencies we'll tell them you know you really didn't demonstrate that right or you don't have your prerequisite homework done you didn't have this in your presentation we'll kick them back get a chance for them to revise make sure that we want apples to apples when they display these things to the government so we're looking forward to that um you can contact me at any time um I'm always happy to talk about this I could go on all morning and take up the rest of your day but I do have another one I have to go talk to but please reach out at any time and um if you have any questions at all and I think that's all yeah I don't know if you have time for one question if somebody has one question if they want to raise their hand I'll pass the mic though no oh here we no was static Jerry thank you very much appreciate it yeah okay thank you thank you we're going to move to the uh to the next uh phase of our uh morning here with the fireside chat I'd like to invite Mike and uh and Dina sorry Nicole I'll I'll let you guys introduce yourselves to the to the team here all right is this on it is well uh thank you everybody my name is Mike Rhodey I'm our Deputy Cisco at service now focused on our U.S federal government environments with uh the task of implementing things like zero trust in in the environment as well as ensuring our fed ramp compliance to uh to meet the US federal government standards and I'm joined here today by Nicole Dean Nicole would you like to introduce yourself sure good morning everybody uh Nicole Dean um I am the Chief Information Security Officer for Center Federal services great and we'll get started here with a little fireside chat here today um you know first question I think Jerry did a really good job of talking about the concepts and principles of zero trust and what's going on uh within HHS when I say zero trust to you Nicole what does what does that mean to you and what does that mean to you uh as from an Enterprise perspective within AFS sure so let's let's start with how we even get to zero trust zero trust has been around the the terminology and the concept for quite a long time but it's only as of late that it's really gained traction and everybody is talking about it um and it can mean 10 different things to 10 different people on what zero trust is but how did we actually get here and why is everybody focused on it now so if if we go back in um our guests our keynote speaker use the castle and Mo and that's what I did I mean for years that was how we did security every thing was inside the castle we had this moat um you know filled with sharks and crocodiles and uh you know we had the Fortress wall and we kept building it up and we kept putting more things and we might have a few secret tunnels out of the castle those would be your vpns um but then what happened Cloud happened mobile happened kovid everybody went home happened and all of a sudden the the wall fell down the moat dried up and the castle crumbled and turned more into like an amorphous blob so that perimeter that we had for the longest time that we all focused on building up to protect our environment kind of went away and so the concept was well now now that we don't have that what do we need to do so this zero trust term really took a foothold and I think our keynote speaker really hit on it it's it's really about constant verification and validation continually over and over whether that's from the identity whether that's from the device and it's trying to find those principles so that you can really have a Workforce that can be anywhere anytime and have access to the right information and you know it's them you know it's the right device and you know that's the data that they're supposed to be able to access and that's where zero track trust has really gained Traction in the last years is because that whole methodology that we used before to build up that strong perimeter has just crumbled and we we all live in a new environment now um and that's where zero trust has become important to everybody from an Enterprise perspective so now Mike so what challenges do you see um as a federal industry partner in implementing and supporting uh zero trust environment yeah I think you kind of hit the nail on the head with the the old mindset of setting up the moat and and having the perimeter controls really the challenge now is is okay we've got to change the way of thinking we've got to change the way that we've done business for the last 15 20 plus years and really trying to communicate what does it actually mean to to implement the zero trust model and you know I think the the guidance that's out there is helpful but it's still very conceptual and when you start looking at okay how am I going to get to this this zero trust compliance and what are the steps I need to take to get there it's still pretty muddied and I've gotta we've got to look at the tools that we have currently in place determine if those tools are actually going to be effective in helping us Implement a zero trust model also looking at the data and and finding out where all of the data that we store that we process where it's going where is it flowing what cloud is it going to uh what internal systems are interconnecting to where if one system gets compromised the crown jewels as Jerry pointed out earlier get compromised versus the bologna sandwich and really doing that that strong mapping inventory of systems and where your data is going in those systems and then the the last piece here is this is this is a journey there's not a Finish Line to it so it's not this specific project plan that you take care of these you know 25 steps and boom you're done you don't have a fedramp certification fedramp authorization it's it's going to be an evolving thing that's consistently going to change over time and different products and different use cases are going to continue to come out so it's it's really going to be a change in mindset and I think that's one of the biggest challenges that we see is is moving from the old to the new and to kind of follow up I did mention kind of the fedramp as an authorization but are there any policy or compliance challenges that you see Nicole going along with zero trust implementation I do I mean at least when I talk to other people everybody tries to wrap the Frameworks that exist today that the government has out there as a federal contractor and how you map those to your compliance and meet zero trust and I I actually personally don't see it as much of a challenge because we can go to the framework so if I look at the cyber security framework it starts with identify well it's the same foundational pillar of zero trust I can't I have to know what I have I gotta know what my systems are I got to know what my services are I got to know what my data is I got to know what my applications are I can't protect anything next step in the nist CSF if I don't know what I have so we've all been doing that already so you know the term zero trust and how do I accomplish it you can leverage a lot of the things out there identify know what you have if you don't know what you have you can't protect it and if you can't protect it you can't detect respond and recover when something happens so it all starts to me with the identification of what you have and then being able to map how your risk tolerances are going to exist to what you have that baloney sandwich versus your crown jewels type of thing so which things you know from a technological standpoint do you want to put behind ten doors that somebody has to go through and then get into the the safe in the underground bunker before they can get to it and what things from a technology standpoint are less sensitive you know when I when I think about AFS I can think about like our time system Well it can't get anywhere else so it's a very low risk tolerance for us gonna enter your time okay you know I'm less worried about the device you're on where you're coming from other things and mainly focused on an identity because if you get into it you can't go anywhere else and then you know there are things that we have a lot of compliance checks for because those are the crown jewels or I don't like the crown jewels I like to say the Coca-Cola secret formula um you know that's where you have to go through those all those checksums before you can actually get to that information but we can use a lot of the the policies procedures Frameworks that have all been developed today and mapped that to zero trust because they're they're foundational for getting us to this next layer it's just a different way of implementing technology than the perimeter-based methodology we used in the past so what do you see as uh Mike as technical challenges to consider for a large-scale zero trust implementation yeah I think the the biggest one is there's not a single product there's not a single Solution that's out there that's going to get you to be this zero trust uh you know ultimatum it's it's a scenario where we've got lots of products that are in places there's lots of software sprawl you see with customers I see it internally and trying to get the products that we currently have today help us to achieve this mindset and this concept um you know we we have privileged access Management Solutions and like and now it's really enhancing those Solutions doing deeper dive user entitlement checks and ensuring that the right people have only the access that they need to to accomplish their job functions you know the concept of least privilege is key and you know making sure that there's appropriate checks along the way and that you don't get into a scenario where um there's too much access and it's it's also with your Integrations as well it's understanding what machine to machine type of connections do you have and really mapping where if there was a single point of failure there was a compromise that you are able to turn that off and turn off the access to where your your sensitive data is and be able to to quarantine and take action so I think that's that's been probably or is one of the biggest challenges is really trying to identify what products we have that can help us and then also integrating you know those products and making sure that those products can integrate and work together so we're not operating in these silos that's great so Nicole I'm going to jump in a little bit on to what what AFS is doing so how is how is AFS adopting a zero trust methodology yeah well we're on the same zero trust Journey as everybody else's um but one of the the key things and it resonates back to what Jerry said is simplification so I think you know one of the things um uh I have always been a key advocate for even when I was even when I was in the government so when I used to run um organizational uh Information Systems when I was in the federal government one of the things that I always that always happen is every vendor came in and they had a great product and then you ended up buying it and so you had millions of products and then were fully optimized and that drove me insane and I've carried that with me out into industry um and that's the the Mantra that I set for AFS it's got to be simple it's got to be simple it's got to be simple and so when somebody comes to me and says well this only gets us 85 percent of the way you know we need 10 more products to get do we really need 10 more products or do we sit there and say I know I am at this level right now let's figure out how to optimize everything we have at the 85 percent level then we can figure out if we need to go into the the last little bits and I think um we spend way too much time trying to um make Perfection rather than make good and if we can make good and optimize absolutely everything that we have you're actually going to be more secure than you are with a ton of different products that not everybody knows how to use they don't all integrate nicely or they don't all play together nicely and you're struggling and you're struggling and you're struggling and then you never get to good so I am all about simplification and reducing the amount of tool sets that we have to implement zero trust so finding the the key critical things that can that can help us help us do that you know servicenow being one of the components of our zero trust architecture that we use in Accenture Federal um again that servicenow is our know what you have you know and that's what we use that tool for that's our identify tool um and so I am a big proponent of simplification simplification simplification and don't make Perfection the enemy you know of moving forward and I think way too many of us tend to do that and especially when you get your technologists out there they want to try absolutely everything that's great but it never ends up working and you only create more vulnerabilities in your environment with the more stuff you add into your environment they say there's so many vulnerabilities in every um line of code so the more products you use they're all developed on code so that's more products that you have to think about how you're going to protect and that becomes a a challenge so that would be my one Mantra and that's afs's Mantra too simplification simplification simplification reduce the amount of tool sets find the critical ones that you need to do your mission and do what it is you're trying to achieve and then figure out once you have those at optimal how do you add on anything else and do you actually really need it or are you fully covered with what you actually do have so that's that's the biggest thing that we are doing in AFS right now why don't we take it back because we're we're running what about servicenow how get how what are you guys uh seeing uh and doing for zero trust and and how can you overlay that for where the US government needs to go yeah I I think your point to simplify simplify simplify are spot up and the you know I look at kind of what's happened in the evolution of the government over the last 10 plus years with the you know look at the DHS CDM program you know conceptually with a great idea let's get these security products out to the agencies and agencies can can become more secure by getting licensing to all of these products and kind of what happened over the years is there's lots of great products give each agency has licensing to just about anything they could want or need from a security perspective however they didn't integrate and so there there's lots of shelf wear that's out there and there wasn't that integration it wasn't getting to the point where you're using the tools to the optimal capability and and being able to um solve your problems with you don't need more tools all the time here there's there's plenty of tools out there that you can put in a kind of an optimal mix where the tools work together and that's one of the areas that that we've been able to live term our own platform servicenow is through a lot of the Integrations when you look at the Integrations and the tools that are out there from a security perspective our platform isn't necessarily you know focused on specific security features or specific security features that they're trying to try to address instead we are the workflow engine behind um you know integrating all of these different security tools and and different products so you know that's that's absolutely something that we've adopted as well um you know some of the specific areas that that we've been doing on you know kind of tactically is is really looking more around our our data and where our data flows go and making sure that we've got proper segmentation across all of our environments whether there are customer Cloud whether there are government Cloud whether they're our internal Corp ID and and really making sure that okay we're we're cutting off any communication that's unnecessary and making sure that communication that is necessary we've got the appropriate controls in place from a privileged access management capability that's great yeah so I think we're we're at we're getting close to where we're going to take questions so I think the last thing we want to leave everybody with that we'll both do is like what the key piece of advice is and I think that the number one thing is and you've heard it said many times is that zero trust is a journey what's your zero trust architecture and journey looks like today is going to be very different five years from now the principles are all still going to apply but technology is going to change five years from now um and so you have to you have to implement something that's flexible and adoptive for as you know technology changes and allows you to continue to use what you have without re-architecting every single time and the other piece of advice I would say is don't try to do it all at once everybody here has foundational elements of zero trust today whether you realize it or you don't um every single person does um because you have some of those elements from our old castle and moat that carry on to where we are today so you really have to look at zero trust as what's your journey to get more and more secure as you go along um and I like to say don't try to eat swallow the elephant whole eat it like one spoonful at a time be good at one thing before you start on the next thing um and I think we we all tend to try to tackle so much because we want to get there sooner faster and that just tends to lead to more issues than trying to you know take it slow and recognize that you're in this for the Long Haul I absolutely concur um you know the the whole don't boil the ocean you know it's there's so much to digest with zero trust in changing you know mindsets of where you are today which are what what the government is doing what industry is doing and you know really really take the time to effectively plan out what your journey is going to look like um you know I think Jerry Jerry slides up there they are one of the most advanced agencies in rolling out zero trust and he's already got plans through FY 24. so you know you're looking at this this is this is two plus years of an organization that's that's pretty darn mature in this program so um take a look at you know what you truly want to accomplish some of the first steps really inventory you know understand what what what you have under your control understand where your data is going and then from there you can start affect actively planning out the long-term approach and the long-term strategy so so yeah with that we're we're open to questions we tried to make sure we left enough time so people could ask questions anything that you would like to ask of us yes sir within the zero trust framework what do you guys see are opportunities for setting up continuous monitoring and auditing um the continuous monitoring dashboards that you see and start they want me to work okay um well that's to me continuous monitoring is a foundational element of zero trust um because we we just said we're in continual verification and validation that you are the right user um on the right device with the right data um and so that is to in my humble opinion a continuous monitoring type of tool that you could think about um and there's all sorts of there's varying dashboards and different ways to look at continuous monitoring you can look at continuous monitoring from the health of your user and uh the health of the endpoint that they're on um but you can also look like I said a continuous monitoring is this really the the person that that I want and um you can set that up and create dashboards so you know that or automation more so to speak that security and automation portion is where I think continuous monitoring comes in that we heard Jerry talk about that you know if something changes with that user that they are automatically disconnected or have a lower um uh entry point into the environment so that they are not being able to access the Coca-Cola formula they can only get to your time system um and so um I don't know that the traditional continuous monitoring dashboards are going to stay the same as we move forward it's going to be more about how you're interacting and who's interacting with the data and is that at the policy levels and the risk acceptance tolerance levels that you as your Enterprise have defined and I think that's probably one of the biggest challenges that I see too with zero trust is figuring out what your risk tolerance is um again when we went to that castle and moat everything was in the castle behind the moat and Behind the Walls so pretty much everything was protected at the same level and in this new world that we're all living in um that's not necessarily the case and you know you are going to have to change risk tolerances and set those policies for the different types of things you have and I think that's one of the the things that I find the hardest to get people to wrap their heads around because everybody's like well zero risk zero risk zero risk we all take risks today we don't live in a zero risk environment today we're all taking risk today um so getting people to wrap their minds around the fact that you know moving forward you're going to take risk and you're going to be able to show where your your cutting off access where it should be and automating that so because if you try to do it manually too late what about you I I would agree I think that you know when I think of continuous monitoring on the federal side and think of the you know vulnerability scans poem development I think what we're talking about here from a zero trust perspective is that Paradigm shifts more to your state your your typical security operations center and more of the real time real-time alerting and shutting off of access and and and and and re-looking at risk on more of a continual basis more operationally more so than the compliance aspect any other questions I'm good uh confidentiality Integrity do we need Improvement on Advanced course data you want to start this time first [Laughter] I think I think it's a I I think it's a good question I mean I do look at it much more from the confidentiality and integrity perspective that's a great question um I do think that ultimately we're looking to not impact availability right and not not degrade user experience and the like I do think that there are improvements for availability in the sense that you're able to to shut off access if there's a potential compromise in one part of your environment to where it's not going to affect your entire environment and to potentially bring down your your entire environment um and and you're able to to more effectively keep your environment up and available if you're able to shut down kind of adversaries much earlier in the process before they can get too deep into your environment so I I'm going to agree with that and I'm going to say that I do think that zero trust focus is definitely much more on the confidentiality and integrity of the data but those lead to the availability of data so um you know um if your data is compromised then it's not available um it may be available but it's not right um so um you know you have to start that's I think why it goes in the CIA framework confidentiality Integrity availability so if you don't have the first two the third one really doesn't matter um uh you know um so I think when we talk about zero trust it leads us to the availability standpoint um I also think that in the way that we thought about availability in the past to changes so again we're not putting everything in data centers anymore we don't you know have to have you know these huge business continuity failovers that we all used to have to do in the past from one data center to another data center um and making sure that you know you are on different Power grids and different things so that you know you had you had full availability of your data at all time times now as we make the move to the cloud some of that availability matters comes in so that's where I think the confidential and confidentiality and integrity take a little bit more of a priority as we move to the cloud you're getting that inherent availability that exists um from cloud services but again the it's the availability of your particular data and so if that confidentiality and integrity isn't uttermost with that data that you're hosting in that cloud then while it may be available it may not be right what other questions Nicole I I have a question sure um first of all great great presentation from you and Mike both um I love love love the message simplify simplify simplify I think that's very very key uh one of the things you touched upon was trying to maximize and optimize the tools that you're using before you go out and and and look for additional tools and and I can imagine maybe for the audience here that's a lot easier said than done you know as managers you know can you explain a little bit how do you monitor that how do you manage that how do you know when is the right time to get a new tool and how do you justify that next step um and and yeah appreciate some of your thoughts on that yeah so um when we're when we are looking at new products um uh I have a policy that you have to that anybody that comes to me that says we have to make a new investment that you have compared it against what we already have in the environment so does what we have in the environment can it actually need it and you can come and tell me that new tool a is a hundred percent but our current tool B is 85 or 90 and I'm gonna force you to stick with the 85 or 90. um I am not going to go invest um in something new let's invest in what we have that can do it and that's really about what the policies are that you set um uh for your Workforce so if you want your Workforce always out you know looking at new exciting things yes they can do that but you also have to say you really have to give me the right business case to make me want to invest in something new and that's just something I have put out across the Enterprise don't come to me with something new unless you can really tell me why what we have can't do um what this new thing is and um you know that's that's really a standard that you know um you can choose or you know um to implement or you know you can you can choose not to but I will tell you that what I have learned over my years running um networks in the federal government 20 plus years you know retired SES 20 25 plus years I hate giving away my age um you know running uh networks in the federal government um from you know the SDI down to the unclass level and now being out in the industry that if you don't put that in place you are going to end up with a technological mess and you're you're going to constantly be requesting additional resources that you probably won't get because now you have way too many tools and not enough people that know how to run them um you have way too many tools that aren't integrated and not enough people to make that happen so it's really a forcing function and a policy decision that you can make as a as a leader in your organization great great answer thanks for that another follow-up question you know we're you know certainly from a servicenow perspective or a SAS based provider you know there's a number of executive orders from the federal government looking for agencies to move to the cloud does moving to the cloud make zero trust easier to achieve or harder okay I um so we are a cloud first organization um Accenture is a cloud first organization um and uh zero trust has to me nothing to do about Cloud um you know whether your data is in a cloud or your data's in you know one of those data centers you know um in Leesburg or off 234 in Manassas it doesn't matter you know um it's zero trust is about constant verification validation trust but verify you know right user right device write data at the same point in time so does it really matter if your data is in the cloud or does it matter if your data is in a uh in a warehouse somewhere um it doesn't matter um so I look at the journey to Cloud as meeting what we talked about before that availability function of the confidentially integrity and availability so Cloud really helps achieve that availability standard in a much easier way but the other other two principles for zero trust it doesn't it it doesn't matter where your data is or where your user is because the principles apply no matter what I had on yeah and I'd agree I think at the at the end of the day it's where you're knowing where your data is located uh where where your data can be accessed and regardless of whether it's sitting in you know data center that you own manage and operate or if it's being hosted by you know a cloud provider any other questions well thank you Nicole for sitting down with the fireside chat with me I appreciate it and thank you everybody Al and the audience who appreciate the the time yeah thank you everyone you have a wonderful day thanks guys all right everyone thank you I know you guys are all having a good conversation we're gonna wrap this up with a little bit of nerd talk on some zero trust stuff my name is Will Coffey I'm with Accenture Federal Services I'm with our servicenow business group I'm one of our certified Master Architects I specialize in security and risk portion of the platform that's not really that important what we've got is David peridan from servicenow Office of the ciso got Dave darling our cyber CTO we've got Shawn Wells who is one of our managing directors in our cyber security practice who specializes in zero trust right he's our zero trust owner so today what we're going to talk about is we have a panel discussion we've heard a lot of good stuff from Jerry and you've heard a lot of great stuff from Mike and Nicole and a lot of that is a lot of the standard zero trust things like what is zero trust why is it important what are we doing about it have you seen the executive order you know all that kind of good stuff uh but what I want to do now is talk about the nuts and bolts and zero trust and talk a little bit more in the weeds of we're implementing zero trust what does that look like from a ground level and what are some of the things that when we're implementing it that we're doing or that we're taking into consideration so I'm going to sit down I'm gonna start posing some questions to these guys and we're going to get into some some nerd to talk about zero trust so if you could give yourself a little intro let everyone know who you are what you do here sure thanks so much good morning everyone my name is uh David peridan I'm with the office of the CSO field security team I've been with servicenow for about six years I was an actual consultant then I actually transitioned into a practitioner so thanks for having me thank you for being here um I'm Dave Dowling I'm in uh supporting the federal government for uh good amount of years uh I started out in compliance um then became an auditor and then became an engineer and then became a security analyst um and running socks so I've been able to see uh the development of zero trust over uh over my lifespan in all aspects of xeritress and so I think I'm going to bring a little bit different aspect to zero trust today then you probably normally will hear yeah I'm Sean I work on the technology side of Accenture so less less business suits advisory and more implementation and Tech strategy I come out of the offensive side out of uh NSA red teaming so I I have actually far less defensive experience than I am on the other side of the keyboard trying to break in excellent well thanks we've got former Consultants Auditors and people that are going to break into your stuff all exciting things to jump into on this stuff all right so what I wanted to start with is you know we kind of jumped into what does zero trust mean to you and the other ones but really in the trenches what are we doing about zero trust what is it what does it really mean when we're dealing with zero trust and parenting I'll start with you yeah so I'm responsible for managing fed ramp instances for our surface in our cloud and one of the you know things that I had to go through was to onboard um you know customers into our Cloud but for my specific case um when it comes to zero trust I had to go through a process of being allowed into our GCC environment right so you know things such as you know identity and access I had to basically you know get adjudicated um get approval from my my manager Mike rode he was just here in that last panel discussion and um you know now that I've been onboarded into fedramp um what I've had to or what I actually have to do is essentially I log in with my token I I basically have to access various resources I have to jump through groups various groups you know in terms of accessing our vpns that's going to specialize in terms of terminating connections into into GCC and then once I'm inside then I'm able to take a look at certain things such as customer instances are there any sort of approvals that I need to go through like say for instance if there's a sales order and I have to approve a servicenow instance I have to make sure that this customer is going to be you know properly provisioned correctly and you know vetted and so forth but throughout that whole experience I'm constantly getting challenged I just can't move laterally or you know essentially do something a little bit you know abnormal I'm being tracked I'm being logged on a case-by-case basis um you know so I I do have to take training so that's another aspect of zero trust that we don't really talk about and there was something earlier you mentioned in terms of there was a question questioned by this gentleman here by continuous monitoring so when I have to access you know these various systems within our GCC environment the continuous monitoring activities that we're taking or we're actually executing is all right where is Dave going is he accessing you know our uh highway or basically our now support portal but then also he's taking a look at certain Cloud instances am I accessing the information for the right reasons right all that information is being tracked there was another question specific to availability I want I was so wanted to jump up and ask or answer this question when it comes to availability in the context of zero trust hopefully I'm not getting you know too long-winded here um right um when it comes to the availability of it you know we're we're talking about I think Jerry talked about it this morning um basically assume breach right if you're assuming a breach you are now having to take a look at your current processes your procedures how do you get that system or that application or service back online right so you're going through your incident response process and so forth once you have that sort of policy in place right you're able to get back to your business so that is another variation if you will of availability making sure that you have those um you know those response processes or plans in place in order to re-establish that actual application um yeah I think that's I have to say there no that's good that's good so Sean I'll jump to you and talk a little bit about that from a zero trust perspective like what is that what are we doing when it comes to zero trust and we're talking about implementation size like what does that really mean yeah I mean we we largely break the conversation down I guess in Industry as a risk-based approach to Identity and a risk-based approach to data access but when we distill that perhaps we can start talking about the need for dynamic operations where how do we get Telemetry from endpoints to enable continuous monitoring to enable uh this this autonomous resiliency so we start diving in to almost these Progressive safeguards where we want to take a I guess you told me to get technical so what we end up doing is I'm going to drop these so what we end up doing is actually getting into things like how do we start infusing threat intelligence where we know the Bad actors are behaving in certain ways dropping certain malware samples using certain techniques codify that in some sort of data taxonomy that says bad guys are dropping a malware here's a signature bad guys are attacking us through the following Network patterns here's their signature and autonomously feeding that into something like a web application firewall or AWS private link or something like that so what we end up doing is distilling this risks risk-based conversation to a series of almost Telemetry collection what are they doing how is the system performing how is it configured how do we get that in real time to drive kind of these autonomous decisions and when we put it all together the idea is to assume breach um so we have Department of energy unsealed three indictments of Russians who are what four weeks ago uh publicly acknowledged they've been inside of scada networks in uh in I think it was the western region uh DOD just released their CIO strategy for zero trust acknowledging for well at least from my knowledge the first time the CIO said yeah we have adversaries in the network openly acknowledging that so if we have this real-time autonomous system to collect near real-time data we can drive uh this this resilient infrastructure and and that is how we try and actually make it actionable instead of talking you know thematically maturity thematic risk um what does that mean though actionable like what are we doing with it what do we do with the Telemetry so we start building these capabilities like if we take um risk-based user identity I think we talked about a couple times today an example of that is we we work with technology Partners like like a crowdstrike Paulo or Sentinel one to get technology sorry to get Telemetry from the laptops how they're configured are they dod stigmed are they fizmud are your win10 images configured a certain way is the hardware attestation down to the BIOS patched and things like that and we almost create a device trust score to say do we even want this device on our network from there we start monitoring user Behavior you'll hear it called end user analytics or Yuba but the idea is if I'm normally working from nine to five I log in at 2 am that's abnormal if I'm logging into a data source that I haven't that's abnormal so how do I combine the trustworthiness of the device with the pattern of behavior from the user and create a trust score so that trust score then informs do we want to have them re-authenticate every hour because they're being a little weird How would how do we know it's still Sean do we want to have the device require new patches because they're out of date um so all of that technology if I'm answering the question right is is kind of how we start scaling the the how behind this and all of those kind of start to fit into the pillars of zero trust yeah and that's that's been one of our our big challenges so we we have this thematic guidance of how do we get from traditional you know average to operational excellence across the pillars of device Network identity and so forth from sizza DOD has their own but a challenge we've had is you'll you'll see thematic guidance like use a risk-based approach and how do we translate that so in the fisma world or or the ATO world we have the nist 853 control catalog and somebody in security gave us a spreadsheet of like here's the controls you have to meet and you answer them but how do you answer thematic do you do a risk-based approach um that translation often gets fundamentally technical very fast and that's where we start seeing people have have trouble yeah that makes sense so Dave darling when we talk about those things and we look at and Jerry talked about it a little bit earlier other technologies that are in the surrounding environment or ecosystem around zero trust things like sassy like how does that fit into the picture um it kind of addressed a little bit what we were talking about first and then I'll jump into that and tie it all together so I mean zero trust has been around is actually we're talking about how long it's been around right it's been around so early 90s I invented it in the 80s um and you know Google came out in the in the early 2000s and then Sunburst happened right and it was like oh no we need to actually make it real it went from a compliance check based to a technical and and I I think I mean if you actually look at compromises they said 34 of compromises are directly related to human error right the other are supply chain also human error right or internal configuration issues also human error so when you actually think about it it's all human error when it comes down to you know how we get compromised right somebody made a mistake somewhere um and so when we switched from hey you know here are the things that you need to do as a bare minimum to everyone is an Insider threat everyone is a threat right we got to remove that and get to that to that aspect where we're treating everyone the same if they're an ATP if they're you know the David and Sean sitting next to me I treat them the same when it comes to security right I wouldn't just be there I know right no um but so when it comes to like sassy and it comes to uh the the goal of sassy is to get those protections as close to the data and as close to the end point as possible maybe it would be helpful because I don't think everyone in here knows what that is what is Sassy um secure access service edge all right so it's making sure you know moving the the automation moving the protections moving the detections um down as close to you know on your endpoint um around the data you know as we always talk about uh you know we're moving away from the perimeter uh some people are saying data is the new perimeter don't necessarily fully agree with that but I do agree that data and humans are the two things that you need to protect the most right you need to protect around the human and you need to protect around the data and so as you're you're going out of the human right you you're having that automation you're having those detections is it going to access the data and leaving the data you're also having that and that's where the sassy comes in is you're protecting those two aspects which are the most critical aspects the people making the mistakes and the the crown jewels that you may call all right I like it apparatin yes sir it's all zero trust created equal oh no no zero trust is not it's not created equal um a perfect example of this is again I just mentioned how our environment is set up right um You would have to essentially you know take inventory I think Mike Brody said it earlier I think Jerry said it as well taking inventory of what you have in your organization or in your uh your infrastructure and then you know taking uh you know performing a gap analysis right understanding where your gaps are and then we saw those pillars that were thrown up on the board red green yellow actually I like that approach um but you know essentially if you're able to take inventory rather efficiently oh one thing I think it was another question about a tool set I think it was Michael you said that um I want to address that to to select the best tool sorry if I'm going off the topic here but I'll get back to it um to address like you know the selection of a tool I was talking to David earlier you can set up a dashboard and have that vendor essentially um you know give you a trial period what have you and then you know you can measure the efficacy of that actual tool or tools and now you're able to provide the evidence back to that vendor right um Ben Prime I'm not sure if you're in here or not but here he is in the back my colleague former colleague we've we've set this up all day long until terms of setting up these dashboards and then providing accountability to you know those respective vendors now you have the ability to make a decision all right is Splunk better than logarithm and so forth so in terms of selecting I agree everything with that that uh um forget the person's name again that was sitting in this chair Nicole thank you um what she what she mentioned however you can also add in the leveraging technology to help you make that decision especially when budget comes into play so from my perspective if you're trying to protect the crown jewels that we're talking about I don't think you should put a price tag on it because you know if you start to compromise that that you will have some sort of like um you know weakness that will develop that will then lead to a breach right so I think having a an actual tool efficacy dashboard is one way to help you select your respective technology now getting back to what you were mentioning not all organizations are the same in terms of zero trust or how basically is implemented it really depends on your people your technology and your process and how mature you are and what you're doing right because you're talking a lot about it from like the cloud vendor sort of perspective so Dave or Shawn like how does that what does that mean from a zero trust implementation perspective I think are all zero trust environments created equal from the other side from the client side from our side the resulting side uh so yeah there I mean not all vendors are created equal and again we were talking about this and it really comes down to um The Cutting Edge perfect tool is only as good as the configuration and the people that are doing it right you could have something that meets 100 of the requirements but if you don't configure it right or have the people to run it right then it's not doing you any good um and you know going off that is doing those assessments I mean we do um aoa's alternative analysis all the time um and we do what we do is we do a continuous purple teaming um and this really comes in with a technical aspect where we're actually doing adversary emulation inside the network running real tests running you know log4j or Sunburst or any of the you know the latest hacks um and it really changes the the perspective right and it's of course not everything is created equal um and it it changes with every customer and so when we run these tests we find the gaps we find is it a configuration issue is it a people issue is it a tool issue or is it a detection issue or is it a response issue right um there's more than just hey I'm gonna go buy Palo and we're done no I need to buy Palo I need to implement correctly I need to integrate it correctly I need to configure it I need to teach I need to write detections and then I need to you know have an instant response plan and so I mean there's again the tool is just a small portion of the zero trust in the technology I would say I would say that you're defining the right users to having the right accesses right for um to the right data for the right reasons that's good right so Sean you were talking a little bit about Dynamic operations and we're talking about kind of the different views from a zero trust ecosystem when we talk about those Dynamic operations in the human element technology element and how that is all implemented into one zero trust strategy what are some of the considerations that we need to take into account for when we think about all of those different environments and how they're interacting well um so so I run the delivery teams on the zero trust side at Accenture and we generally break the conversation into are we talking about secure Workforce meaning meaning the humans and how they access the data or are we talking about a secure workload on micro segmentation and posture and things like that so depending how we go it'll drive where we start and there's different principles for both argue well if if uh nobody I don't know if CIS is here but like if we throw out this is a model yes um so the the ideas we we generally do begin like if we're talking on uh some of the work we do at Department of energy it's publicly acknowledged it's in the news and that largely is a focus on secure Workforce where they're talking about identity they're talking about device attestation they're talking about how their users can access the data um meanwhile we have other public customers within DHS that are talking about secure workload which is cloud security posture management Network micro segmentation secure browsers so we start I've never actually phrased it that way so I may be stumbling but we generally start on a path down secure work force or a path down secure work load figuring out which one's going to be more important but ultimately you'll do both right yeah yeah you just gotta start somewhere and it's um it sounds like it's a enablement right in in a in a positioning of like Hey we're shifting to this new model yeah and as we shift to the new model eventually we get to the point in delivery where you find commonalities and CIS has been a leader here where they've started stepping up and providing shared services like protective DNS whether you're a user or a machine you need like protected DNS queries to make sure there's no exfiltration um eventually you start moving into like secure web gateways and secure web browsers browser isolation um as a service or share desktop as a service you move to a Enterprise sock that actually takes all this Telemetry so that you can start making these autonomous decisions from the network to the user to other aspects of the infrastructure and that I I'm I'm surprised shared services aren't more clearly art defined in a lot of the maturity models out there so from a compliance perspective and any of you can answer this how does zero trust fit into the existing compliance models that are out there that's very vague I know but I did that on purpose no not necessarily so you have uh the memo 2209 that came out um and in that one specifically they talk about the automation of technical assessments right so again I've I've been in isso so I've been the one that's writing and validating internal compliance I've been the assessor running dhs's compliance team where I assessed you know hundreds of DHS assessments so I know from assessment perspective and then I've also been the engineer right where I've been audited on my Technical implementations and so I know how to get around any assessment right like I know how to answer the question legally right where I'm not I'm not in violation of Ethics um but and get passed that's the problem right we can't we have to get away from this paper-based compliance assessment and going to that technical assessment and automated technical assessment now there's an open source uh project going out there with um to be able to do that you know through markdown languages and stuff and and do that I know uh and and Splunk and inelastic you know we have dashboards now that are you know searching for technical controls and having dashboards and stuff that if you're meeting them that's the way we have to go with compliance right is we have to get to the point where it's AI saying you are compliant or not and then actual technical assessment saying yes you are compliant um and not should not be anything with you know hey here's a 600 page document of how I'm compliant and I read it hey that sounds great good you're good to go right we have to get away from that I agree so as a as a former assessor like looking at the system security plan everyone raised their hand who know what an SSP is right oh my God oh my gosh like that document it will put you to sleep well I I think it doesn't have to suck so um I think a couple things maybe to to raise awareness of um the first problem is we we Implement a service whatever it is protective DNS you get your nist 853 control catalog you decorate your spreadsheet usually by hand and what we're trying to move towards um are really two technologies as the Royal weeping the work we do with nist the first is something called s-cap security content automation protocol it was actually mandated in the vowels of DHS CDM and the idea is to create a data taxonomy that will give us structured pass or fail for technical controls so in the dod World Imagine an operating system Stig of our passwords the right length is crypto turned on in applications maybe whatever technical controls is TLS enabled the idea is if I can get a pass or fail check I have a data taxonomy for operating systems middleware applications that will give me a structured red light green light and I decorate that data taxonomy that says um nist control X makes you do the following at the operating system you might turn on the auditing subsystem at the application layer you make sure it generates user login and log off events and you start layering operating system to application and and so forth in your infrastructure what escap allows us to do is find the gap so if your operating system is providing a shared control maybe your application Server doesn't need to if your application itself is doing something maybe your operating system won't need that and driving that is usually a human assessment process that takes forever in many spreadsheets the idea of skep is to automate it um so that gets us through how we technically get this Telemetry uh on an ongoing basis for the controls technical controls so now whether we want to tie that into themes of continuous monitoring where I run the scan every day every hour every time there's a deploy and it empowers izos to say when I developed this a month ago here's the Baseline I did incremental git commits or software commits or pushes here's the drift over time and I can compare that and and that's all well and good simultaneously there's something to be aware of called O scale o-s-c-a-l and it's another data taxonomy out there that layers in the human people process technology side of the accreditation so I can structure my answer to allow me to say this is how I do backups this is how I do risk-based identity this is how I do whatever um so when we marry these together what kind of Dave is getting at is we now have programs dynamically generating system security plants no more human requirement traceability matrixes no more 5000 page Word documents we take the technical Telemetry from endpoints defined as you know virtual machines laptops web servers we take the human Pros that was structured in a certain way and it allows us for things like DOD Platform One it allows us for some of the devsecoff environments At Doe to actually dynamically build our SSP to verify every technical control with every software push or every period of time like every Monday morning and I would argue that that's been one of the major wins of this whole zero trust thing is making people aware the need for technical Telemetry to drive these autonomous decisions um so now you know for Niche areas and an ever-growing amount of Niche areas we don't have the six-month atos we set up the manufacturing process in a very specific way which which is a little bit slower than normal but once we're live atos are dynamic um yeah I think another part of it sorry yeah I think another part of it is it's also changing it from letter of the law to Spirit of the law kind of thing um you know for example we all have password requirements I remember when it was eight characters then it's 14 characters and yeah I mean how many of you guys feel that your passwords are as secure as they should be are you just adding a one two three at the end are you writing it I mean I've just changed my password every 30 days great um it gets a lot of passwords I can't reuse the same one um that's a letter of the law right and it actually is less secure than if they would just let us have a complex password at MFA and now we're getting to the point like they actually removed the complexity requirement in this last EO right they're like you know what it's stupid password complexity is stupid right and now it's no passwords right we're getting to no passwords and and different types of MFA right and going back to you know the the risk score of the asset you know is it is is it uh compliant you know does it have everything I want can I force things before they can access it um it's all with the compliance portion of it it was zero trust it's changing the way we've looked at security and putting it and making it truly secure instead of um just what somebody one place thinks it's secure yeah I would I would actually add that you know if you're thinking about it you know in terms of making it easier and more secure go back 10 years no one was doing momentum Factor authentication with their phones to get into their bank account we're doing it today right so if you think about we have progressed right so we have made things easier with the Inception of AI and machine learning that is an indication that we were heading the right direction and we're starting um within the cyber world you'll hear about ioms indicators of misconfiguration like a Stig iocs indicators of compromise which are retroactive things like a malware sample was found and ioas or indicators of activity so so the idea is as as a as an industry we started to push away from indicators of misconfiguration and push away from historical indicators of compromise to building real-time indicators of activity you know here this pretty much from every industry sector the idea that we're trying to shape um starting with common criteria which is uh the attestation software vendors have to follow we actually give software vendors now themes that they have to express do you have the ability to in real time identify malicious users do you have the ability in real time to send Telemetry that allows me to make a decision if you're compromised and we're not getting as granular as those five thousandness controls anymore so that started with application servers that started with operating systems and we're trying to gauge if there's interest to extend that out to the newness new revisions of the distress management framework so instead of having technical controls actually being audited on your ability to have organizational agility in decision making so a lot of the zero trust I think people when they think about zero trust they think of it as like oh it's just this new security way of doing business and how I get into stuff but listening to you guys talk it sounds like it's a very Dynamic and real time repositioning of your security posture all the time does that does that make sense and so my question is if we're looking at these things is there really I know we talked that there's no no one zero trust answer and all those things but if we're layering Technologies on there MFA came up authentication identity is one of the pillars like is there one authentication capability or technology that we're looking at I mean right now could we use 10 different kinds of authentication mechanisms to do zero trust in one environment so this is actually um something that we've really been focusing on because there isn't there isn't an ideam Solution that's bedroom High out there there isn't a single identity solution that meets all the requirements um and so this is actually you know uh you know scope creeper axis creep um Shadow I.T stuff like that all of that is probably one of the biggest issues right is knowing your assets knowing your identities and so we've actually been really focusing on this um we hired some amazing identity management people and really working on the Automation and moving away from hey this new person just joined I'm gonna go in and I'm gonna share access with this with this with this with this instead of going in hey this person is a part of this group this team this contract with this role and just tag it and automation goes and gives access to everything they need right and then as soon as that person removes moves to a different role they remove all access just by removing the tags and then give them the new tags again and redeploy all the access right all through automation at any time I need to remove access from data I remove a tag I don't have to go and see who has access Legacy access I'm just removing the tag and the AI the automation completely takes over and removes all that access and so you got rid of all of your you know access creep right uh I still have access to uh a Twitter account for a company that I don't even work for anymore right because they have never removed access and they've actually called me and said hey I can you reset my password right um you know so getting to them so for us that I whole identity management we've really been focusing on and we now have a fedramp high compliant automated identity management solution um that we can go with but here's the thing is it's not a single vendor we actually have proven it out with multiple identity management multiple tools right so that we don't come in and say hey your investment that you've spent millions of dollars and you know multiple years on is no good we come in and we can say here are the keys and the aspects that you need to add or change to keep your investment in place and get to that level of identity zero automated zero trust identity management you need to so the end game of zero trust isn't necess necessarily find the right Technologies to meet the needs of the thing that you're trying to do it's you know let's look at this environment see what we need to do try to move towards automation as much as we can but know that you're going to have to dynamically reassess your security environment really all the time in real time yeah 100 so we actually have what's called a zero trust uh um level up or maturity model assessment and Jerry actually is you know red light green light yellow chart right it's very similar to what we have and the goal is yeah we go in we assess what tools they have how they're configured we do technical assessments and then we come out with hey here are you the technical gaps here's the configuration gaps here's the people process gaps um because it there is like I said there is an a tool that fixes it there isn't in all of the tools out there are good I mean Nicole talked about it if it's at 80 right you have mitigating controls and mitigating tools elsewhere so you don't need to have a hundred percent tools everywhere right you can mitigate that with other tools so the best place to start with zero trust to me is with the tools you have right and figure out how to improve them to meet more of the requirements I know Sean you were about to jump in there I forgot okay so I think that zero trust to me seems like an area where the government is leading right I think differently than most often you hear about Silicon Valley or the commercial sector is coming up with some new Innovative way of doing things and the government sort of Falls in line with that but to me it seems very flip-flopped here and I think the government is leading the way in a zero trust implementation Sean do you agree or disagree and why do you agree violently disagree um no it's not it's so so we have you know we have nist 800 207 which is the zero trust reference architecture you have the dod reference architectures one recently got released there's been one existing you have the scissor maturity models and finally the White House executive order came out a year ago and it was really a reflection that uh for whatever reason the intrinsic motivation to modernize our systems towards an adversary first approach wasn't there so the literal president had to issue an executive order stating explicit guidance to Force action um so no I would say that that we're dangerously close to being last interesting I've been taking the mic do you want to jump in again uh so I and I so I agree I am thrilled with what the government's been doing a zero trust right I when EO came out like little standing Applause right because finally it's coming out it's a requirement I think the government is setting the Baseline I don't think they're leading in zero trust I think they're like all right guys customer I mean with CMC even like everyone here is now the Baseline right and the Baseline is good enough right it needs to get better um and so like I love what they've been doing um it is a requirement uh but if you actually think about uh the last one of the last studies I said uh studied was the ciso an average lifespan of a ciso is less than two years right and uh and with the government with budgets with procurement right I mean you start adding that is they'll come in they try to make it some change you know Sister tries to make a change and then they're moving on you know before anything changes and so you don't really get that consistency or on the commercial side there's a little bit more consistency when it comes to that and so they can progress further and they're all about the bottom line and return on investment and I've worked for non-profits and Commercial both ways and it's a different return on investment on the commercial side I need efficient I need fast I need good right um and on the federal side they don't necessarily have those right I need good and I need cheap right um and so again they there is that Baseline but we are getting there and I think a lot of the vendors are really helping out like we're really working with the winners and you know like I support cisa directly and I am sitting down with vendors and saying here are the government requirements make changes to meet these requirements and they are and so they are leading the aspect in that is they have enough power and weight to go to these vendors and say hey if you want to play an r0 trust you know that playground you need to make improvements um and so overall I think it is making vast improvements for the industry itself I couldn't agree more um I like I'm not sure why I'm trying to go back and hitch like I'm a history buff or something but I'm not um just going back to like say when DARPA when that that basically was created right um I couldn't have said it better you know or you could have said it better I mean I know you had my same name but um Baseline is a great way of saying maybe not leading but you know definitely we're you know the government has been the Baseline now it's up to the private sector and other markets to bring that Innovation and expand it even further that would work collectively able to progress so I completely agree so from a zero trust end game where do you think currently like what are we looking at or did anyway actually you were going to talk go ahead yeah I mean I I'm gonna take a page out of what these two guys just mentioned um relative to the last question I'm not sure if there isn't any right that we're we're constantly evolving we're we're changing um this movement for digital transformation right when you fully transform right are you done probably not right so I think that with zero trust from my perspective um we can hope to achieve an end game but I think you're always going to strive for better I would say we it's the realization I I've never had to reward this we by taking an adversary first approach we realize we need to move away from indicators of misconfiguration in a way of basing our entire atos on indicators of compromise towards the ability to create indicators of activity that drive real-time awareness as I said I'm going to take a very different view on that so I so to me on the end game is I've been through the government when we were on-prem like I remember the server clouds and I would go and physically touch those um and then we're like you know what we're not good at Hardware management we're going to move to private Cloud so he stood up you know dc1 dc2 I remember we created rack packs like so we actually created a a server rack we built it configured it and then we'd ship it out places that would uh home run to to the the federal data centers and then we realized they're not good at it so we went back to government we went back and started doing on-prem again uh government started doing on-prem right um and then we're like hey this Cloud thing you know this is pretty good and so we moved to the cloud um I also remember when we uh when we set up 911 our DHS um uh Coast Guard managed our email right um and then we tried to have HP do it and stuff and finally Microsoft came out and said hey we'll do this as a service and no one's looked back right you're on Google you're on Microsoft no one's managing their own own uh uh email anymore and for the most part no one's managing their own Hardware there's very few we're I mean we're now a cloud uh only Cloud first and we're moving to the cloud um we are you know we used to manage our own ticketing system I mean we're at a servicenow thing I mean how many people are managing their own ticketing system maybe a few here and there but for the most part we're now having servicenow do it um are we having AFS thank you do it for service now with service now right so as you you think about like the progressions we've made as we realized we are not good at doing things right um we are good at doing what we do um and not good at doing other things um and so as you can see we're moving more to managed Services SAS and pass and is with security and I think with security uh the end state is not doing security ourselves right is moving to manage services moving to Azure with their whole Defender suite and their platform is amazing Palo Alto and their platform is amazing crowdstrike and their platform is amazing right they are good at what they do let them do that so that I can focus on my mission my goals and start allowing people that focus on those aspects handling those aspects so now the key is getting them all to work together right and making sure that we're getting the Telemetry we're getting the logs we're getting the data um necessarily to do it and that's where our Shameless plug managed xdr right that is our bread and butter right is uh Gathering the Telemetry from all of these SAS and pass and I as an on-prem and bring it together and you know correlating all that into a single location and doing those risk scores and asset scores so to me that is the end state of zero trust is getting to that level of letting everyone be the best at what they are I don't want to steal your thunder for a quick second but um do we really think that zero trust is the true end game here we all know something's going to come down to Pike here shortly just got to give it time so I completely agree with what you're saying but we've seen this story written so many times where we've seen this story before something else will come out right it already has yeah Quantum with quantum computers uh and all of our encryption no longer being valid you know by they're expecting was it 20 26. yeah late 2020s they're expecting that our whole encryption everything will be void and that yeah so this is just getting to the aspect but just snow we're about to redo this all over again so just know the next big thing is we're going to be having a Quantum encryption conference in the next six years right yeah yeah IBM just released a thousand cubits yesterday yeah well what I wanted to do is kind of wrap up down the line here before we get into q a um giving people the opportunity to ask questions to us as implementers but just kind of last thought on you know any advice from a zero trust implementation you can start Sean and just get down this way in the same way nobody rolls their own crypto anymore um stop rolling your own services so says is stepping up to use protective DNS secure web Gateway you have login.gov for human identities citizen facing and internal and maybe to refund a little bit of what Dave said it's it's utilizing or establishing shared services to to do in common what's commonly done is a very near-term imperative um so I will say to me I think we really have lost sight of the human element um human-centered design uh so I mean you know going back to the the passwords and things like that um we need to make sure as we're implementing these security requirements that we're not just pushing the effort onto the users right we need to to be as effective and as secure as possible we need to make it as easy as possible for those users right so like with phishing campaigns right now um AI can write a phishing campaign that has is more successful than any human can write it it's it's pulling from their social media it's pulling from you know correct grammar it's pulling from you know real domains it's using real Services right it has got to the point where I hate to admit it have clicked on phishing you know fishing stuff because they are so good now right we can't rely on just training our employees to be really good we as service providers and implementers need to make sure if we are realizing that we're not overloading the human and their capabilities all said I'm a pretty simple guy I'm going to keep this really really brief but from my perspective take a look and see what you guys or what your businesses are understanding your business right and then aligning that that business with the respecter Frameworks not all Frameworks aren't the same so you have to take a look and see what really drives your business for Success align those those principles with the various Frameworks that's out there and I think you're going to find out that you're going to have a level of success specific to your business or your agency so I wouldn't look at other agencies how they're doing it or other organizations you need to focus on what is allowing your organizations to succeed right so from my perspective I always want to take inventory of my household what's working for me what's not working for me and then kind of go from there and those are all those are good and those are good thoughts on this stuff so what I wanted to do is give everyone the opportunity to ask questions if they had any uh what they've got on that stuff and you know feel free I think you can run the gamut on whatever you want from high level down to low level Implement our questions so bring whatever you got any questions I guess that one over here yes now um so I think um that's a good question so I think it it starts with um you know taking a look what we have currently but you know specific to um what she was mentioning I from my perspective I would you know essentially make um you know basically create a team um but then also uh that will let me step back a second I would actually you know start to form an actual team in order for me to really understand uh what sort of initials and I assume that you're saying this is for for any customer or is this just strictly for your business or will this scale is what I'm trying to ask right so again I need to get some smarter people in the room to help me understand look in order for me to build a solution right that is going to meet the masses sort of requirements I may I may need to have multiple playbooks right that I need to go ahead and follow or to create or develop from there then I can test out the the efficacy or the effectiveness of those playbooks over time go back to those customers and say hey I know that we started with this sort of effort in terms of zero trust it's it's my job to go back and see how they're performing that way I can improve those templates going forward does that make sense and uh so are you looking from a servicenow perspective of like how you would use the platform itself the applications and stuff on the platform or just how servicenow would support that got it okay so if it's more product specific I'm gonna have to go no you just said how well I think how you would as an organization as a vendor would support that right that's what you're asking oh as a vendor um no that's how you answered anything right yeah I think that's how I yeah I think I would just rely on what I just said um previously I wasn't trying to cut you off right um so we have various uh organizations be used you know that we can help towards that um I think our uh you know offices you know to see so is that liaison to collect that's actually my my job in fact is to collect customer requirements and then I go internal to you know within our company uh across various pillars if you will to assess and see all right what sort of services and applications can we help customers onboard themselves to leverage the platform to its fullest capability and or the services that we provide now again we're going to have how to assess and make sure that you are succeeding right so we do have a customer success group right that will you know check in on you every once in a while but we're going to take that actual Intel and see how we can make our process a little bit better for future customers I think it also depends on what level of environment and data you're going to have in your servicenow environment because there are different ways to access servicenow depending on whether your il-4 il5 or they're using the disa cap or self-hosted or self-hosted all those things right so there's a lot of different ways to be able to think about how you're getting to the environment and then how who can get to the environment and what are they able to do once they're there right but I think there's there's a lot of different ways to crack that nut if you're looking at it in terms of how do I get there hopefully I answer the questions any other questions nobody has anything oh there you go you spoke about moving towards uh indicators of action uh versus uh indicators of uh compromise I think uh could you elaborate on that just maybe give like an example uh I guess on the technical side uh or yeah just uh I mean the answer is a personal rant perhaps so we we have our existing ATO system um Federal atos based on indicators of misconfiguration the Mystic 153 catalog is a password 10 characters or two or 30 or 5 is crypto left or right and we have baselines to measure operating systems application servers and we we often fail atos because of these configuration settings so to mitigate that we moved to uh continuous monitoring so the idea is every 90 60 whatever period of time we go and reassess or you'll have a defense cyber practice CPT come in and do a re-audit the the challenge with that is it's all lagging indicators um so then you have people like DOD platform one who will evaluate the configuration during the software build and during the software delivery and that was kind of the next stage and you'll hear it called devsecops but in federal you know DOD Platform One is kind of the Pinnacle and again that's fine we're we're auditing the manufacturing process so that we don't have to continuously audit the output almost makes sense uh however once a once a workload an environment is operational well what do you do so we then have this pivot towards Telemetry and Dave touched on it where we want to get the data from the network and the SAS and the endpoints and the virtual machines and throw it into a sock to do something and that do something is collectively called you know ioas or indicators of activity so we want to take the telemetry from multiple Technologies your operating system your network your identity your application and find what malicious behavior looks like at a holistic view so we'll talk about it as extended detection and response or xdr um what actually drives xdr is is these indicators of activity the Telemetry so we're we're trying to Pivot atos away from rigid compliance of misconfiguration whether it's done in a build process like Platform One whether it's done periodically like DOD Stig scans and actually move towards the collection of this Telemetry right I'll add a little more on from the defense side um engineering defense um so we have so for example we have uh our thread Intel team um and all they're doing is they're looking and saying hey this attack happened here this attack happened here and here are the indicators of compromise uh and so that is our indicator yeah so they have like they attacked from this IP they attacked from this URL they these are the usernames they used here is the locations they came from so those are all uh Indica iocs right and so we take those and I just block those right hey I know that bad actor we're going to block those um and we get rid of that that is retroactive right uh with the actions we are looking for hey we just got a scan from this IP which is normal right I get scanned from the internet I mean thousands hundred thousand times a day but then I got scanned and then they tried to log in right so now that is activity that is someone saying hey I'm probing your network and I found something that I'm going to try to exploit so now when I bring those two ioas together right I don't care I mean I've already blocked the IPS um and I I've blocked the usernames and and things or in domains and things like that but I'm starting to piece these ioas together to um figure out when I'm getting attacked and how I'm getting attacked and miter's come out with a really good with their miter attack framework and their miter attack uh it's a new one that's defense right they came out the the defense framework as well is it's it's coming up with the ways that people are attacking where they're at in the kill chain where that in the process and trying to piece those actions together to look at for compromises so you're you're really taking a lot of information and then like back in time right and then you're running it through this algorithm in a sense to pick these or hey this this actual point in time that's a problem so we can focus on that and now we can have that that actual uh empirical evidence or data to improve our workflows or what we're having right um we are doing in real time through with AI and ml um so I have an old content team that's all they do is build data models specifically for each type of attack and we store all logs over you know we store for 18 months to meet the 2231 or 20 21 31 uh memo uh but we we look over the last 90 days it's called historian so every time any new ioc comes in every time you attack anything comes in we re-look at the last 90 days but anytime we're also storing everything so as those data models are coming in we can say hey this has scanda so many times and get to those beacons because the whole point of an attacker is to get around those detections of signature based detections stay dormant right right and so we we try to look more for those ioas because those are you know more consistent and not something that you would normally detect on a signature thank you okay question in the back hi Sean was talking about xdr and if you most of the monitoring companies now moving to XTR platform right now and if you have xdr why you need zero trust setup a little bit if you have xdr why do you need zero trust um that's like I don't even know how to decompose that so the we end up having xdr to take action and that is almost the the the enforcement point the idea of zero trust is I guess to have a design model that allows us to build that Telemetry from the beginning so you're uh we talked about sassy earlier we want to bring some of the security services like secure web gateways secure browsers um limitations on privilege access as close to the user experience as we can which is a component of it so there's still design patterns that we need to consider when we build Enterprise services that are separate from the ability to take action once an event is found so I would just say that I mean xcr for the most part is just a a pillar of zero trust right it's more of the monitoring pillar um for the most part and the application pillar for the last part it doesn't have it's not the rest of it it's only a piece of it so I also think that xdr is helping in the zero trust model because the whole point of zero trust is to decentralize your security model sure and xdr is taking you know it's not taking the traditional perimeter approach so you have to watch everything all the time which is what xcr is doing you fundamentally won't have the Telemetry to power these decisions unless you bake in design choices ahead of time but you know they use endpoint protection yeah so EDR is a great example um so I you know whether you're taking the Sentinel ones crowdstrikes or polos the idea is you'll you'll deploy you know a sensor on your laptops or you'll do Cloud workload protection and shove it as a like a kubernetes sidecar to get to Telemetry from your containers so yeah these that's a great example like EDR endpoint detection response generates that Telemetry to power a broader xdr decision um okay thank you yeah I felt I don't know if I was if you were playing chump that like stump the chump or if you're leading us well I just want to know we are in process of going to xdr just want to know if really zero trust same thing or no yeah no yeah like I said you have to have the other aspects you have to have the secure of gateways you have to have the sassy the casbi solutions you have to have the identity Management Solutions none of those fall under the xdr the xdr with the EDR and the ndr is getting the Telemetry and doing the response and doing the monitoring piece of proposal yeah overall zero trust extended ecosystem so what's next yeah people want to eat I guess yeah they're like hungry lunch is next all right well thank you guys oh we've got Mike Greco is going to come back up I just wanted to say thank you to the panel panelists for being here and really appreciate your time today and thanks for all your expertise thank you guys for participating in that I'll turn over to Michael Greco thanks guys that was great thank you Dave David Sean will and thank you for your for your time today hopefully you found this insightful um the one thing that we have learned having done a few of these sessions is that it uh you develop an appetite so we want to invite you to join us for lunch out there um and some more networking and discussions uh you know happy to entertain more discussions uh at one o'clock we are going to be running the security challenge so if you haven't signed up is that next door Andrew right next door if you haven't signed up and are interested would more than uh be happy if you join we have done these all over the world Italy London Japan Singapore India and they're a huge success and uh and a great way to rethink about how you handle security operations so if you're interested would love to have you join us so with that we will close our session for today invite you to join us for lunch and anything else I'm missing Andrea no so thank you very much

View original source

https://www.youtube.com/watch?v=jjaE0ZZnbpU