logo

NJP

Let's talk about ITOM Security (Discovery, CMDB & ServiceNow)

Import · May 19, 2021 · video

hello hello before we get started please just close your eyes for five seconds and think that you are a security person and all of a sudden you get pulled into a random call by a 20 or 30 year old something consultant who tells you that dear sir in order to build your cmdb we need admin access ouch and indeed that is what we're going to speak about today the very very important topic of item and security so buckle up guys because this is going to be a fun discussion so as you guys can see i am working from a houseboat today and i just like to mention a small disclaimer before we get started which is that some of the things today are personal observations and experiences and my name it is alexander jungstrom i work as the managing director for allen and partners and throughout my career i have been exposed to approximately 30 larger enterprises in these type of security discussions so i hope that you will find my experiences useful and should you have any questions or opinions well you know what to do drop a comment below so one very common thing which i see being repeated again and again is that consultants in security discussion tend to think that it is an us versus them thing we need to convince the security team it is only the security team that we need to get past and so forth and so on and yeah this is of course madness the security team is there for a reason they need to do their due diligence and ensure that they have done everything in their power to stay compliant with any security policies so really it's about understanding their perspective and finding a common ground together as a team and that will just make every discussion much much easier if you show them that you genuinely care about the security they are not a hurdle to get past they are a very very important step in the process so include them super early already from day one when it comes to item discussions actually from a philosophical perspective security is hugely interesting and for me it's always about finding a balance a balance between manageability versus the value you get out of it so let's say you're going to discover a network you're going to build a cmdb of course in theory you can lock it down to the most granular bits and pieces and apply super super security policies to it all and maybe maybe sometimes that is required but sometimes it's also about finding a compromise so everything is not black or white you might have more sensitive parts of the network where you apply one methodology and then other parts of the network where it's less strict you can have another methodology and finding the middle ground between these two worlds is very very important so what i'd like to speak about first if we're speaking about methodologies is actually the agentless discovery approach so let's have a look here so i'm going to try and summarize this security model in front of you in three minutes or less and on the very bottom side you have the ease of management starting from quite easy to quite complex and the security model is based on four levels and the first level it starts with a low hanging fruit here we tell our customers that ok don't use wmi for windows but switch over to winrm per default and of course secure powershell for linux machines use ssh keys instead of username and password and for the mid servers then make sure to do some mid server hardening meaning patching and keeping them up to date for level two that is where it really gets interesting so i've noticed a lot of trends that people are lazy they want discovery to run easy so they only have a few credentials but actually from a security perspective that is a no go it's much much better to segment the credentials and make sure that the credentials are only valid on certain subnets or on certain domains of course and finally for the very sensitive equipment and machines i always recommend to use just enough administration i will put a link in the description below what that means from servicenow perspective level three um that is not a solution which is built into service now but it is something which you would need to construct yourself we have helped customers do this and what that actually means is that you have specific time windows for example every sunday at this time window we're going to discover the windows machines in this particular subnet or in this particular location and only then are the credentials active any other given time they are remaining inactive and that is of course very powerful from a security perspective and finally level four that is where you actually rotate the credentials on a daily basis and you have a lot of credentials stored in service now but you rather have them stored in an external credential store and i know this sounds very attractive but actually having a privileged access management solution it is a different beast to tackle but if you're already using it or if you're planning to using it then just be aware of that you can connect it to servicenow discovery as well so these are the four layers um or the four levels rather and as you can see there is a lot of wiggle room and there are a lot of possibilities which you can utilize so keep the security model in mind when you are doing your agentless discovery all right all right i know what you're thinking but alex why do we need local admin access for windows and this is a simple question with a simple answer so in order to discover the running processes and the network connections for all the logged in users to a particular windows machine you actually need local admin privileges um this is a design choice by by windows it it is not a requirement from servicenow but it is actually related to windows security but i always guessed it gets this question and yeah i just wanted to throw it out there that is the reason why servicenow requires local admin for windows machines one thing which we haven't spoken about yet is what are the options to the agent let's discover in servicenow well you might already be aware of that in the latest release then an agent-based approach is also offered and actually we created a video series about this which i also will put a link in the description below of course at this given time when this video is being recorded then the agent-based approach it comes with certain limitations nonetheless it is a very very valid approach that you can use in combination with the agentless one so have a look at it and definitely consider it as part of your discovery roland plan so to end this video um i think we can conclude that there is a lot of flexibility when it comes to servicenow discovery and how you approach the topic of security granted we have not touched upon the technical bits and pieces in depth there is a lot more to be covered from a process side but as a starting point i hope that you found this useful and that you realize just how much you actually can work towards a more secure discovery rollout and strategy and of course as always don't forget to like don't forget to subscribe and keep on the loop on our youtube channel in order to stay up to date on the latest item stuff thank you so much for watching

View original source

https://www.youtube.com/watch?v=K0BVqi8jl40