logo

NJP

Transform Enterprise Security with ServiceNow Security Operations

Import · Jan 18, 2023 · video

foreign [Music] what does it mean to transform Enterprise security it can mean a lot of things to many different people from effectively responding to the evolving internal and external cyber threats and organization faces to managing and reducing risk along the digital attack surface it can be even defined as managing and resolving risks outside of the traditional I.T infrastructure such as devops the cloud and operational technology with these critical capabilities in mind let's take a look at an example of how servicenow is helping one organization transform their Enterprise security meet Sarah she's the Chief Information officer for a large multinational Bank as CIO Sarah has a lot on her shoulders like weighing the pressures of the current economic environment and all that implies with ensuring her company rapidly and effectively responds if and when a crisis event occurs when a major security incident does happen Sarah is notified about it via text and logs into her dashboard to review the CIO dashboard available from the servicenow store gives Sarah an at a glance security and risk overview of the various areas of her organization's infrastructure in this case she opens the security Tab and can see information about the security operations Center's incident response status how vulnerabilities are being managed how quickly things are being patched and how well their organization is doing to meet compliance benchmarks Sarah sees that there is indeed a major security incident so she logs into the major security incident response dashboard from here she's given a wealth of information about the current incident including the overall impact assessment incident timeline Who's involved in handling the crisis event current status actions and more Sarah wants to know more so she contacts Adam the head of cyber operations for the bank and the person responsible for making sure the business is not impacted when the worst case scenario happens part of Adam's job is to make sure everything is responded too quickly and accurately as the various security incidents and vulnerabilities are being remediated and the tasks are being assigned and managed appropriately the visual task board helps him do just that we can see that patches are already being scheduled firewall blocks are in place public relations is involved Etc Adam can also view the collaboration that's happening to bring this event to a swift resolution some folders were automatically generated when the major security incident was created as well as a log of the team's chat related to the incident all of the information provided is crucial to Adam as it helps him manage the crisis from a single dashboard equally important is the ability for Adam to provide regular status reports to his stakeholders like Sarah and the other executives fortunately he's able to do just that with the built-in reporting function he's also able to keep track of all of the assets and people that are affected by the incident as well as a review the associated security incidents and vulnerability remediation tasks since this major security incident started with an exploit Sarah's next stop is with the vulnerability manager Carla to see how the organization is doing in handling the vulnerability logging into the vulnerability manager workspace Carla can see that a watch topic has already been created for this particular vulnerability watch topics allow her to quickly set up a View using custom variables like monitoring for a new high-profile vulnerability she can also create and monitor the status of remediation efforts set up to patch the vulnerabilities Carla drills down one more level and can see that three remediation tasks have been assigned these can be assigned based on a variety of different variables like geographic location windows and Linux teams Etc in this case they're assigned by geography clicking down one more level Carla can now see that progress that's been made to patch each vulnerability who's responsible for it and if needed can take direct action like creating a change request to assign work via itsm all of this work had previously been handled by spreadsheets and email which resulted in huge delays in both identification of vulnerabilities and their remediation by transforming the processes and workflows they use to handle Enterprise security customers similar to the one we just looked at have seen a 93 percent reduction in high priority incidents and 88 reduction in the time to resolve security incidents and are able to drive overall response down from hours to minutes all with the help of servicenow if you'd like to learn more please visit us at www.servicenow.com forward slash s e c Dash o p s thank you

View original source

https://www.youtube.com/watch?v=B5tjV1wYf7c