logo

NJP

How to: Get Started with Vulnerability Response

Import · Jan 31, 2023 · video

hello and thank you for joining me today my name is David Adler I'm a senior solution consultant specializing in security operations here at servicenow today I'll be walking you through our how to Clinic program focus on the vulnerability response module within the security operations offering before we get started I just want to start off by reading the Safe Harbor notice for forward-looking statements this presentation may contain forward-looking statements that are based on our beliefs and assumptions and on information currently available to us only as of the date of this presentation forward-looking statements involve known and unknown risks uncertainties and other factors that may cause actual results to differ materially from those expected or implied by the forward-looking statements so we'll be focused on three main takeaways for today's have to session and those are walking you through how to get started with your vulnerability response implementation some key Concepts and skills you'll need to successfully use and Implement vulnerability response as well as providing you with some best practice recommendations as well as some guidance on additional resources to help you in your vulnerability response Journey with servicenow so for the agenda for today's session I'll be covering some challenges we're seeing with our customers as well as in the security Community more generally with vulnerability management I'll go over what we see as the goals for vulnerability response both for vulnerability teams generally as well as those who use servicenow vulnerability response then I'll dive into how servicenow security operations VR works and some of the different components of it then I'll cover some best practices for implementing vulnerability response within your own environment before jumping into a live demo of vulnerability response and finally I'll close out with some next steps and additional resources for you as you work to implement vulnerability response so what are those challenges we're seeing with vulnerability management teams today well as many of you all are probably familiar with in your day-to-day work the attack surface is expanding by the minute digital transformation has only been accelerated by covid and remote work 71 of Security leaders are expressing a lack of visibility into those remote networks and as that digital transformation happens companies are more reliant on third parties who access their data as well as providing access to data to their customer base so that digital transformation has led to an overwhelming amount of work for our security and it teams who are responsible for managing vulnerabilities with their environment um that work can only be hampered by a lack of cyber security resources whether that be on the budget or having trained analysts and while many teams have a suite of tools that they use to manage their hygiene and posture getting the most out of those tools is often difficult when that information is is disconnected from each other and we know that work is only going to continue to increase as the number of critical and high vulnerabilities increases over the years so with that overwhelming amount of vulnerability information it also becomes difficult to prioritize what to address first so many organizations find it difficult to prioritize the correct actions to address vulnerabilities on their Network as well as having difficulty in knowing which assets within their Network are most critical and should be addressed first so I know in my experience and in the experiences we've seen with many of our customers one of the most difficult parts of implementing a vulnerability management process within an organization is implementing that collaboration between your security operations teams and your it operations team so as we know within a vulnerability management process it often falls on the security teams to identify validate and prioritize vulnerabilities on a network and then once they've done that they need to hand off those remediation efforts to our it teams who need to identify who's responsible for implementing solutions for setting the processes and workflows for how to remediate vulnerabilities and then actually taking the action to remediate those vulnerabilities and once that's done the information needs to go back to our security operations team so they have a up-to-date picture of what's happening on their Network now if flow can really be hindered when teams are relying on Antiquated processes such as spreadsheets emails or swivel chair processes which get in the way and slow down remediation time so with those challenges in mind what are our goals when implementing these servicenow vulnerability response module within security operations well we have three main goals for servicenow vulnerability response the first established visibility into the vulnerabilities on your network so we want to get all of that vulnerability data that business contacts and that risk information into a single pane of glass where our security and it teams can get a single holistic picture of the vulnerabilities within their Network next we want to have the right information to prioritize those vulnerabilities so by knowing what we can and should address first we can more efficiently respond to the most pressing threats on our Network and lastly scalability vulnerability teams need a solution which can automate those processes and allow them to respond to all the threats across their entire network so how are we building cyber resilience within the servicenow platform well it's really from the ground up within the now platform we can bring in all of that data from our third party services and devices and correlate that information with the configuration items within our cmdb and we can establish workflows for our vulnerability teams when we couple that with information from I.T service management and it operations management we can get greater visibility into all the devices and services on our Network and correlate that with our vulnerability information which then all leads to the vulnerability response module which allows us to take in all that context from the now platform and prioritize threats and identify remediation Solutions or patches and continuously monitor our assets even after initial remediation actions have been taken and servicenow vulnerability response is not just for devices on your network yes it is a great solution for it infrastructure vulnerabilities but within servicenow vulnerability response you can also address vulnerabilities within your custom-built applications you can identify software assets which have been misconfigured making them susceptible to attack and we can also track and manage vulnerabilities and misconfigurations within our cloud services and containers all from a single platform and just to dive into application vulnerability response a little bit more servicenow vulnerability response integrates with tools such as Vera code which allows you to do das testing and identify vulnerabilities within your custom applications and work collaboratively both with your security teams as well as your development teams to proactively secure those applications before they go into production and serve your customers when we talk about our goals with software misconfigurations within the servicenow vulnerability response we can bring in configuration scanning results from tools like qualis and tenable and correlate that with information within your cmdb to give you business context about your different software assets and reference them against any industry or regulatory standards that you may be beholden to and you can then assess the risk that those misconfigurations have and work with the remediation owners to correct those misconfigurations so now that we have our challenges and goals in mind let's deep dive into how VR Works within security operations and the now platform before we talk about all of the different Integrations that security operations has with best-in-class security tools it's important to frame where servicenow Security operation sits within the security Enterprise servicenow security operations is really that Connecting Point for all the different security incident and vulnerability information that you are collecting across your network and across your different services and devices so for this discussion we'll focus on the bottom left here on our vulnerability and configuration information which gets ingested Into the Now platform and correlated against business context within our cmdb and we can use that information to prioritize vulnerabilities and utilize things such as analytics machine learning or automation to more quickly remediate and address those vulnerabilities within our Network in addition to vulnerability information and business context we can also bring in any threat information that we may get from Community Resources or paid subscriptions which can further enrich the context associated with those vulnerabilities we can also bring in exploit and solutions Intel from authoritative sources and vendors which provide our vulnerability in ITT it teams with more information and best practices on how to address the vulnerabilities they're seeing within their Network one thing I really want to highlight on this slide is that you'll see specifically with vulnerability and configuration information that these arrows go bi-directionally so servicenow is not just using your existing Investments as a source of information but they are fully integrating with those Solutions so when you bring in vulnerability information into the now platform and you prioritize it and use your automation or workflows to address those vulnerabilities once they've been remediated or if an exception request or change request has been put in associated with those vulnerabilities that information goes back to your devices and scanners and updates it so you're not seeing continuous false positives or or incorrect information about things that have already been addressed now that we know where servicenow fits within the security Enterprise we can begin to see how it can really begin to maximize the Investments you've already made for your security team so servers now integrates with Suite of the Best in Class security tools this what you're seeing on the screen is is really just a subset of the out of the box Integrations that you get with security operations so for instance you may already be using something like rapid7 for your vulnerability scanning that information gets brought into the servicenow platform and you correlate it with all of that business and risk context from your cmdb and you prioritize it and connect with your it teams to automatically create remediation tasks for that vulnerability you can then also bring in threat Intel from page subscription such as recorded future and get even more context on why a vulnerability may be more pressing to your organization based off of threats those threat information providers are providing to their customers we also integrate with vendors such as Microsoft and red hat who provide patching and solutions Intel now come into this servicenow platform and are available at the fingertips of your ITT teams to begin remediating those vulnerabilities so they don't even have to leave the platform to find the information on how to remediate the vulnerabilities last thing I'll note here what you're seeing on the screen is not a comprehensive list of of all the tools servicenow integrates with out of the box and even if you're not using something that works out of the box with servicenow we also have a bevy of custom Integrations built by our partners as well as the ability to integrate using apis any custom Solutions you may be using within your security organization so what does the vulnerability response workflow within the now platform well we discussed all of those out of the box Integrations with different vulnerability tools and that's where we'll start over here on the left so we bring in that vulnerability information about the assets on your network and we integrate that into the now platform we then correlate it with information such as business contacts from your cmdb or threat Intel from Paid subscriptions and then we automatically prioritize those vulnerabilities based off business threat and risk context once we've prioritized the the most pressing vulnerabilities on our Network the net platform then automates the assignment of those vulnerabilities to the correct ITT teams now before we get the remediation there are a couple options for your it teams once they receive a remediation assignment if there are exceptions are or deferrals that they believe are necessary for this vulnerability based off of things that they're currently doing on the network or if they believe they've implemented compensating controls for that vulnerability they can Mark those things and send those actions back to the vulnerability teams for their review and acceptance if an IT team believes a vulnerability task has been incorrectly assigned to them they can Market as Incorrect and the Machine learning within the now platform can learn over time which vulnerability should go to which team and get better at those automated assignments but let's go back and follow our path to remediating a vulnerability so that vulnerability has been automatically assigned to an I.T team and then all within the now platform within the same pane of glass they can start that remediation process they can reference information from vendors for solution recommendations and they can start change requests and Patch orchestrations to begin remediating those vulnerabilities once those actions have been taken the now platform automation confirms that those vulnerabilities have been resolved and sends that information back to your vulnerability scanners so they're also working with the most up-to-date information and in turn future reviews by your vulnerability teams are using the latest picture of your network so now that we understand how servicenow vulnerability response works we can then begin to see how we may apply it to our vulnerability management process now the best place to start is understanding how many vulnerability and it teams address vulnerabilities on their Network today without a solution like servicenow vulnerability response this process may be familiar to many of you it's certainly familiar to me in my past experience on vulnerability teams and assessment teams so we start here on the left with our output from our vulnerability scanners which may send us something like a spreadsheet for our vulnerability managers to review the vulnerability managers then may have to manually review something like a cmdb or some other it asset management software to understand that context of that vulnerability and prioritize it once they've manually prioritized it they then may have to send an email or spreadsheet or walk down the hall to their it teams and assign that task of remediating the vulnerability then in order to remediate those vulnerabilities those I.T teams have to take even more manual processes of going to say Microsoft for patching or solution information or even prior to that doing their own review of IT information to understand whether they may just need to defer this vulnerability assignment and once all that's been done they then have to manually put in that change request before they can even close out that vulnerability all of that takes hours days and weeks which as we know as Security Professionals threat actors do not need that much time to cause damage on your network and every hour and minute we're losing using manual processes opens up a window for Attack on our Network so how does a solution like servicenow vulnerability response help break down those silos and eliminate those manual processes in your vulnerability management processes well let's start from the perspective of our vulnerability manager through the Integrations with our vulnerability tools that information is ingested Into the Now platform and correlated against threat and business contacts from our cmdb or Intel feeds and a vulnerable item is created once we see a set of similar vulnerable items those get grouped using automated rules into a watch topic so we can see the full picture of vulnerabilities on our Network and how we are exposed to risk or what teams we need to start working with to remediate those then the now platform automatically prioritizes and assigns ownership and groups those things into remediation effort so just to stop here that remediation effort can be created automatically through rules which we've redefined but if it's of new vulnerability that we've never seen before we can create manually remediation efforts then once those remediation efforts have been created then those tasks are automatically graded and assigned to the correct individuals and teams on our it teams to begin that remediation process again so much of this is automated and happens automatically without the vulnerability manager needing to do anything but there is always that ability to manually go in and and create efforts and tasks so now that that remediation effort has been created and those tasks have been assigned RIT professionals can then receive those tasks within the it remediation workspace and they can use all of that context available to them in the now platform to decide whether to defer or remediate if they believe it's appropriate to defer the remediation of a vulnerability they can start that exception process straight from the platform but if they believe that they need to remediate that vulnerability they can start that change request process and allow them to deploy patches through orchestration to all the necessary assets within the network and once those actions have been taken the platform automatically marks that vulnerability as resolved and that information is then visible back to our vulnerability management teams so I hope I've given you a great overview of the power of the now platform and what servicenow security operations vulnerability response can do to transform vulnerability management within your organization now I know you may be a current customer of servicenow utilizing vulnerability response and if you are I want to go over some of the best practices for implementing vulnerability response so you can get the most out of your investment you've heard me say a thousand times on this presentation so far one of the most impactful things about servicenow is its integration with so many tools so we are going to want to do is really prioritize the integration of your existing Security Services and devices now each one of those Services May integrate a little differently into servicenow I mentioned that we have Integrations out of the box with a bevy of tools and you can go right onto store.servicenow.com and look for your services and see if there's a pre-built integration and you can with your servicenow credentials set that up within your instance usually using something like an API key but if you're utilizing something that is maybe on our roadmap for integration or if you're utilizing something that you've built custom within your organization that doesn't mean that it can't integrate with servicenow you can create custom built Integrations using apis to bring that information into the platform and to that note one last thing I really want to suggest is finding the right partner within our servicenow partner Network so many of them have experienced building custom Integrations or they've already built Integrations for tools that they've seen in other customers so to really get the the most value out of your vulnerability response module you need to set up those Integrations and bring the right information about your network into the nav platform so we can begin taking those actions the next thing you can do to get the most out of your vulnerability response implementation is to have a really comprehensive understanding of your current vulnerability response process in order to properly manage vulnerabilities we need to understand how we are currently managing vulnerabilities or how we desire to manage vulnerabilities this will allow us to establish workflows and automation within the vulnerability response module to make sure that the system is is operating in accordance to the way your vulnerability management organization wants it to now there's a there's a couple elements to consider here for VR we really want to understand how your organization values and prioritizes different services and assets so we can set up those price prioritization rules we need to understand the current policies and service level agreements for vulnerability remediation within your organization so we can understand what the timelines are for remediating vulnerabilities and what goals your it teams need to meet next we need to understand how your organization deploys patches across multiple devices so we can get the correct Integrations and processes in place to more easily and in a way that fits your organization deploy those patches using things like Microsoft SCCM or or bigfix lastly we need to understand how you want to assign tasks and which teams are responsible for what within your organization the real power of vulnerability response comes in how it mirrors the way your vulnerability and it teams operate or a desire to operate to meet their goals so we need to understand how we want the solution to assign those vulnerabilities and to whom the last tip I'll give you is to really understand your assets identifying and classifying your assets is what allows us to prioritize those efforts and tasks that are created within vulnerability response with servicenow you can achieve this in a couple different ways uh you can use your existing and mature cmdb if you don't have a cmdb we would suggest looking into establishing one of those if you have a cmdb but it's maybe incomplete you could utilize something like servicenow Discovery or work with a servicenow partner to get the correct information about your network into the cmdb so we can get that context in regards to your vulnerabilities you can also if you don't have a cmdb Implement something like a third-party it asset application such as big fix or Microsoft SCCM or if you don't have any of that you're not out of luck you can still utilize vulnerability response by establishing manual prioritization rules within the solution so with all that covered let's jump into our demo instance before we get started I just want to lay the plate of what we'll cover in the demonstration I'll be walking you through the sizzo dashboard the vulnerability management and it remediation workspaces and the capabilities that are available to you within those workspaces I'll walk you through setting remediation Target rules walk you through the vulnerability calculator and how you can set variables according to your organization and then lastly I'll walk you through the integration process so starting off in our sizzo dashboard we can get that 10 000 foot view that's going to be really important for our sizzo or our vulnerability manager to get a lay of the land of what vulnerable items are on their Network as well as how their vulnerability management teams are responding to those items so here we can see the average vulnerabilities per asset the mean time to remediate each vulnerability we can see the average age of vulnerabilities on our Network and we can also see a breakdown of which Services have the most vulnerabilities on our Network to understand that that business context if we're a globally distributed organization we can also see a breakdown of countries which have the most vulnerabilities we can see our monthly remediation efficiency and how our teams are are getting better responding to vulnerabilities and finally we can see a breakdown of new and closed vulnerable items over a set period of time now this dashboard comes out of the box with vulnerability response but like most things in the now platform it is completely configurable if we have those Integrations with your vulnerability tools and services and the right data is in the now platform we can configure all of these dashboards to produce the metrics which are most important to your organization now now that we understand kind of a broad picture of how our teams are performing and what the threats landscape is like we can go over to our recommended actions tab and we can see a breakdown based off specific vulnerabilities and what we're facing on our Network so we can see the top 10 vulnerabilities on our Network that have exploits available the top 10 vulnerabilities with the highest impact Solutions you can see the top 10 oldest vulnerable items on our Network so we can know what what's been sitting for a long time and what maybe we need to get around to doing and finally we can see the top 10 vulnerabilities which are most prevalent on the assets on our Network so we can see here that the most vulnerable items seem to be associated with log4j vulnerabilities which even to this day is is not uncommon so this is definitely something we're going to want to start tackling so we can go over to our workspaces and go to the vulnerability manager workspace to start taking action to remediate those vulnerabilities so here we are in our vulnerability manager workspace the vulnerability manager workspace is broken down by watch topics these watch topics can be created using automation by grouping different vulnerable items by The Source or the particular set of infrastructure associated with those vulnerabilities or in this instance by a family of vulnerabilities such as lock4j now a watch topic doesn't necessarily have to be created using automation it can also be created manually here with the create Watchdog button on the bottom left but let's move into our log4j watch topic here in the vulnerability manager workspace we can see Trend information for log4j on our organizations Network we can see an overview of vulnerable CIS so how many distinct configuration items are affected by log 4J as well as their Associated class within the cmdb we can get an overview of the distinct log 4J vulnerabilities and we can even drill down further into the distinct vulnerable items that are affected by log 4J but now that we have an overview of all the vulnerable items on our Network we want to get started with that remediation effort so we'll go up here to the top right and create a remediation effort here we can give it a title and a description of this was populated automatically based off of the watch topic for log4j and we can assign by group so the expected remediation group for this vulnerability as well as grouping by the log4j vulnerability itself so now that remediation effort has been created we can go up here to our mediation effort tab and start seeing how those different tasks have been assigned as well as their status updates so no actions have been taken yet so we don't have any information on how those vulnerable items have been closed but we can see over here on the remediation task tab all of those remediation tasks that have been created off of this remediation effort we can see a rolled up risk score and risk rating for this remediation task and that's based off of the risk ratings of those individual vulnerabilities within that task we can see how many vulnerable items are within that task and we can see which assignment group that task has been assigned to if we want to get a little more granular we can go to the vulnerable items tab and we can see the specific vulnerable items within all those different remediation tasks we can scroll over to the right as well see those risk scores and risk ratings we can see the assignment group and even the specific analysts that has been assigned to remediate this specific vulnerable item and as those actions are being taken by our it groups as we'll see in the IIT remediation workspace this will automatically update with the latest information of how these remediation efforts are going so now that we as the vulnerability manager have identified the family of vulnerabilities within log 4J that we are susceptible to on our Network we've seen those grouped into a watch topic and we've created a remediation off that remediation effort off of that watch topic let's see how our it teams or specific vulnerability analysts will go about tackling those different vulnerability tasks and Remediation tasks all within the now platform so we'll go up to our workspaces and we'll move into our it remediation workspaces and this is where our it teams will see all the necessary information they need to tackle the vulnerabilities that have been assigned to them as part of that remediation Act here within the it remediation workspace we can filter tasks that have been assigned either to myself specifically or to groups that I'm a part of and here we can see a list of all of the remediation tasks that have been assigned to my group we can see that there's 153 remediation tasks there's 53 preferred Solutions available on those vulnerable items that have been assigned to us we can see the number of vulnerable configuration items within our cmdb that are part of those tasks and we can see how many patches are available for those vulnerable items so let's take a look at the preferred patches which are available to us here we can see a list of all of the preferred patches associated with vulnerable items which have been assigned to my group here they're ranked by criticality so let's tackle the most critical one first within the patch management workspace we can see information on this patch we can see its specific number and risk rating and we can also see a description of the patch directly from that solution provider so all of the contacts we need to make a decision on whether we want to deploy this patch is available to our it teams right within the platform here we can also see which vulnerable items specifically are associated with this patch now once we feel we have enough information to go ahead with the patching process we can schedule it right here in the workspace we can group The assets we want to patch either by predefined groups within our cmdb or we can select a specific list of individual assets here we're going to group by computer group we'll select our group here we can give the deployment a name a start time and an end time and we can deploy it and this is where the Integrations come in again for instance in this example this will directly integrate with our big fix instance and that patch deployment process will happen automatically through the actions we've taken on the platform but let's go back to our it remediation workspace and take a look at that log 4J vulnerable remediation task that was assigned to us as part of the log4j remediation effort so here within the remediation task workspace we can see all the information correlated to this task that has been assigned to us we can see the specific vulnerable items within this task as well as the affected configuration items within our cmdb we can see what the target is for this task we can see when it was created and who it's been assigned to as well as a brief description that was created as part of the remediation effort process we can also see Solutions and patches associated with this vulnerability for us to take action on but with all this information available to us we can also go in and create a change request to remediate this task here there is a set of standard templates available to us for different change requests so we don't have to reinvent the wheel each time we want to submit a change request so for this one we'll go with standard server changes and we'll want to use the reboot Windows Server template and all that information associated with this change request gets pre-populated for US based off of the information that's already been associated with this task so saving us a lot of time and effort for our analysts as they create change requests to remediate vulnerability so we'll go ahead and create this change request we can now see within this workspace that a change request has been created associated with this remediation task and with that I.T and vulnerability connection that same information on the change request will be available to our vulnerability teams within the vulnerability manager workspace so we've seen starting with the sizzo dashboard how we can get an overview of the overall health of our vulnerability response process within our organization then we've seen how our vulnerability teams can group vulnerable items on our Network and create remediation tasks based off of those watch topics and assign them to our it teams automatically then we saw how our it teams can go in and create change requests or start the patch management process all from the now platform but to really start getting power out of the platform we want it to reflect the way that our vulnerability response process should operate so there's three things I want to highlight in that regard I want to highlight setting slas or remediation timelines associated with remediation tasks I want to walk you through how you can set a criticality of vulnerabilities based off of the criteria which is most important to your organization specifically and then I'll talk to you a little bit about how you can go into the servicenow store and get different Integrations for your existing security stack and set those up to work within your now instance so we want to make sure that our it teams are remediating vulnerabilities in a timeline that is expected of them based off of our organizational needs we want to make sure that we have metrics to track how those vulnerability teams are performing in their day-to-day efforts so one of the most powerful ways we're going to do that is by setting remediation Target rules and we can do that within the VR module here we can see all the different remediation Target rules that we have set up based off of different criteria associated with those vulnerable items so for instance I'll show you how we assign targets based off of critical vulnerabilities here we can Define this risk grading rule we've called it the critical risk rating Rule and we can set our Target for how quickly we'd like our it teams to address critical risks here we've assigned it at 15 days and then we've also liked to set a reminder period so if something is critical and has been sitting for a little bit with no action taken on it we want to notify and remind those themes at seven days before the due date that there's a critical task that requires their attention and we can set this all based off of our condition so as I said this is based off critical risks so we've set a condition that if the risk rating is critical then this rule goes into effect we can also set rules based off of specific types of vulnerabilities or specific configuration items affected by vulnerability so now that we've set the target for vulnerabilities based off of different levels of criticality we want to dive a little deeper and understand how those criticalities are calculated so we're gonna move over to our vulnerability calculators and here you can see a list of all the different vulnerability calculators that we've set for our organization now these can be turned on and off depending on your current posture or how you'd like to operate but we're going to move over to our default risk calculator and here within the calculator we can see that there are different rules which make up how these vulnerabilities are calculated and in which order they execute so we're going to move over to our default risk rule and within our default risk rule we can see what conditions need to be met in order to invoke this Rule and start the calculation of that vulnerability here it's just that it's an active vulnerability then scrolling down we can see the different criteria as well as the weight we'd like to assign to those criteria so this is where it becomes really important to understand what's most important to your organization every organization is going to have a different view of risk and that's why the now platform is completely configurable to meet your organization's needs going down a little further we can see a table of what the resulting score will be based off of how the criteria that vulnerability is returned and I'd like to demonstrate how this is completely configurable so let's change these weights based off of different organization's needs so let's say that we are a little more concerned with configuration items which are externally facing so we'll give that some more weight we want to take context from our cmdb to add more weight to more critical configuration items and business services within our organization we'll give a little less weight to vulnerability severity that's coming in from our vulnerability scanner and we want to be a little more concerned with vulnerabilities which have exploits that are actively being utilized in the wild and here you can see by changing those those weights for each criteria the platform automatically updates the table and changes the criticality scores based off of those criteria so this is a great reference not only to set criticality scores and criteria based off of what's most important to your organization but also for your decision makers to come in and see a visual representation of how risk is being calculated within your organization so that way your vulnerability teams understand what it means when they see a critical vulnerability or when they see a specific risk score so now that we've set the criticality of vulnerabilities within our organization the last thing I want to show you today is setting up those Integrations for the existing Investments that you've made in your security stack that's so important as I showed in the presentation portion the now platform acts as a Connecting Point for all of your systems of record and when dealing with vulnerability response it's so important to have all of your scanners and different tools integrated into the platform so the first thing we'll do is go to the servicenow store and we can check out different vulnerability response applications and here we can see all the Integrations that are available for vulnerability response now let's say we're utilizing crowdstrike Falcon insights we can click on this integration within the store and we can request an install we just have to enter the specific information for our now instance and it will be associated with our now instance going back to our implementation we want to set up those configurations once they've been associated with our implementation and we do that through the integration configuration page and here we can see all of the Integrations that have been associated with our secops implementation so just to give you some examples say you have a showdown license you've got the integration from the servicenow store now you just have to configure it within your implementation so you find that integration hit configure and you just have to give this integration a name and typically it's just an API key associated with your implementation or maybe login information or some more specific configuration information and then once that's set up then that information starts flowing into your instance and we can start doing all of those uh powerful things that I've showed you so far in this demonstration so I'd like to thank you for joining me today and just to recap um I showed you the suso dashboard where you can get a high level view of how your organization is responding to vulnerabilities then I walked you through the vulnerability manager workspace the it remediation workspace so we could see how our vulnerability and it teams work together to remediate vulnerabilities on our Network then I walked you through how to set up Target rules how to set vulnerability criticalities based off what's most important to your organization and finally I walked you through how to set up Integrations in to your instance I hope that gave you a picture of what's possible within servicenow vulnerability response before we close out today I just want to provide you with some next steps and additional resources to help you in your vulnerability management Journey with servicenow so first thing I'll say here it's important to understand where you need to go based off where where you are now on our vulnerability response maturity scale if you're over here on the left using completely manual operations like spreadsheets and limited visibility then we suggest that you look into a solution like servicenow vulnerability response to begin breaking down silos and automating those processes if you're already a vulnerability response customer and you want to get more out of your implementation then let's focus on automating prioritization grouping and assignment getting all that information from your Integrations or it information into the single system of record which is servicenow and really starting to improve the visibility you have into your vulnerabilities from there you can begin to get more advanced with more automation machine learning and further integration with other parts of your servicenow implementation such as augmenting cmdb data based off of actions you've taken within vulnerability response or integrating with something like servicenow GRC to understand how vulnerabilities and the actions you're taking are affecting the overall risk posture of your organization final thing I'll leave you with here is just some really great resources you can use to get more advanced or get a but better understanding about your vulnerability response implementation I I can't say enough great things about the documentation we have for vulnerability response on servicenow.com you can get information on have vulnerability response works as well as how to best Implement vulnerability response you can get support both directly from servicenow or through our community Through the secops Community page or resources like now create if you want to become certified or get an even deeper dive into VR and secops you can pursue training such as secops fundamentals or VR implementation and pursue those certifications next if you'd like to seek some help in implementing VR you can use our Partner Finder to review all the different partners we have here at servicenow and find which would be best for your organization and your needs to assist you in your vulnerability management Journey and lastly you can go on YouTube at servicenow Community to find other videos such as this one where myself and my colleagues can walk you through all the different powerful aspects of servicenow I'd like to call out we'll also have a sister presentation to this one focused on servicenow security incident response I'd like to thank you for joining me today um again my name is David Adler if you have any questions for me please don't hesitate to reach out there's my email you can also connect with me on LinkedIn and we can discuss how to best Implement security operations or what options may be appropriate for you thank you

View original source

https://www.youtube.com/watch?v=a1Y915CQPbY