How to: Get Started with Security Incident Response
hello and welcome to the servicenow how to for security Operations Security incident response my name is Shane rasby and I'll be walking through ways to best utilize security incident response starting off I just wanted to touch on the privilege and confidential information notice this is covered by the non-disclosure agreement between your company and servicenow as well as the Safe Harbor notice for forward-looking statements as there are some statements contained in this presentation that are forward-looking and this is just based on Management's beliefs and assumptions and on information that is currently available so our agenda for today we're going to start uh by talking about automating the security incident response process as well as goals when it comes to security incident response so what we really want to accomplish and how security incident response Works through servicenow as well as some best practices when it comes to security incident response implementation then we're going to jump into a security incident response lab where we're going to look at some common practices some common actions that you might take within the security incident response environment a servicenow and then we are going to just finish off with some next steps we really want to look at how we are going to go about this and how we're going to optimize these processes so first of all we're going to talk about how to get started with your security incident response implementation then we're going to talk about key Concepts and skills for using security incident response and then we'll jump into some best practices and additional resources so when it comes to automating the security incident response process starting off just going over some challenges that are very often faced by security teams uh these can involve oftentimes two things and that is the inability to prioritize incidents quickly as well as manual and delayed responses to processes so when it comes to lack of prioritization uh we see that 76 percent of organizations have no common view of assets and applications across security and I.T and 82 percent of employers report a lack of cyber security skills so we can really see that deficit when it comes to resources and context in the cyber security sphere furthermore we see 56 of organizations uh having things slip through the cracks because emails and spreadsheets are used to manage response processes so those manual processes causing a large number of slip UPS as well as 62 percent of reached organizations were unaware that their organizations were vulnerable to a data breach in the first place we know that teams are already stretched thin so tools that make us smarter and faster and more efficient when it comes to security and I.T are not just novel but necessary for success and while spreadsheets can be good for things like weekly meetings they are just not enough and don't move fast enough to keep up with threats that move at machine speed foreign so when we look at the threat landscape we can see a number of concerning aspects or concerning numbers or figures um starting off we see 73 days being the average time to contain a breach and a 667 percent increase in phishing emails since March to April of 2020. furthermore we see uh 3.92 million dollars being the average cost of a breach and 78 of cyber Espionage incidents um include fishing so just some figures that really show some of the massive issues the massive concerns uh related to having an insufficient cyber security environment insufficient security hygiene when it comes to businesses and overall we see a 6 trillion uh Dollar in constantly increasing Global cost of cyber crime uh for 2021 we see uh information in the news daily about cyber attacks and organizations being breached and while they vary depending on the incident uh these are often generally revolving around these common issues and these common problems in cyber security starting with the workflows and case management processes that you already have and digitizing those and automating your most common security use cases is going to be one of the ways that we Implement sort within your business and so why do we want to automate this connection between security and I.T uh with servicenow security incident response solution security analysts in it are able to combine their forces to respond smarter and faster so when we work from this collaborative platform teams can easily handle tasks while they still maintain that visibility into their goal at hand so making sure to Route tasks or activities based on skills and assigning tasks to the correct responders it's a really great way to increase efficiency and security and I.T collaboration is critical for success and automating with soar capabilities enables the team to constantly stay ahead of threats so how important is Automation and collaboration between security and it teams well we see 2.5 million dollars being the average cost of reach savings by companies with fully deployed automated Security Solutions so we can see the massive amount of money that can be saved and protected by having these solid security automation practices in place and ultimately that comes from driving cyber resilience and having these operational efficiencies so covering some of the security incident response goals that we have one of those is going to be knowing when threats change and when new threats occur and this comes from continuously monitoring security incidents across your Enterprise at scale and having visibility into your threat exposure identifying security changes in real time and accurately assessing business impact so that you know what to prioritize and how to respond but this can be a lot of work and it sounds like a lot of work for teams to handle that's why automation is so important and when customers do implement it we see them reporting dramatic reductions in investigation in incident triage times furthermore another goal is knowing which incidents are critical and how to prioritize different incidents as they come in and quickly prioritizing incidents relies on business context and severity insights so that we can quickly prioritize things ultimately the single integrated platform that now security incident response delivers enables your team to quickly correlate security events identify dependencies across systems and orchestrate tasks and automate system interactions across the Enterprise to prioritize and align responses before your business is impacted servicenow security incident response support for miter attack framework is a knowledge base of Cyber attack tactics and techniques that is used as a foundation for the development of specific threat models and methodologies that deliver superpowers for security analysts and this is how we can stay one step ahead of attackers by utilizing Integrations like motor attack with our security incident response given that security teams are struggling to understand their adversary's intent when dealing with security incidents and they may incorrectly prioritize security incidents without this Insight we have this new capability to allow incidents to be mapped to the minor attack framework so that we can provide Advanced context on attacks to enable analysts to stay ahead of attackers and reduce the overall attack surface once a security incident is mapped to a miter tactic or technique security analysts are then able to use the servicenow attack navigator to visualize how an individual tactic or technique is used by the numerous adversaries tracked by miter security analysts will then have an adversary perspective and a roadmap for investigations and resolutions furthermore when the average Enterprise uses 75 security tools in their SOC it's hard to see the big picture the security incident record puts everything into one place from related tasks to notes to attachments because the single system of record is also shared with it it's really easy to collaborate and create tasks for them as well but it's important to know that security instant response is a scoped application so it is going to require those separate permissions but this does allow the silicone system of record to communicate together depending on how you want it and just really enables that repeatable and collaborative workflows furthermore another big goal is to respond faster with collaboration across teams so this comes from automating and orchestrating processes and assigning the right owners so we're able to Route work seamlessly between security and it teams to reduce cumbersome processes and manual handoffs during response and Remediation so this allows us to increase performance and productivity through consistent and cross-functional automation and we do this by enabling things like Dynamic dashboards to enable teams to easily communicate and collaborate on response tasks and allowing to have things like reminders for assignees if their tasks aren't completed on time to meet SLA thresholds as well as escalating tasks if it's necessary and security analysts can also communicate with stakeholders from within the now platform via things like connect chat to keep everyone in the loop so how exactly does security incident response work so we have several categories for security devices we have our detection software so these are going to be of course the pieces of software that are going to detect security incidents security vulnerabilities and then we have our vulnerability scanners and these have the function of scanning the organization's environment to detect vulnerabilities and misconfigurations then we have our correlation software this is just a fancy way of saying uh security incident event managers or security information and event management software which is basically how you're receiving the events from several detection and vulnerability scanners on top of these devices we also have things like threat intelligence software that are there to support our findings and give us more information about the events that we ingest so events and alerts are going to be flowing into servicenow along with any user submissions through third-party Integrations or the service catalog and these events are then going to be matched to your cmdb if you have one and if you don't have a cvmdb we can still match these events and map them across our own implementation rules So based on the kind of event we receive the system will automatically kick in the appropriate workflow and these workflows do have to be configured into the environment so for example a workflow for phishing or a workflow for malware etc etc along that process if there are steps that should be automated the system will automatically do so so things like blocking or quarantining something if necessary so just looking at this in more detail we're going to see some names that may be familiar to you so within the detection categories some of the things that we uh integrate with Pablo Alto Symantec then with correlation things like Splunk and for vulnerability and configuration rapid 7 tenable and then we can see also threat and tell with things like recorded feature and exploits and solution Intel as well as our orchestration software so things like crowdstrike and all of these are going to be pulled in and integrated into servicenow used with servicenow so let's say you already have one of these in place um you can use Integrations in order to keep what you have and just bring it into servicenow bring it into that environment and use that data to help with your security incident response process so how does automated security incident response work well we're going to walk through successful implementation as I mentioned in the previous slides once we integrate with these third-party security devices an alert is going to be recognized from one of these devices or multiple ones at the same time the system is then going to be able to de-duplicate that event record and then prioritize the event whether that was through your cmdb or through manual rules we have in place like the location of that incident or maybe even the computer owner if we want to have a rule for people like our c-level executives the system would also be able to pull in some data that matches the threat we have identified and give us data that we can help in making future response action and that's going to take us to the next part and again depending on specific rules we have in the system we can determine appropriate responses so that response can be maybe manually done that response can be either manually done or automatically orchestrated we then finally move on to the remediation step and the beauty and all of this is that the post incident reviews are automatically generated so this allows us to maybe use that data for an audit record or as a lesson learned exercise for the future so we can just see here how through each step we're able to pull in some of those Integrations and go through the various steps and here's just a visual here's just a visualization of manual processes that we often see and as you can see all the Box highlighted in green represent the automated steps in security incident response with servicenow and the purple or as you can see all the boxes highlighted in green represent the automated steps in security incident response and those dark blue as you can see he's just a visualization of the manual processes that we often see so the boxes that are green are going to be the automated steps and security incident response with servicenow and the blue boxes the light blue boxes are going to represent manual steps so we can see how by utilizing manual processes like you may be doing now a resolution that can usually take an hour or two is stretched over the period of days if not even weeks and now a much prettier picture showing us how after we Implement servicenow security incident response automation we're able to turn the response process from Mostly manual to completely automated and we can see all of these different boxes flowing quickly flowing efficiently and reducing that time to Mere hours to respond now I do want to touch on some security and I do want to touch now I do want to touch on some security incident response best practices starting with the security incident response accelerator so the first step into getting your security incident response up and running within your own environment is installing the right Integrations for the security devices that may already exist in your organization's environment the installation to each security device might be a little bit different depending so getting these devices prioritized is going to be a best practice and you can see below the link to the servicenow store um and as well as custom built Integrations and how you can leverage a pre-built partner integration next is understanding your current architecture in order to automate a process we need to understand how that process is currently going so this is going to allow us to build the desired workflow and the appropriate run book and playbooks that are going to be leveraged through security incident response this considers things like prioritization of your organization's services and assets as well as currently current policies and slas as well as workflows and playbooks that come out of the box with any service now security operations license we often see people as well building their own playbooks custom to their specific business needs and those being very useful very heavily utilized finally understanding your assets so making sure that you're able to prioritize your effort in your task assignments and we can achieve this by leveraging your pre-populated cmdb or leveraging third-party asset applications so things like Microsoft sacm and leveraging servicenow's Discovery system as well as manual prioritization rules being relayed I'd now like to jump into our security incident response lab so starting off we want to start by impersonating a role just to get an idea of how that specific role would view the security incident response solution uh in the environment so we want to start by impersonating in the top right here with our user profile uh we're going to impersonate Andrew and this is going to kind of be our view of how someone like a ciso would view the security environment from their perspective or from things that they personally would be focused on tracking and that's where we're going to go to our favorites and go and look at our CSO dashboard so for somebody like Andrew somebody like a CSO um we're going to have a really useful overview here and this is just going to give us a number of metrics to drill down into if we want um so we can see things like our policy compliance tracked our configuration compliance average time to close when it comes to vulnerabilities and security incident responses average time to respond um and things like our risk overview across our environment so really just all of these uh metrics that we could drill down more into if we wanted to give us an overview of our environment and how it's currently performing the other tab I want to touch on here is the incident handling tab so here we're going to see some metrics like our security incident backlog growth our P1 versus P2 incident count and things like new versus closed security incidents and for both of these we are going to have those drill down capabilities so if we wanted to go in and look at these in more detail we could and once we drill down into for example here security incident backlog we are going to be able to look at how this has been trending over time and up here a little bit more detailed summary and we can even kind of customize this view we can see all the options all the tools we have up here if we wanted to do that as well but we're going to jump back out and from here we're actually going to swap to another perspective so from here we're actually going to take a look at another performance analytics-based dashboard and this is going to have a little bit of a different level of detail maybe suited towards somebody such as a security manager or an SOC manager or maybe a lead security analyst so from the upper left of our screen we're going to click on the mycso dashboard Arrow drop down and from here we're going to have a couple other dashboards available to us to visit or we can search up in the top and typing in security we're going to have the option to go to a couple security related dashboards in this case we're going to look at the security incident Explorer dashboard so clicking on that is going to load up that dashboard for us the security incident Explorer dashboard is going to be displayed and here you're going to have the ability to perform some actions such as filtering incidents into your environment based on things like priority and their business impact and we can see here we have those security incident closures By Priority um as well as the security incidents num Total Security incidents listed on the side and then we have security incident assigned heat Maps here so we can really see um where are these security incidents are going uh what categories they fall under and things like that and also how they're prioritized so next I'm going to be impersonating Adam this is going to be our security analyst persona and we're going to see from a security analyst perspective what they're able to do the tools they have at their disposal with the secops platform and so from Adam's perspective we are going to go ahead and from the filter Navigator uh go under our favorites and we can see here in security incidents we're going to open up our security workbench and with our security incident workspace are actually going to be able to see a big list of all of our current incidents so we can see up at the top as well in our quick filters we're able to filter this down to make it a little more digestible so in this case we're going to categorize or filter out our incidents um by our current open incidents with the category of phishing so by clicking on that we're going to be able to get a more specific list of our incidents revolving around phishing and by clicking into one specifically here we're going to go into this phishing report we're going to be given a lot of information surrounding this incident this phishing report we can see um some details and we can see also on the side I do want to draw attention to our Playbook so here uh depending on your specific needs you can customize playbooks to respond to particular incidents so let's say that we found that we were actually getting a lot of fishing incidents coming through if we wanted to we could actually build a Playbook so that we have a more reliable kind of framework to respond to these phishing incidents in because oftentimes you find yourselves doing the same actions going through the same things so our Playbook will allow us to automate some of those more common incident response actions and create a Playbook around that to make those easier for analysts but for now we're going to take a look at our overview and just go through some of that information take note and um kind of see the details surrounding this current incident and we can even go into the Playbook and for now we're going to click on our first uh task which is the analysis phase where we're going to acknowledge uh the user submission and ask if they interacted with the email we see that somebody in the organization has reported this phishing email we want to make sure that they didn't actually click on any of the likely malicious links that were included in this email and by doing compose email by clicking compose email we're able to go ahead and draft an email to this person um just to check in on that and ensure that and we can um have templates for that as well so we don't have to draft any email every time and once we've done that we can click on start task to continue with the steps so we're going to drop that back out and going through here we can see some other information in the explore tab so by clicking down on observables and looking into our observables we can actually see a couple of things here it's identified uh two observables and the one up here these the totally legit website uh malicious website has been identified and so we want to go ahead and confirm that there was a URL found in email and we can confirm that this URL is malicious as it's by been identified by one of the threat lookups that were automatically conducted and we can dig into this farther by reviewing the automated threat lookup results within the same explore tab so right below observables we can do threat lookup results and we see that this has been identified a number of times and the integration vendor or threat lookup solution slash service that the observable was run against along with the corresponding finding and result value confirms that there are malicious threat indicators in the reported phishing email so navigating back to the Playbook task and as you're going through the analysis process you might run into a step like are there related incidents for the threat and this information can be found in several places on the incident record we can also initiate an inquiry that searches all of the emails within our environment with the option of Performing actions on them so if we go to our explore tab under investigation and then search email and observables we're actually able to go ahead and use this in order to look up particular emails and figure out what we want to do with them or take action on what we want to do with them whether it's deleting them to make sure that they are removed from inboxes and through our containment step we might need to perform some sort of orchestration with a third-party integration we have so for example if we wanted to block all requests from a certain IP this can be achieved via navigating through the explore tab so go again going down here and going into our observables and going back to that malicious website we're able to go and click on the check box to the left and by highlighting or selecting this on the drop down list we can choose what we want to do in this case we could allow block requests or we could delete it we are going to block this request and then we could go ahead and click run to start orchestrating that response foreign next it's going to pop up these implementation options and by clicking the lookup using list icon the magnifying glass on the right we're able to go and search what we want to use to block this in this case we have the Paolo Alto for networks firewall and we're going to choose the global URL block list option and then we're going to go ahead and submit that to use this particular tool as our block list also we do always have the option to add new observables if we want to if we run into something as we're going through the process and this could affect the risk score of the incidence and prioritization so in our explore tab once again we're going to go and expand configuration items down here and under more we have a couple options and we're going to go look into our configuration items and from here we can click edit configuration items and it's going to pop up a edit record and by searching for a particular configuration item we can add that to the list so let's just add this for example and then clicking the arrow we can add it into our list and save it so that would be this is an example of if we needed to isolate a compromised asset so in this case the one we've chosen here now next we're going to click the check box next to what we've just added in here and in the isolate host drop down we can see our options here for what we'd want what we'd want to do in this situation but here we do want to isolate the host and so once we hit run we're once again going to get an implementation option we're going to get an implementation option and here we're going to use endpoint protection and from there we're going to be able to isolate our host navigating back up to the top we're going to want to go ahead and go to our closed incident tab so returning to the incident record and going to our closure information tab we could go ahead and fill out our closed code closed notes and if we wanted we could check the box to create a knowledge article and this is going to allow us to leverage that knowledge article for future things like creating a newer updated Playbook or creating a lesson learned exercise for example and then we could go ahead and close the incident from here and that is going to conclude the lab I'm going to jump back to our presentation for a quick wrap up so just as a wrap up in our lab we were able to go over some of the highlights of different tasks that an analyst might have to go through we saw how the analysts could perform some solution steps like blocking a domain on the firewall adding a compromised asset to the incident record isolating the host and creating a new playbook potentially with the information that we gathered also if you do want access to any of the resources today that we went over simply reach out to your servicenow account team so what are some next steps well it starts with manual operations being moved so using spreadsheets for tracking or having no centralized system for security responses can leave teams struggling and crossing their fingers and hoping for the best when a problem does come up so we want to move that into our step one which is basic operations like automated incident creation automated prioritization or improved visibility for example such as with the dashboards that we looked at from there we would move on to things like automated investigations threat intelligence correlation workflow driven consistent processes or accelerated responses and then finally our step three would be to have the full remediation process orchestrated automated having playbooks to respond to certain critical scenarios automated incident response and integrating easily with new tolls through the new now platform and finally here are just some additional resources documentation training videos for example for you to utilize surrounding secops thank you so much for joining us in our secops overview slash how to hope you have a great day
https://www.youtube.com/watch?v=Pu8JdJrHJ2E