Snyk Peek: Application Vulnerabilities Delivered To ServiceNow Application Vulnerability Response
so welcome welcome everyone welcome to live on servicenow with sneak uh my name is Aaron Bennett I'm Tech alliances manager here at servicenow and I'm proud to welcome uh this neat team plus one of our own uh to present to you um this uh Community webinar so Marco Morales Aquila manigoli Wendy Swank uh welcome and I'll turn it over to you I'll start sharing my screen in one second and go ahead and feel free Wendy or Aquila to uh let's talk about the results of our poll I mean did you want to take that sure thing okay so our first question what brought everyone to the web webinar today looks like we have a good balance of um our press release which hopefully everyone did see on on the 24th we issued a great press release that um really shows the Journey of servicenow and sneak from um being a client of sneak now our partners in an investment news as well so that was very exciting looks like our second question are you leveraging sneak and servicenow today a good mix of about 15 of the audience leveraging sneak 45 leveraging servicenow nine leveraging both and 30 neither so this is a great opportunity for those of an either Camp to learn more about what we're doing together you'll see the strengths of servicenow the strengths of sneak but of course the Better Together solution is the the real power here who will win the big football game this is kind of sad 45 said what game well all right so we gotta have some additional enablement here we have 27 on the Chiefs I think they have won too much and I'm a Patriots fan so I'm sure people will say don't say that Patriots have won too much but we have been looking terrible this year naturally um the Eagles 27 all right so it looks amazing yeah pretty even on the teams but the the surprising part is the what game all right so with that thing we're welcome to disinterested absolutely of course of course why don't you go ahead and introduce yourself and let's get this thing going sure I'll leave why don't you go ahead and since you've been talking excellent well thank you again all for joining my name is Wendy Swank I'm Los located outside of Boston if my um a team affiliation didn't give it away um uh Alliance manager here at sneak working with um our strategic partner servicenow and working very closely with Aaron Aquila and a lot of the other servicenow folks very happy to be here today hi my name is Marco Morales I'm a partner Solutions architect at snake um and I'll be doing the sneak side of the demonstration I am from Chicago I presently live in in uh Philadelphia so I'm supposed to be rooting for the Eagles uh I will go next Marco hi everyone I'm a particular architect part of tech Alliance team from service now work closely with Aaron and of course on the partnership of on sneak with Wendy and uh Marco and I'm from Bay Area okay so today we're going to be in the next say half hour or so we're going to show you a couple of slides to introduce and give you context our goal today is to describe the latest and the new and improved or however you want to call it integration sneak Hazard servicenow so we'll show you some of those things and then we'll do some demoing to show you how people use sneak to provide context some of you may not be developers some of you may be but it's going to be here's how a developer uses sneak and then how it plugs into servicenow so if you're brand new as of January 24th we have a new app on the servicenow store um we we we did this over a period of several months we're really excited we want to start conveying certain ideas that we're going to hit home a couple of times during this presentation or in this demonstration first is that we're going to help you all your entire team track and manage vulnerability so what's happening is um with today's devsecops teams sometimes people don't have full visibility so we want to help your entire team track and manage those vulnerabilities we also want to be give with this enhanced visibility the chance for your team to make decisions a little bit faster which we believe and we also want to pull on the idea that this is a unified view across your entire team including your application security team Security Professionals which may have been previously disconnected um this whole this whole idea here is to give everybody a view so that you can all understand the risk of what your vulnerabilities are and I'll show you a couple examples of what that means let's get started introducing snakes so snake it's a developer security platform if you've seen any demonstration or visit our website you'll see and hear us talk about word developer first really what that means is we try to work within the day-to-day workflow from developers we try to provide all these tools and experiences for their benefit so they feel very comfortable using our products we have more than one we have sneakode which is for what people use when they write code some people call that SAS or software application security testing that is one of our products we also have sneak open source which is going to be the primary emphasis in this webinar open source are the libraries that developers may bring in as they build and create software we also have other products for a snake container this question does come up often we are not covering that today but it is for those people who create containers we have sneak ISE for infrastructure as code we have sneak Cloud for cloud deployed assets again we are going to emphasize sneak open source and know that people have other questions but you'll see a lot of the conversation only around this um this solution here why snake so this is a why should you care so we have a bunch of different assets out here and I am going to speak to a couple numbers so snake has the world's largest open source Library database and that's pretty cool for us we have more vulnerabilities in our database than any other company which we find is really helpful because oftentimes we've learned in the example here in the middle that some vulnerabilities hit our database first before anybody else at a pretty good rate we also offer ideas around how to help your teams work with false positives many of you have seen a phone book a very large number of vulnerabilities we're trying to eliminate those as much as possible and we also want to provide you and your team the right context and guidance so that they know how to solve and address these vulnerabilities it's one thing to be told you have an issue here it's another one to be told here's why I exist and as a third thing for us to tell you here is how you fix it and we'll show you a little bit of that today where do we fit in so this comes up often in terms of where does snake fit in how does it work I am a security professional we want to emphasize that we are primarily in the application space many of you may be familiar with perimeter or networking uh defenses sneak is not that and those are great Solutions we have Partnerships we have we're friends in them we respect them but we are primarily around the software application that you and your teams develop at this point I'd like to turn it over to Aquila to give you an overview briefly about servicenow thank you Marco you know I was just thinking where to start with service now right um I don't know I'll just start from the beginning so I don't we have a lot of people on the webinar uh I don't know how much you know about service now so historically we know that service now started as ID ticketing solution right but over the past few years folks have seen just how much more service now has done and is doing so it's the service now starts with the now platform and it's breadth of capabilities all of which we can leverage in various Industries we serve today it could be fin serve it could be Healthcare it could be many other Industries and also the verticals we serve like um the solutions a portfolios we serve like ID service management ID Ops management it would be security operations risk and the latest one to add to Alfredo is the ESG the HR Service delivery and so much more and you know as we say service now helps the world work better that's what solution stands for but you know as Marco was sharing in in today's presentation we are going to limit to vulnerability response so as I was talking about um Security operation the vulnerability response module is part of that at the broader secops module which really helps organizations to to manage their attack surface management so when it comes to Tax Service management you might be familiar there are multiple different kinds of vulnerabilities in organization organization can be exposed to there's infra vulnerabilities there is cloud vulnerabilities there is you know as Marco's talking about container and all of that the vulnerability response module supports basically by bringing in the data from you know integrating with multiple scanners you bring in the data to service the platform and then on top of it you can add the features are part of the wall response module co-mingle all that and which makes the remediations faster for the Target teams but you know again dwelling uh just going uh a level deep within that is application vulnerability response so which is part of the broader wall response which focuses mainly on the application vulnerabilities So within application vulnerabilities if you were to think there are multiple different kinds of vulnerabilities there is a you know sast which is a thermostatic application testing uh security testing and this test which is dynamic application security testing and there is software composition analysis so with sneak and service dog Integrations we are going to bring the software composition analysis results found from snake platform into the service now vulnerability response module and you might be familiar that you know developers tend to use the open source components in their code which is a very very familiar concept that said that exposes so much risk and that the open source components does have you know multiple vulnerabilities in built into them and how do we mitigate them and sneak is one of the top planning tools that is known for SCA vulnerabilities and a sneak integration of sneak with service now brings all the data for you in a much higher level fashion within the celestial platform and the mixed developers lives really easy but can you go to next slide yes so I touched based on this already a little bit as you see um you know application vulnerability response expansive or SAS dashed SCA pen test and and furthermore and it could be API security today's standard world right so we for today's conversation we'll be focusing on software accomplish analysis results of integration with sneak and service now Mark I want to take it from here um I was on mute thank you So today we're going to show you how you know we cover these Asics here you know it is a new app we're excited we want to show you how we provide visibility and let's now start getting into a demonstration of the the everyday workflow of a developer and how this gets absorbed and fed into servicenow so if I'm right this next slide oh again we're here Better Together infinity loop this is fantastic stuff but the part here is we're going to show you sneak I'll do that for about five ten minutes um and then Aquila is going to pick it up with how this information is picked up in servicenow so from here I'll transition over to a different tab I'll have more than one tab that I'll navigate into to just give you a feel of the everyday um you know life cycle of a developer so first and foremost I want to just draw attention to a public GitHub repository that sneak hosts and we have a number of deliberately vulnerable applications we have them in different languages this one happens to be node um we have Java and other ones but we provide these as public assets for you and your team to inspect and try out one thing we do recommend is that you do not again do not run this in a production environment these are deliberately vulnerable because we run exploits today I'm going to leverage some of these um these vulnerabilities to just show you how it works and how it looks within sneak next what I want to do is show you an IDE I've made the fonts big and high contrast for your benefits you can see if you like you know small fonts in dark mode we'll do that at a different time but for today and we'll just look at it in nice and easy and an easy View so what I have here is the actual clone repository I created a fork and I have it in my environment and what I want you to appreciate if you're a developer or not is you know we try very hard at snake to give the developers an inline experience if I do this to write all the stuff that I'll show you is going to stay within the IDE of course your developers can go elsewhere but when your development team is writing their code and using open source one thing I forgot to mention during the presentation is we've discovered that anywhere between 70 and 90 of the total application payload in modern applications is of actual is actually open source so that means developers may be writing 10 to 30 but they bring in a lot of open source and that's where this example comes in so I'm a node developer I have certain files the file in the middle which is packing Json is something most node developers are filming with and they'll say I know what this means on the left what I've already done is I've navigated into the sneak extension on Visual Studio code you may be wondering do we support others the answer is yes we do have IntelliJ and Eclipse but in my day-to-day I tend to use Visual Studio code because it just happens to be of my benefit if you look in my screen closely you'll see I have the open source security panel open but I've closed the code security and the code quality which are around the other products again I want to emphasize one more time we're only looking at sneak open source for this servicenow integration at this time so developer has this information they're looking at it and they manage their own work within their life cycles maybe they make changes whenever they can or maybe they use ticketing systems but the idea that sneak is trying to support is we will give your development team all the information they need as they're doing the work so they can triage and do the right thing you'll see the letters like C for critical H for high these indicate high and critical uh severities for vulnerabilities there is a lot more that we're going to dive into but these are all signals for your development teams to know what am I working with what am I looking at I've highlighted one this Jason pointer because it happens to be a critical it's like the second one but I could have done handlebars the information we have here you will notice is going to be available in a variety of formats here's when the IDE later I'll show you the the the UI on the web application what we try to do is we try to provide people as much context as possible include including the CBE database entries which are public assets that contain all this information anyone can look at it this is a way for you if you're curious or just want to know more can click into and study them but at your fingertips here you have a number of things like we described the problem we tell you what to do in this case it's a version upgrade and you can then choose to operate within your team's workflow your sdlc to address this issue one of the things I do want to show and your team will have different um different ways of using this information if they want to use pull requests and so on we support all those things a question that sometimes comes up is what repositories that we support we support all popular git repositories this happens to be based from GitHub but bitbucket and gitlab those are all equally fine on premise or or hosts that are also good what I'm going to show you here is some developers do like using the command line I already have it in my history I'm going to run a sneak um scan for open source and it's only going to look at the critical issues it takes a few seconds I get my results this kind of information is useful for those teams that'll make this big this kind of information is useful for those teams who have members who really enjoy or like using the the command line maybe they use Json output or maybe they include this into their build operation for any number of pipelines that we do support this again I hope you can see helps you see how a developer can do all this work to manage their workload within their ID environment they don't have to leave it and they can do everything as as they know and they love next I'll transition over to a more global view which has the same information in our UI sneak is a hosted application I have there's organizational structures we have these things called groups and projects where really think about it's like a nested foldering type of structure the application I have happens to be forked under my name and the information we have here is in graphical format and UI same kind of information that you have with the ID where this helps people is if you and I are working the same team maybe I don't have my laptop or maybe I just want to open up a browser or maybe I'm a leader or someone doing a drive-by and I just want to visually inspect the status of my teammates other activities without having to do all the IDE work and other things this is available for them package Json if I click into it is going to give me the same information but in a more familiar ui-centric way than most people are are accustomed to when they use these these different tools I can talk through all the different fields that we use to help your teams prioritize but the really the biggest Point here is you can probably start to deduce that much of what we've been doing is around the structure to help developers work help them collaborate help them do all this work so that they are best equipped to address software vulnerabilities appsec is probably on the side wondering when can we see when can we do stuff and Akil will show you that in a couple of minutes but I want to close out with just a few more points the details I'd like to show you here um kind of go along the lines of how we provide the explanation to developers but one of the things we know it's really important and it's used in the service now side of the demo is that we have a concept of a priority score what we've learned over time is that sometimes people use one dimension like cbss score to prioritize what snake has done with his Intel database and other proprietary and open open information as we've used informational is does this vulnerability have a known explain in this case the mature exploit does this vulnerability have a fix available you can imagine if there is an exploit that is known and there is a fix that's available your price priority scores should get bumped up the filters on the light left help you do some of the right things if I were to click on critical to limit to just three and see which ones are fixable or whatever the numbers are here this really helps you and your team figure out I can solve something very soon you can see there's nothing that's fixable but partially fixable is other stuff that we have oh again this part of the demo is uh I didn't do this track but you can see the the intention behind it this is the kind of information we want to have your development team have at their fingertips so they can do the right thing the last thing I'd like to show is something about dependencies if you recall on the IDE screen I had a small list of I'll make this terminal small I had a small list of direct dependencies that me and my team listed you can see there's probably about 30 in this list if I navigate over into the UI you'll see that I have over 700 so this is something that's really important for those teams because transitive dependencies are really critical for how we do this what happens is I use open source software but the providers of that open source software may use other packages as well and then you get this lovely tree when we look at the details behind the vulnerabilities you'll see that tree spelled out as this brings and this brings in another thing and so on and that's available to your teams for you to use in closing I'd like to just demonstrate that we've done our best so far and we will continue to try to empower your development teams to address software available is as they encounter them and manage it in their own time now Akio is going to show you how we give access to the application security folks in servicenow visibility into what's happening Aquila at this time I'm going to transition over I'll stop my share and let you pick it up thank you just a second I'm just bringing my good evening already thank you brother that was very uh detailed walkthrough of sneak platform and how you users can look at developes within sneak platform and you know the additional features of that have been all of that so the good news is you know now you've seen how snake scans the application available and reports it for you at you know and you can go see all the data there but and with this integration with the sca integration with sneak in service now we can bring in most of that data back to servicer platform and make it visible for you and I as I was sharing along with that we can make use of the application vulnerability features we have like Risk over respirating assignment rules combine with all of that which helps you the security teams and the developers to prioritize which volume it is they want to be fixing first not only that the post um remediation steps can be automated based on the process that you follow right all that is feasible and possible on service or platform and I'll just take a step back before I uh you know start deep learning into the data I'm showing on my screen so what are the benefits of using application vulnerability response module itself um you can find and prioritize the application vulnerabilities faster and we can remediate the um availabilities and the visibility across the team and we can automate the prioritization and risk management using the configurable risk or calculators and rules and uh we can the response activity can be driven much much much faster and efficient with by development teams and um not but of the least pinpoint development issues proactively all this is possible just using the application availability features now now I'm going to show you the data you're seeing already this is the data we are brought in from the integration so the integration itself makes makes use of the oauth Authentication and once you authenticate there are import jobs in place when you run them that the input to bring in the data into the platform of course there's a lot of processing that's happening you know all of that is in place and call using and making sure that there's no duplication all of that is already in place so once all that happens the records get created in application availability item table which is the application one response as you see the stores you're already seeing here as sneak so I'm going to Deep dive into this data a little bit here now and you see the risk of populated risk rating the state and the remediation Target if it's already already was you know set so let's take a look at one of the a bit if it is nothing but um a unique combination of a vulnerability to uh endpoint that's that's what any of it is but in application vulnerability it's invulability existing on a unique um application release so um what is the benefit of this integration right the sneak and service now integration you will have an ability to bring the project from sneak uh which you're seeing already here I'll walk you through that also in a little bit into service now platform AS application releases and packages and understand applications and you'll have an ability to bring issue from snake into servicenow as vulnerabilities application vulnerable items and packages and you'll have ability to link application release and scan applications using the well-known CI lookup rules that are provided within the platform and also additionally based on the how your organization operates you can also add additional CR lookup groups if need be and not and finally you know everybody needs the organizations need the data visualization so that's already in place which is a very friendly dashboard which the limitation teams can utilize really well so um as you see here I I'm going to highlight the application release and you see the package and as I said Avid is a unique combination of a vulnerability which is already a thing here which is a CV with that number on an on a packet that was found in a snake platform if you were to scroll down a little bit on this record you would see something called a source link Source link is a drill down link which will take you back to the sneak platform for this particular application vulnerability if you were to were seeking additional context so many times what I've seen is the remediators or the in this case it's development team or the security team if they were looking at this vulnerability if they need additional context they have to login back to sneak platform separately and then start looking for this particular application release and the vulnerability but here we made it easy for you just this link will directly take you to the vulnerability found where you can get additional context that you're looking for along with that it also shows you the vulnerability summary and the recommendation how as Marco talking about you know sneak does provide recommendation on many of the vulnerabilities that are found already how this can be remediated so all of this data above and combined with the features of vulnerability response like calculating risk and risk scores it will help developers prioritize vulnerabilities at a faster rate and the assignment rules you might be seeing here so there are predefined assignment rule it it manages to assign to a specific assignment group based on the configuration that's already set in place which is exposed to end user to do that so um along with all of that you can also drive all these you know prioritization based on the cmdb that's already populated with the application release data so in a nutshell sneak data sneak SCA data along with service application vulnerability response module helps developer and security teams remediate the vulnerabilities at a much faster rate so with this smart wall stop sharing and give it back to you thank you at this time I don't think we have any more slides to show but we'll have to show screens if people have questions um I think there are a couple questions um Wendy do you have any guidance situation we should address first yes let's start with um in no particular order I'm just going through ones that we got in the chat that were um excellent I think for the whole audience to hear first one being how do I find the app is it free or not um Mark why I can take this but I did post the link um in the the Q a section our app is live in the servicenow store today it is free to download um you will need certain entitlements on either the servicenow and sneak side in order to leverage but the app is in the store today just head over to the store you can type sneak right into the main navigation search bar and go ahead and download that thank you Wendy I'll look at the first question the sneak UI provides almost all the details required for vulnerability remediation what extra does servers now offer so one of the in the Aquila you can pick it up after I start but one of the things we've learned in in the numerous um requests we've had of customers is the servicenow user population application security security-minded folks don't always have visibility onto the day-to-day life of of a developer there is friction there's a desire of the security folks who say can I see can I understand do I need to push a tool down onto there's all these questions around understanding how the developers are managing their issues what we're doing is we're encouraging developers to address vulnerabilities as much as a mechanic and Grant visibility into the into the the service now population Aquila if you want to add anything please go ahead I wanted to keep it short on purpose yeah I know I think I think you've covered it Marco thank you for that okay thank you that the next we've got a few coming in so let's hit all these questions then okay we'll see when they slow down yeah if I understood the uniqueness won't there be collisions on package names and CVS across groups or orgs with multiple package names of the same value um so so I think um Wendy I think I need your help here this question does come up so if if the same vulnerability comes up again in the same package I believe I'm right to say you don't get duplication but if you have two different packages two different software um applications that have the same dependency those things do show up separately as two different times Wendy that is correct okay you nailed it yeah how does this work with multiple groups so there's a lot of language here and maybe the anonymous attendee can can post the follow-up so groups can mean a lot of things servicenow has probably its own term snake has its own team your company may have its own term um and so maybe what I want to hear is a clarification because we um if multiple group says I have two different development teams or multiple groups means like two different groups and sneak um please help me understand with a little bit of a clarification on that um if so I can better answer what do you mean by how does this work with multiple groups unless um some of the people on the phone or to call have a have their own perspective why do we sign vulnerabilities to to a group why not group them and assign them in service knowledge we do for infrastructure vulnerabilities um Aquila I'd like to lead with your answer first and then I'll color commentary group why not group them in a sign in service now like we do so the assignment group is very similar uh uh sanjiv it's um the assignment group rules are the broader you know um it comes in the configuration side it works very similar to um both infra and application vulnerability so there's not much of a change so I I'm kind of confused with your question if you were to answer other grouping rule from Health yes there are grouping for functionalities yes okay sneak also collects Dependency license information yes that's right is that information pulled into the service now platform I see when they Swank my counterpart is typing an answer and I'm waiting with baited breath Wendy if you can type it in yes um this current integration does not pull in the the license data okay thank you um I see it disappeared too are there group uh how do we assign it's a weird ass so I'm looking at sanjeev's um 11 31 a.m Eastern question are there grouping rule functionalities for application vulnerabilities Aquila is that yours which one um this will be the one at 11 31 my time so it's from Sanji that's when I asked to send you a question he reposted so I I can't okay thank you how real time are the updates of service now so there is a scheduling component right the the uh there's a I'm sorry there's a batch operation um I don't know the timing um it can be triggered by human um what is the timing on this is just to add to that so input jobs can be scheduled daily or you know based whatever at different frequencies but pretty much what I've seen is organizations schedule them daily and uh after the daily import job that run you know the data is refreshed from and it matches with the snake platform to service now at that point okay is the 11 32 the anonymous attending the multiple snake groups um common is that a clarification from one of the previous questions was that a new type of question I I also interpret that as multiple sleep deployments possibly or like differentiated environments where you might want to pull that information into servers now together right so when we say multiple differentiates sneak deployments are we talking about uh well so what are we talking about uh help me understand Aaron so say you know company a has a sneak deployment and then they acquire Company B now they have two yeah so that's something that's a that's a so how this the the end of the day type of question is depending on how those two organizations get Consolidated within sneak and at a very simple level snake has say starts with two primary structures a group can have many organizations two different companies are likely to have two different groups if we combine them if the two companies get acquired or merged or whatever how those companies want to maintain their assets is going to be something that affects it if you have two separate groups you're not going to combine into the same service now environment it's maybe the better one they'll be in separate um in locations go ahead let's say I see a good one um we might want to hit on is Sneak UI provides almost all the details required for vulnerability remediation what extra does servicenow offer obviously a question for Aquila or Aaron yeah I can add to that so um just take a step back um you know it's it's a great integration with for SCA results to bring in uh inside service now but I'm just looking from from an organization from a security perspective they might be using multiple tools for multiple different application already scanning so with this you can have your SAS task and SCA everything in one platform that's one way to look at it right you can see all the data as I I don't know if you recall I have a showing on my screen it that we do have a source field which specifically shows which of the data is coming from So based on that you can group your different scanning you know Imports and then and then remediate them at once and have a global view of what's happening within your application vulnerability uh for the given organization so along with that from the remediation standpoint you can always use the additional workflows built into the vulnerability platform itself that can be leveraged to uh to move the remediation faster and do you want to add anything here additional that you can think of um well I think the other answer is is sort of more um you know Global it's you know having a data in service now um you know having the audit capabilities of servicenow layered onto the sneak tool without you know causing any kind of conflict or you know friction with sneak users so we're not taking them out of their environment to um you know submit issues or do anything it's all transparent so that's that's essentially the the biggest you know boost that we get is that these groups can work together without any visible conflict or friction between the two tools they just continue the regular operations are we at the question from Sir Rob what do I need to have in cmdb for CI rules I think that's your question to work efficiently and not end up with unmatched CIS it's a great question saurabh and you know um that's an ongoing struggle for all the organizations right so um you know coming back to cmdb we need to have the robust cmdb to start with for the CIA look up close to work that said that's the first step you know how how can we measure the health of the cmdp I know I don't can really uh add in more here you've been working on the different seem to be connect with them himself um but that's that's a you know an ongoing um problem and a solution for you know it's an ongoing work I would say right um how do I keep the health check on for cmdb and that way I can make use of the Sia Luca proof better so that it won't end up in the unmatched CI so that the short answer is to have a good CMD populated before you start but as I said you know realistically we have seen that you know it's it's not a easy it's very easy as said than done so it's it's a bit of a lot of work there to have a good thing okay answer sir Rob we had a question at my 11 36 from an anonymous person snake UI provides almost all the deals we did answer that question live um and and the and maybe we'll have to back up the video next time to get a chance for it but I want to keep moving with the questions is there any triaging functionality built on the service now side for example marking of finding as a false positive or the ability to ignore vulnerability finding it so it doesn't show up as a risk anymore um I'll start the answer I think the answer is no um we don't have that um ability to trigger or change the state of issues in snake from servicenow but please other people please answer no you're right uh the current uh available features for application vulnerabilities or either you can close or resolve so uh that's that those functionality is available for infra but not for the application yet yeah that's more of a function of the nature of the object because you know obviously if you've got a different version of an open source repository it becomes a different entity um so you know you replace an object like that you don't actually like patch the open source um objects so it's a bit of a different you know mentality from an interpretable typical infrastructure uh approach similar to container vulnerabilities we don't actually update the container we replace it with a different container right let's make sure we're not marking these questions off as we go we don't miss any so um I saw that there was like were we on triaging functionality if I'm going down the list of questions I see a few more I want to make sure that we we hit the automation closure obviously like those those details are picked up a lot of the work in service now and then going back to the question about what the extra value is the extra value is that the developer does not have to design a security workflow around their um their you know their developer activities they don't have to manage it you know these little security team is more especially you know focused on on those sorts of workflows and so that's what search now provides such as like a in a deferral process in vulnerability response so go ahead Marco thank you I think what I've seen before is people write effectively to some type of script to automate the importation so we we've done all that work for you and the reconciliation so this is this is a few a few things you don't have to worry about anymore that that we're doing so that it's uh it is done more automatically yeah auditing reporting visibility you know rolling risk up to the greater organization so that you have security results from your infrastructure Employments your production and your you know coding development you know those sorts of things that you know would be just a headache for a developer becomes something that the security organization can do in service now yeah um so we're gonna go into Trio is there any triaging functionality built in the servicing outside for example marketing and finding false positive or ignoring um I think we just answered that question yeah thank you and the last one is sneak in itsm integration makes sense but I'm not sure about the sneak in VR integration um I'd like to lead with the servicenow team yeah I think it's an interesting observation um you know I itsm you would just have the data there and as I don't know talking about you don't have the ability to integrate with disabilities workflow first of all to start with right uh it doesn't have the remediations it doesn't have the assignment rules or or the risk or risk creating you know prioritization all of that is not feasible within itsm integration yeah I'll say Kila it's possible that it makes sense to have an ideas of integration then you're talking about a different you know you're talking about a different objective so if you're talking about fixing something in runtime like say a service outage or something like that then yes obviously we'd want to do that we want to make sure that we're getting the right data from Steve and correlating into the right type of incident for a service operations to do something like that whereas in this case we're strictly looking at risks created from security vulnerabilities that are ongoing and you know possible or accepted risk that we have to take into uh production and how do we mitigate that risk this is that's sort of more the approach of this impression but that's a good question for the use case we are discussing here it it fits well into the VR integration getting a sense of the questions Aaron and Aquila Marco um folks on the line and I think in general a good observation is that a lot of people are used to the traditional infrastructure scanners which this is not I think it might be worth a minute of explanation of the traditional like the qualis rapid seven um those scanners real quick Wendy while we talk about this I wanted to launch the poll because it looks like there's some interest I don't want to I don't want to keep people on after the point of time if they need a break for the next meeting so especially if you'd like some further answers on these questions I would encourage you to um answer your guess for this poll and we'll reach out and make sure so I'll leave this open while you uh yeah thanks for that Aaron um I think just a moment of explaining how this is different than the traditional or classic infrastructure scanner it might help the audience as well Marco and Aquila if you guys want to want to take that miracula do you want to go first so I mean start with the infrastructure being you know it's the way we understand infrastructure is you're scanning of our environment you know it's focused primarily on running you know runtime Hardware computer servers um maybe virtual virtual infrastructure in you know you know in a location not necessarily Cloud it seems that's a different thing oftentimes um Aquila do you want to go into how um you know this source code analysis takes us forward in the head of that type of world yeah yeah so you know within you know attack service management I think I spoke a little bit in the beginning of uh within this talk so that itself it's huge right the attack the attackers management is really huge and it can be divided into multiple different areas infra is one area application already is another area and then you know we can we can get into more details of you know the s-bombs and the API security so that's that's the next up you can start looking into expand your attack service management and get a view of That So within infrari you can have you know the the um the infrastructure owned by the organization which I'm not talking about servers laptops and points all all of that and it could be a cloud environment and then you can think of your uh coming to the cloud and containerization your containers and then within application you can you can think of you know your um how you can get this the static static security findings and the dynamic security findings and then the sca so there are various components um of the vulnerabilities itself so bringing all that into a one place and then having a unified view I think that really helps the organizations get a get a bigger picture of where my organization is in terms of you know vulnerabilities and so on thank you let's let's keep answering these questions as long as people like to stick around so um we'll stay obviously until the top of the hour if you'd like to um please if you're if you have you know if you have someone who need to be or need a break before your next call today um answer your guess to that question so that we can follow up with any other items of interest but let's let's go on to anil's question if I understood correctly simple scan application repos how about vulnerabilities in application servers used to running these applications foreign yeah so so you know um the way I read this question is you know we do scan code repositories for sure um the and that's that's its own discussion track like I know the purpose of this webinar is to focus on snake um open source within service now but yeah the answer is yes we do scan um repositors and we do have um snake Cloud for running infrastructure I'd like to defer that conversation to a different uh to different dining stay focused on the servers now probably out of the scope of this integration uh you know it's possible that that could be covered by another existing infrastructure scanner you know because we're scanning runtime with an infrastructure scanner but if that's in you know say the cloud or if that's a running container it's possible that you've got a coverage Gap there and integration or Aquila you have any thoughts on that to add no I think I was looking at sanju's another question here sorry that's the one you're saying oh yeah if you want to answer SMGs why don't you read it first yeah what I noticed is you assigned a vulnerable item to a group and not available vulnerabilities that you find it's it's in millions so and just addressing through vulnerable item is a nightmare for the remediation teams so the what the feature that's in that's introduced there is you group them as you know based on the the assignment groups so which is called as remediation tax not vulnerable task in in the latest version so the remediation task is what the remediators will be looking at but each remediation task contains multiple vulnerable items within that but coming to uh application vulnerability first of all the numbering is not that huge and it's it's definitely doable and maintainable within the vulnerable item itself and and the grouping and Remediation is slightly different when it comes to application availabilities and hence the assignment group rules are worked on the vulnerable item itself yeah and it'd probably be interesting to think about what the grouping logic would be because you've got people working on projects and like their their projects would be you know potentially installed on you know um thousands of containers or hundreds of machines or however you look at it but it's it's a bit of a different approach because of where we are in the psychological deployment app in fact I was thinking it it can always go back to the uh the application release you can tie to that and tie it to the which is in the cmdb and that way you can map you know run down with multiple mapping within that picture drill down who is the owner of that you know who is working on that application things like that that can be leveraged here and that's what you sort of use search now to do as well as build those reports based on release and start to get a picture of um of the performance and development all right let's move to the next one so sneak has an integration with jira who serves down a better alternative well I would say our default answer would be of course yes you want to add any color to that um uh personally I have not seen that immigration so I would know I I can't comment with the jira integration but um you know going back to what I've been saying uh this the the service number already response and application availability response will definitely give you a much more unified view of if you're looking from organizations perspective any type of application vulnerability you have you can bring in and have one unified View one thing I'll add is is for the jira integration you know we we see them as different solutions um jira is for one type of population and the service now people plina please correct me when I'm wrong you know we see jira as a developer friendly hey I want to manage my my day-to-day code things um server style I mean because it has such a wide breadth of solutions and products I mean they they they've solved a lot of other problems that are not addressable they say by by jira so so um I would I would say um service now is is the best alternative for all the problems that servicenows is addressing um and and I'll leave it at that yeah it might be you know just to to expand it a little bit you know the jira might be more focused on say issue management like you know talking about assigning work to developers whereas this we're looking at you know a security overview of you know the issues that are coming into um you know coming in through the code while it's in process we do have a product called strategic portfolio management that is a little bit more similar so because this integration is not with that solution it's probably a little bit of apples and arches I see another question here um what is the difference between sneak and other scandals like tenable please tell us the benefits why we should consider sneak in addition to terrible which we currently thank you um you know as I think um when they detach upon the infra vulnerability scandals like terrible qualities and others in the in the industry so terrible definitely is on it can be leverage for it OT and on that side of the vulnerability uh scanning whereas sneak is developer first platform when DeMarco please again add more to that um and then with this integration we can find a software composition analysis specifically into service now you know the sneak sort of uh you know Edge when it comes to their approach uh Marco and Wendy I'll I'll start by saying they are different types of solutions you know snake has this scan code container you know perspective tenable is a different one I I'm not a liberty to say like the different distinctions um but in general um we see more complementary than competitive yeah that's a good way to to that question and and so the the I'm sorry I want to add just like another 30 seconds so like um so we've used different metaphors to describe like security is not just one thing there's usually a lot of things and there's different models the seven layer or whatever the the sphere model um if I use a simple example I would say like if you were to go outside and it's very very cold you would want warm boots warm pants warm jacket mittens gloves and so on each of these Solutions is their own thing maybe we can be greedy and say sneak is a fantastic jacket but someone else may be the Fantastic mittens um and it's it's something that we would want you to just understand it like we see tenable as something that is not really overlapping um you know with with our solution so dress warmly especially on Super Bowl Sunday another Point different end users as well sustainable end users make end user we're scanning different things scanning itself well thanks everyone for the Lively q a really appreciate it um we do have a few more minutes if anyone would like to um you know to ask another quick question we will um at this time and that hole and um let me grab those results and we'll make sure to follow up with anyone who did indicate in the affirmative that they'd like to be contacted for more questions um I think call to action for everyone who's still on the call today um please go to the store and check out the sneak integration at store.servishnow.com search for snyk also if you search for sneak and servicenow there's a couple of great you know there's there's a we've made an appearance in the journal with that announcement with our own CIO Chris Betty who made some comments on the sneak integration it's gotten some really great attention um just because of the relationship and the obviously the exciting you know technology innovations that are going so we wanted to thank everyone for your interest and for attending today uh Marcos Wendy I'll leave for you with you for any other closing comments you'd like to add you know there's one more question on there why is Steve giving more Focus to open source and continuing it but not with sneak code um if you're talking within the context of the servicenow integration this this um this uh first version of this app is is primarily focused on the open source you know we we don't want to convey that the other products are not important but this integration is about sneak open source and again like if uh if you want to um I don't know if you indicator that you'd like to be followed up with but if you'd like to uh I think did you did you when did Margo flash your email before um I did not all right let's uh well anyways um leave a comment on the webinar page um you know I don't know Wendy if you want me to put your email address on on video yep sure thing it's just windy at sneak that is pretty easy if you have any questions about the road map Wendy is the person to ask so obviously if there's interest in in this we'd like to know and uh continue uh to iterate on this uh on this solution but we would encourage you to first you know go and check out what we do have because I think it addresses an important um an important question for most organizations all right okay well I think uh we'll give we'll give folks 30 more seconds for another question um again on behalf of Marco Aquila Wendy um thank we thank you all for attending today this was a great session make sure if um you know if you missed any part of it because you had to catch a call or anything there will be a recording on the service now community and um you know we encourage you to uh to check that out um check out the integration check out the uh the blogs and the other articles that have been put out recently and uh we look forward to uh coming back and presenting on the next big thing let's see thanks everyone thank you all thank you all
https://www.youtube.com/watch?v=jU_9nxejjUM