Improving Healthcare Provider Service Operations with ITOM Cert. Management
hi my name is Lauren Miller I'm a Solutions consultant here at servicenow specializing in all things it operations management or item and today I'm going to be walking you through a brief introduction to itom certificate management which is part of itom visibility and specifically how this can help health care providers to really keep their services operational and secure it and we're talking about certificate management we are specifically focusing on TLS or transport layer security certificates also formerly known as secure socket layer or SSL certificates and what these type of certificates do is they essentially put the s or Security in HTTPS essentially encrypting all of the data that is sent over the internet from your different online applications portals websites Etc so specifically for our Healthcare Providers when you start to think about all of the patient portals applications websites that are processing any secure transactions for patient data Phi pii all of those transactions need to be encrypted and secured and when you start to count how many portals applications and websites you have that all need to be connected in a secure way that becomes a very long list of TLS certificates that are used on each of those applications to encrypt that connection and so this creates a very complex management process for our pki teams who are not only managing the TLs certificates installed on those applications but also making sure they're managing the life cycle of those certificates and specifically managing those expiration dates what's really at stake here when certificates are not proactively and automatically managed as we're going to talk about today with itom certificate management as we put ourselves at risk for service outages when certificates are not installed on time or expirations are missed patients for example are logging into their patient payment portal scheduling portals and this is the message they could be unfortunately seeing that that application is experiencing an outage because the TLs certificate supporting it was not renewed in time it expired and took that service down you don't want to be like Microsoft teams in a case a few years ago where the certificate supporting the Microsoft teams application expired was not proactively managed and caused a multi-hour outage costing that company millions of dollars in Revenue because of that unexpected outage on the other hand as I mentioned we're putting security that s and https encrypting that data that's transmitted by these applications so the other hand of this is when TLS certificates are not properly managed and those expiration dates are missed the TLs certificate expires and is no longer supporting that application encrypting that data we're putting our data at risk to be breached to be hacked because that connection to that application is no longer encrypted no longer private no longer secure and in the case of Equifax Equifax a few years ago they had multiple client data pii be transferred out of the Equifax environment we buy hackers because of an expired certificate so you definitely don't want to see this be your patient's data and you especially don't want this to be your patient's experience so it's really at risk here right critical application outages those applications going down because of an expired certificate something that's so easily prevented by a appropriate proactive and automated process that we're going to look at today that's putting yourself at risk of millions of dollars in Revenue being lost as a result of those averages that we want to avoid we talked about patient data making sure we don't have delays in renewing these certificates applying these certificates in the first place keeping our data secure not letting those applications be vulnerable to security breaches as a result of lack of certificates there and under HIPAA you do as a health care provider have an obligation to secure any electronically transmitted Phi and ppii and while HIPAA doesn't explicitly prescribe TLS or SSL certificates to do that this is typically the easiest and most effective way to meet that compliance requirement and you truly can't afford to be transmitting unencrypted PHI for so many reasons but especially when we talk about HIPAA and potential litigation fees applied when you're at risk of that and lastly just providing the best patient and provider experience as we can these unexpected and extended outages as a result of these expired certificates or certificates delays and applying those to new applications this is leading to poor and user experiences that again are so easily avoided so as we're going to walk through in our demo today how service now really approaches certificate management is with a couple of things one being that automated discovery of your certificate inventory as itom Discovery schedules are running scanning your environments your digital Estates and populating the cmdb we're going one step further and looking for those TLS certificates to create that automatic inventory as part of that Discovery we're also detecting most importantly those expiration dates and using that field to automatically and proactively create those expiration tasks defined to be assigned to our correct pki team members and teams to make sure we have that proactive visibility and tasks assigned to go ahead and renew those certificates before expiry avoiding those outages and making sure we have that visibility and lastly we're going to look at how we actually automate those certificate fulfillment process working with apis out to our certificate authorities to completely automate the tasks needed to renew request a new and revoke a certificate and as we're going to see throughout this demo what we're really looking to achieve here and what certificate management gives our customers especially our Healthcare Providers is that automated visibility and tracking making sure we're proactive automated preventing those massive P1 incidents and preventing any blind spots from occurring in your certificate management process automating that fulfillment process so really speeding up the process and time it takes to get certificates requested or renewed revoked as well to make sure you're securing those connections and meeting HIPAA compliance without any delays really focusing in on service driven operations we're going to see how not only do we get visibilities to your certificate inventory but also where they live from an infrastructure perspective and what business critical applications they support in your environment as well as how we integrate from a one platform model with event incident and change management but our main theme of today overall is preventing outages this is a cost-saving initiative providing you better end user experiences for both patients and providers in keeping your operations and services secure and with that I will proceed on to our shortened demo so for the sake of our demo story let's say I'm Amelia I'm a pki administrator here at Memorial healthcare provider or Hospital whatever the organization may be so as a PKA admin I need to answer very Mission critical questions related to my job with working with TLS certificates and one of those that we're going to look at in our certificate management dashboard here is part of the certificate management module are things like hey how many certificates do we even have how many certificates are we managing in our infrastructure and out of those how many of those are self-signed versus Certificate authorities that we're leveraging and definitely from a reporting perspective we need to be able to know what kind of upcoming expirations we have what of those certificates are expiring in the next 30 60 90 days over the next several months years this is all data that we are automatically discovering and populating in these out of the box dashboards via that automatic Discovery process again your normal Discovery but specifically looking for those TLS certificates either installed on the ports we're scanning or via several other mechanisms that we'll dive into in further demos now as Amelia as a PKA admin other questions that I'm responsible for answering besides just about our certificate inventory are things like are we automatically and proactively creating tasks before certificate expiration how are we proactively managing these things and before we dive into the answer being yes how we automatically create those tasks and what that looks like I first want to highlight one of our main Integrations with Incident Management so as expirations are passed and certificates are discovered to be Beyond expiration or that expiration is passed for whatever reason we are automatically integrating with Incident Management to automatically create incidents for any expired certificates so integrating with that side of the house as well but we want to get as proactive as possible looking at our Priority One tasks that are automatically created for me as Amelia showing me that a certificate I'm responsible for is coming up on expiration so that task was automatically created for me to go ahead and renew the certificate in this case digisert that based on that discover data is coming up on expiration here shortly this was automatically created by default 60 days in advance of that expiration date giving myself and my team who this is alerted to plenty of time to go ahead and act accordingly to renew the certificate and avoid the outage that it may cause now another question that I'm responsible for answering here at Memorial is not only what certificates we have when they are expiring but what business critical services do they support So for every certificate CI and my cmdbs I can see not only that unique certificate record that's flashing here but also from an infrastructure perspective what server this is installed on and in this case this particular certificate is living on this particular Linux server in my infrastructure environment but from an application service perspective I can see exactly what application this particular certificate and this infrastructure is supporting in this case my mission critical patient portal application and if I zoom up a few more levels I can actually even see from the business side of the house what business application this is alluding to the business service as a whole the exact offering and even the business capabilities that I've associated with this to see what this actually means to my healthcare provider organization as a whole and seeing this level of relationships seeing this business criticality helps me to understand if I let this particular Digi certificate expire I don't act accordingly to that proactive task that was created for me automatically this is what's at stake of an outage and potentially a security breach of the data living in this application and supporting these business needs now as Amelia as I start to act on that automatic task that was created for me to go ahead and manage that certificate we just looked at I have a couple of options in terms of how to do this as we mentioned on our outcome slide one of the main things we want to achieve is automating that certificate fulfillment process as much as possible so today as part of our service catalog here one of the management or excuse me one of the modules you'll see is certificate management and under this automated category I can see the out of the box workflows that are leveraging apis to actually kick off these functions request new certificate renew certificate and revoke certificate automatically out to select certificate authorities that we have in place today here at servicenow now that is a growing list of certificate authorities that we fully automate to today that includes Digi digisert interest and Microsoft certificate authorities with other Solutions out of the box in place for additional certificate authorities as well as self-signing processes so that's going to automatically Reach Out execute those apis to really streamline that process of fulfilling that Certificate request process now for example if as Amelia I got a request in from one of my out-of-box catalog item request saying hey maybe from the devops side of the house we have a new application we created we need a new TLS certificate to support this new application as Amelia maybe I launched that request new certificate flow in this case out to interest one of our certificate authorities that we support out of the box with that API what that will look like when I've launched that API as Amelia is it's going to create this new certificate task automatically it's going to execute that API out to interest once it's created that new certificate it will attach it to the top of my task here mark this task as complete and the last thing we'll see at the bottom here is that integration with the change management side of the house so we really want to follow this process to completion make sure we're following ITIL best framework and make sure that we are following a one platform model and so by having this change request be automatically created and attached to our new certificate task here this is ensuring that we have full visibility and governance as this change request will be used by our team who's going ahead and doing the last step of installing that certificate on the Affiliated server the last thing I'll show here is the final integration with event management so our cost for our customers who are leveraging itom health or event management we can also ensure that our NOC team are monitoring teams have visibility to certificate expiration as well so again going back to the concept of service driven operations same service that we're looking at that we saw in our dependency view here that patient portal service looking at this and our event management module we can see that our monitoring folks will be alerted as well by the system generating these alerts saying that hey a certificate supporting this particular service is coming up on expiration so they have visibility as well and can work with our pki teams to ensure that we get make sure our service is fully operational secured and protected as I mentioned this is a very shortened brief version of our usual demo flow but we wanted to really highlight how we automate that visibility not only to your certificate inventory but automatically creating those renewal tasks to manage that proactively and automatically automating that fulfillment process reaching out to those certificate authorities ensure there's no delays in getting those certificates requested revoked renewed making sure those connections are secured and HIPAA compliance is met focusing in on service driven operations we saw those dependencies out to even the business capability level of each certificate and what it's supporting from an organizational perspective so you can prioritize accordingly and know the impact of those Management areas as well as that seamless one platform integration with event incident and change management But ultimately we want to prevent outages to keep your services secure operational save you money there and make sure you have optimized end user experiences thank you so much for watching and as I mentioned there's a lot more we can cover on this topic please reach out to your servicenow account team to schedule a full demo or discussion or leverage our other materials posted online
https://www.youtube.com/watch?v=FZZmOed_2do