Technology Workflow Utah Release SecOps Security Incident Response Workspace
[Music] thank you hello and thank you for joining me today my name is David Adler I'm a senior solution consultant here at servicenow specializing in security operations today I'll be walking you through the brand new security incident response workspace available in the Utah release of the platform before I get started this presentation may contain forward-looking statements that are based on our beliefs and assumptions and on information currently available to us only as of the date of this presentation security incident response workspace has been redesigned to meet the next user experience that we aim to provide across the platform it has been reimagined with Tier 1 and tier 2 security incident analysts in mind it includes all new analyst dashboards and an investigation canvas to manage incidents and your workload as always within security incident response you'll be able to leverage playbooks and recommendations to easily move through the investigation process and finally through the power of the platform you'll be able to orchestrate actions directly with out of the box Integrations to your security stack all within this workspace so let's jump into the workspace as with other workspaces that have been brought to the next experience UI we start here in the overview workspace here we can see the activities assigned to a specific analyst or to an incident response team we still have the traditional list view of incidents but as you can see it's been much better organized and we have the ability to present dashboards right here in the workspace when we need to triage or investigate an incident we can start here in the overview tab which provides a high level overview of the incident more actions appear here on the top right such as composing an email linking to a major security incident or switching to the classic UI if preferred the investigation tab provides information such as Associated observables configuration items or affected users we can even take action on Associated observables right here within the workspace such as running a threat lookup or putting in an allow or block request The Playbook tab is where we can view the Playbook and its steps the significant change with this feature is the ability to add multiple playbooks so if we start out responding to a phishing email but we find that the user has downloaded the attachment and created a malware incident we can add that Playbook to this incident the related records tab is where we find more details such as threat intelligence and similar security incidents to help us quickly determine if this is a false positive or A true event and it provides us with enrichment data and other third-party Integrations here in the details pane the contextual menu on the right has the work notes in the activity stream and in addition to being on the right side and out of the way an important Improvement is the ability to filter sort and search through the activity Stream So no more scrolling to the bottom and no more manual searching to find that key bit of information needed for the Post incident review or to provide to auditors within this menu you can also toggle between playbooks analyst assist manual run books templates and attachments as part of the improvements to the security incident response process creating and maintaining workflows and playbooks has graduated to the servicenow process automation designer finally for those of you who prefer dark mode it's very easy for users to switch themselves to start using the new Ser workspace simply go to the servicenow store and search for the security incident response workspace thank you for joining me today to learn more about servicenow security operations go to servicenow.com or reach out to your account team
https://www.youtube.com/watch?v=pnQDdTeQN8M