Continuous compliance and security monitoring in a cloud environment
all right I'm going to get started it's a couple minutes after um I am going to turn this over to a nursery we are very excited to have both servicenow and security bricks on the call today and uh Nursery would you like to introduce yourself and Raj and um what Raj and Ben can then injury stem cells thanks to you Sam hello everyone good morning good afternoon good evening you are um we are very excited today to take you through this new accelerator that we are building um which is the cloud security compliance accelerator which is going to be released in our May store release as an innovation lab um so I'm anushree and I'm part of our uh risk business unit product management team and I handle our ID compliance and ordered product as well as a few of the accelerators that we've released in the past and Integrations with other products so I'm here to take you uh take you all through this new topic and with me I have Raj and Ben for joining us from security bricks so I'll let them introduce themselves thanks hey this is um good morning good afternoon good evening again so uh thanks Teresa anushree and others for the opportunity to present the or introduce the new accelerator we are a security firm based in the US and we have been working with servicenow for the past few couple of years actually as is me to help them design the security accelerators or compliance accelerators so be excited to be here and look forward to a great session Ben ah sorry about that all new it always catches me every time hi everyone um thank you for joining us today for this uh webinar on cloud security compliance I am a partner over at security breaks um I just counted this morning I realized I've been doing risk compliance and security and privacy for 23 years I didn't realize it's been that long so I'm excited to be here and we'll look forward to uh you joining us today and we'll demo and give you guys a demo of what we have in store for you awesome thanks Ben um all right so I am gonna start over or start with RC carbon notice because we are going to cover some topics which are coming in the future and some Road roadmap related topics as well so just a safe harbor notice here um and before we start off with our agenda I also want to talk a little bit about the knowledge 360 which is coming up pretty soon uh it's starting uh the knowledge is starting on May 15th so if you haven't registered yet uh we uh we really encourage you to register there are limited spots so you can sign up today uh and there are a lot of exciting topics and uh sessions that are happening in the knowledge so it'll be a great session for all of you or a great experience for all of you to come in and join us okay so with that I am going to start with our agenda um so we're gonna talk a little bit about our vision um what is the vision behind this Cloud security accelerator and in general the cloud strategy um and then we'll talk a little bit about Cloud deployment risk um cyber security posture landscape uh will also then cover the accelerator that we have been working on which will be released uh next week and then uh Raj and Ben are going to talk about the security bricks apps uh that they are working on which will also be released in the store um and which which cover a lot of our uh content around the cloud as well so and we also obviously going to do the demo so with that I am going to hand it over to Raj to talk a little bit about vision and then Cloud deployment rest as well thank you so um thanks again um so here what we what a problem statement that we are trying to solve today is really about the configurations the misconfigurations in the cloud so we are the concept of you know public clouds people deploying it um you know a few times a day maybe it's much more agile and the idea is what are the risks posed or what are the risks that are introduced uh when we set up the cloud right when we go ahead and deploy an application into the cloud so we took the problem statement of misconfigurations and said how do you measure the cloud security posture and what is the context behind a vulnerability or a risk and so the focus was in when we started this and then if we'll walk you through the Journey of continuous monitoring the ability to measure security posture that's been going on for a couple of years and the spin that we wanted today is there is cloud security posture management it is a very very well area there's a lot of companies investing and doing but the idea here is how do you extend that to multi-computing environments multi-cloud environments everybody is using Enterprises are moving to the Cloud yet keeping some of their legacy data centers or hosted um you know centers and the idea is giving that multi-computing visibility so when we take today from the public Cloud there is a as you can see there's been a lot of risks there's been a lot of news about um you know incidents that have happened security instance that have happened that have had implications right they've had some business implications um Gartner estimates that many of these Cloud security issues or multiple these are introduced through misconfigurations and so the idea is first of all how do you gain visibility um how do you um you know if see what you can do to prevent and of course detect is important but then prevent it but then also give some context to it um everybody you know uh cloud is so agile and people are spinning up virtual instances bringing it down there's so much agility in this how do you make sure that you are protecting the data and at the same time you also have you're complying to certain regulations so the problem statement that we wanted to make sure here is to ensure that we are able to give you visibility into your multi-cloud environment from a security perspective and put a compliance context to it so that's the approach and that's the vision of this accelerator next slide ah so uh we spoke about and this is all data that's out there which is you know 13 it's claimed that 39 of people will have hybrid which is they'll have multi-cloud approach a multi-computing environments 33 percent are going to have between probably AWS gcp Azure Oracle another um you know a cloud provider IBM maybe and then you have 27 percent who are actually probably only going to be in single uh provider maybe all in AWS are all in Azure but the idea is all of them come to the similar risks they have similar regulatory impact and they're going to have to be you know measured in the same way so the challenges today and if we talked about various misconfigurations and various you know vulnerabilities that are introduced things like encryption um they uh some of the credentials you know it's very as you go into the cloud um identity management governance ability to have privileged access because there are more people there are people who outside this is transformed where you have groups like devops you have new groups have come in and are now accountable for the cloud infrastructure and the ability for the cloud operations and air control and their you know access that they have so the idea here is there's a lot of challenge that that are posed in the security world and the question is what is it that we want to focus on what is it that we can control certainly there are many things we can reduce the risk because there are a lot of threats that are that that we may not have you know lot of control or visibility but at least the ones that we can prevent it so that we are not leading into a bigger security event by our human you know configuration so that's I think the approach here is hey what is it that we can manage what is it that we can prevent in the cloud even before that so that we are able to detect now so the same time we comply into regulations next slide so this is your typical um you know um ecosystem within an Enterprise you have devops that's you know uh in charge of deploying into the public Cloud they own the public they are able to they have administrative access they're able to use automation scripts they're able to deploy various services within the cloud and they are responsible to make sure the cloud is up and running then you've got security operations who are detecting to make sure that certain vulnerabilities have not been introduced or are not present within the cloud and they run scanning tools they're on various you know processes to ensure that they are constantly checking to ensure that there is no security vulnerability now then there is the irm or the GRC team which essentially is saying look we've got certain regulatory impact we've got certain benchmarks that we want to ensure or certain standards and Frameworks that we want to measure our cyber security posture so that we are able to give you guidance but then the span of control reduces because you know in the olden times when there's data center you had different groups managing but now we have a different sets of people managing with who are who are who are new to security or trying to put security as part of their you know day-to-day job so the idea is how how do you with this reduced span of control how do you ensure that the GRC the compliance the Auditors have visibility how can security Ops ensure that these in you know they've defined a particular say there's an encryption issue or a password issue how can they make sure that they can put it right in the prevention stage so that as it's being deployed they are deploying it with the right scripts or the automated scripts that have these security controls in place so that when it is detected that they actually find compliant uh fine you know no vulnerability so that it is compliant so they kind of this whole life cycle is kind of where I think everybody wants to get to it is tough because there is different people different skill sets different understanding so the idea here here is take this regulations find ensure that any of these you know if you can avoid some of these configuration issues in the in while deploying it ensure that they have some regulator impact so that can be detected you know you know we're ensuring that it is you know much more secure next slide so we talked about this and today I'm sure everybody's fatigued by the number of regulatory regulations that are coming out uh previously it used to be you know your annual audit you go ahead you you know submit the evidence um where you're able to say okay I've tested my you know here is the list of you know my scans I've done over time uh we have shown reduction in our security uh threats uh we've got secure code training but here is the logging here is how we you know here is a sample logs to show how we uh revoke and Grant access so these were all you know uh they were all fine because it was pointing time once a year you'd submit it for various regulations but as a cloud as have things have changed more regulations are saying look we need constant monitoring we want to ensure that you're constantly looking for risks and not once a year or at a you know at a certain period of time so the idea is continuous monitoring comes in place and many regulations so let's take five run which is you know based on honest 853 and it was codified by the president in on December 25 22 that said if you are a cloud service provider and you want to provide services to the government or any federal any of the 438 federal agencies you have to be Federal and certified and you have to have your name listed on the marketplace now that comes with some responsibilities you go through as a cloud service provider you go through various you know Audits and checks and controls but at the same time once you are in the marketplace you're expected on a monthly basis and you know short operation you're supposed to provide reports on your continuous monitoring reports basically they are on your posture on a regular basis um how what vulnerabilities you've had what instance you've had so it has changed from hey I'll take it once a quarter maybe to Now show us every month what your posture looks like for us to do that as a cloud service provider they need to ensure that they are monitoring on a daily basis or on you know on almost a real-time basis so the concept of continuous monitoring has come and it is getting more into regulations pcid ss40 has some of these and they follow certain benchmarks right they're saying look follow CIS benchmarks for example they will tell you how to harden AWS they will give you how to work with Azure use those benchmarks make sure you're technically you have all your technical controls in place then you come and report to us so that we are able to get a visible turning posture we don't want to be surprised when there's an event so more and more regulations that are coming down are requiring this concept of continuous Mountain reporting so we figure this is going to be not any more nice to have it's going to be a must to have it has become must-have so the idea is how do you provide tools how do you provide you know the processes so that you can do this in a multi-competing environment next slide okay so at this point I'll let I'll hand it over to anushree so she can speak about uh you know the roadmap what we built and you know where we started and basically specifically to servicenows its product thank you I think you guys actually have a question also did you want to uh check out the Q a why are regulations only American based what about other countries great question well PCI is global um thank you we took an example there are many International regulations too we took some uh that just as an example but there are we just use these as examples but absolutely there are many International regulations we have a list of them happy to share with you about some of these requirements absolutely sorry these were just examples that we picked up so thanks Ash all right so I I wanted to take you through the Journey that we've had um with the accelerators and some of them Raj mentioned on the previous slides um we released these cyber security controls accelerator and Technology controls monitoring accelerator way back in uh 2021 in our Quebec uh Quebec Quebec release um what we released were the CI 7.1 um really uh content right so we had we released the authority document citations and control objectives for CIS 7.1 and as part of the technology controls monitoring accelerator we release a bunch of indicator templates which are both basic scripted as well as manual templates to monitor CI 7.1 as well as ISO 27002 controls so these indicator templates would actually go um and and fetch the evidence from other service naughty bills from uh let's say your uh si uh your start out some VR sir your um see uh the discovery or cmdb HR and other part of the uh service now organization as well so we actually looked at uh all the different products that are there uh and if customers have them enabled you can actually monitor these indicator templates by fetching the evidence from all the different tables so this is already available uh to everyone and we are going to have going to be enhancing it uh further in the roadmap so you'll see that in a bit in 2022 in Tokyo release we uh released a devops accelerator which is mainly used for preventative monitoring of devops config controls what we've done is we've mapped uh the control objectives coming from various regulations like CIS 8 PCI 3.2.1 ISO 27002 Nissan 853 to the uh Pace policies the devops based policies so what we're doing here is by mapping this we are continuously monitoring the devops controls uh but more in a preventative fashion so if for example if a developer is about to release a code or deploy a code in a a proud environment uh if if they're using a sensitive keyword or something which is actually uh violating these regulations or the requirements from these regulation it would prompt a developer and um give them an um notion of if what what are they being non-compliant to and they uh based on that they would be able to prevent uh from releasing a call which is actually going to uh um fall into non-compliance right and then they can request an exception if they want to so this integration and the accelerator is already available and we will be enhancing it even further in future now what we are going to be releasing pretty soon which is next week is the cloud security compliance accelerator we are releasing it as a an innovation lab in May the Innovation lab basically lets you download it in your sub fraud environments and try out the accelerator but before it actually uh is available for General availability which is going to happen in August the intention here is for everyone to try out the accelerator and see how it works if you have any feedback if you want more content anything related to that uh we want that feedback so we can enhance our accelerator and provide more content in future so that's the plan um and as part of this accelerator and we'll go into more details we'll also uh demo it to you today to show you what it does but in a nutshell it allows you to monitor your Cloud controls from various regulations and Frameworks and standards such as PCI and nist ISO CIS um against the security benchmarks from Azure and ews so we this accelerator allows you to monitor their Cloud controls uh using our integration with the cloud security posture management product from secops and we'll get into more details around it so I'll explain that uh what what each of the product does and how the integration Works uh but this is a journey so far and what we have planned for future and some of the ideas that I would love to share with you all uh is where we are going so we are looking at three different buckets here one a single pane of glass which where we want to provide you more content around dashboards and reports um the idea here is to have a single dashboard for monitoring both Data Center and Cloud controls uh against all these different regulations uh benchmarks and standards in one single dashboard so this is something which will give you uh overall uh the overview of your compliance posture uh against your data center and Cloud controls the other thing that we are planning is the cloud governance dashboard so continuing on our Cloud Journey uh our single dashboard which will give you uh various reports around managing your Cloud governance so that's another thing that we've planned in future and um our partners like security bricks they are working on some of the accelerator which will provide the dashboards additional dashboards as well that you'll be able to uh see a glance software till today's time as well on the cloud compliance side we are um like I said the cloud accelerator is coming out but other than uh on the cloud governance side we will be supporting the CSA and cmmc uh in future we will have more out of the box content around Cloud controls monitoring additional uh cspn policies and benchmarks um that we'll be able to add in future and there will also be partner built uh content and uh again Raj and Ben are going to go over some of the things that they are working on when it comes to accelerators and Integrations uh we will add as I explained before we will add more indicator templates to monitor data center controls from various other regulations currently we cover only CIS and ISO but we would like to cover all the other regulation standards in Frameworks to give you more content to provide you that uh way for continuous uh controls monitoring to make it easy for you and give you those indicator templates so that's the plan other than that uh we are also planning to integrate with our sir products security incident response product from secops uh for miter attacks integration so CIS 8 provides you uh some of the meta attack techniques against which your CS controls are uh so if you comply with certain let's say uh first uh I mean top five CIS controls you will be able to mitigate certain uh might attacks so that is a available in your cis-8 framework but how do we actually integrate with the miter attacks coming from our technique from Sir right so that's something that we are going to work on in future apart from Azure and AWS integration we are also looking at gcp Google Cloud integration as well in future so you'll be able to monitor any resources that are on the Google Google Cloud as well other than that there'll be more content and accelerator from Partners so this is our future journey and uh you can see that we want to add more content more more out of the box Integrations as well as a way for you to monitor your Cloud as well as non-cloud controls so with that I am going to move on and explain a little bit around what we are doing from a cloud security compliance management here um and today's demo is focused around our Cloud security compliance accelerator uh which includes uh which which basically has the integration with the cspm module from secops so what you can see here is um we are providing you a wave to monitor your AWS in Azure uh resources using um couple of products here so cspm the cloud security posture management product currently is in the Innovation lab so you can also try that out um uh from the store what it does is it provides you the out of the box uh policies which will help you to monitor your Cloud resources against uh Benchmark standards like uh CIS Benchmark for Azure and AWS it makes use of items uh Cloud configuration governance product which provides you an ability or tool to manage your Cloud resources so with the cspm and ccg products you can monitor your Cloud resources for any misconfigurations against the CIS benchmarks and that will populate as test results in your configuration compliance products so all of this are all of these are connected products you don't have to install them one by one as soon as you install the cspm uh Suite of application or module it'll install everything in the background but um the cspn provides you those policies to monitor your Cloud environments which will provide you whether a certain Cloud environment is misconfigured against a benchmark and provide you those test results whether something is passed or failed which is then mapped to the uh control objectors from irm and it will give you more context around what is being non-compliant right so if you can uh take an example of another cis-8 control uh with this mapping between the CIS 8 control and configuration test you'll be able to understand uh why a particular control uh or uh is non-compliant because of some misconfigurations that might have been there in your environment so it will give you those test results and you'll be able to look at it real time and monitor them so that is the end-to-end intuition that we will be providing you and with this accelerator we will be providing you out-of-the-box content for mapping the control objectives to configuration tests so a little bit of how this works right so you have your csvm product and which scans your um Cloud environment with the help of ccg uh with when you scan the cloud environment it provides you the results of configuration test data whether the configuration test data is uh passes past or failed it will be collected as evidence and if there is a configuration failure or misconfiguration it will generate an issue on VRC side and um it will basically provide you a non-compliance against a certain regulation or a standard so as a end user be able to also request an exception and this is a continuous process so it's truly a continuous monitoring of your Cloud environments all right so with that I am going to pass uh pass it on to Ben to go over what this particular accelerator covers and uh some more details and we'll get into the demo as well if you have any questions you can write that down the Q a and we'll take it that was great um so we're gonna dive into a little deeper around ESPN and we'll look at the numbers itself so as initi said out of the box ESPN provides you with sets of policies so Benchmark as you call it the for AWS on the box to your right there are 55 policies that are specifically designed and created for the AWS environment and there are 51 for the Azure now if you look to the left hand side it says CIS 8.0 for azure and it says 17. what that 17 number means is that of says 8.0 there are 17 controls specifically two it says 8.0 that are mapped to the 51 policies that are out of box now you're going to wonder well there are 17 but yet there's 51 configuration tests what's why is there such a big discrepancy and the reason for that is really if you look at some of the controls One controls from shares might say insurer passwords are configured securely and that translates to ensure that the password is 14 characters in length that expires after a number of days for you to change your new password and then your new password cannot be of the same old password and if the account is dormant for a certain period of time got to make sure that it's either disabled or removed right so that translates to multiple configuration tests from your Cloud environment to ensure that that control pass is say for an example of PCI for PCI it's all or nothing right so if any of those controls fail for any of the resources that control automatically fails until you have it remedied or address or fixed so that's why there is 17 there are map 251 Azure configurations and under 16 for the ABS environment third mapped to 55. now of that 17 [Music] we have it mapped based on the authority source that are provided that are mapped to 51 PCI 4.0 25 ISO 27002 in this 853.533 of them and 15 foreign 171. now these contents are mapped using the UCF so out of the box you're not going to get PCI 4.0 you're not going to get all of the iso 27002 these are the UC references the content the all three documents are not in there yet and this is where security bricks comes in and provide those content to the comp complements exactly what's currently out of box in there now same methodology is applied for how we developed for the AWS environment as well so I won't board you with the numbers and repeat it again but the numbers a lot of difference obviously because again the controls are different between AWS AWS and the Azure so the control testings even though similar numbers uh say 1.1 may be the same but the tests and the conditions are different next slide please okay so a little bit about security breaks we've been a partner with servicenow um for about three plus years now we were closely involved in partnering with security uh with uh search now to develop the the first accelerator the Cyber Street accelerators that was released back in 2001 and we're also a specialist partner that our research now for Consulting and implementations so what we are planning for our site is Q2 of 2023 um well go back a little bit the cspn product is going to be in the Innovation stores already I believe it's next week and it's going to be GA in August so in Q2 what we're planning to do is to release an app that will complement it so like I said earlier the content that are currently out of box right now is CIS 8.0 but we are going to provide additional content to support this 853 and PCI 4.0 so what will happen then is when you run your when you have your cspn product installed you got to configure you got it connected to your Cloud environment whether it's Azure or AWS when you run the test right now out of the box it will give you your compliance status your security postures around CIS 8.0 what we will provide is it will also provide you your compliance posture around psac 4.0 and this as well and along with that you know we'll provide a single pane of glass as kind of shows a sort of a higher level executive level exactly where you stand as far as your compliance across multiple regulations you're not going to be seeing just one CS a tunnel but you're going to be seeing other regulations that are coming out that we're developing and well we have in our in the works to you know heavy release in Q2 so those are all coming up and a little bit about people here at security breaks as I mentioned earlier before I didn't realize I've been you know doing erasing compliance and security privacy for 23 years so most of our staff have at least 15 years in experience and our focus is really on cloud security and compliance uh Raj talked about certifications accreditations earlier we are HIPAA PCI federen and in may we are going to be cmmc uh accredited as well so that's something very exciting for us let's see um next slide please okay accelerator for multi-computing environment so this is sort of a an overview of all the accelerators that we have developed or in the process of released developing and releasing very shortly on the irm side we have cyber security control accelerators currently it supports as a 7.1 the CS 8.0 is going to be coming out soon probably in August of 2023 then we have our devops accelerators we will choose the case accelerator to call it and that supports says 7.1 says 8 and this 853 ISO 27002 and PCF 3.2.1 and today today we're gonna in just a little bit I'm gonna give you a demo on the cloud security compliance accelerator and that itself covers tset S8 and the common controls framework that I mentioned earlier that are mapped to 853 the nist the iso the PCI 4.0 and as I mentioned earlier again the PCI um and then this is going to be something that we will be releasing from security bricks as apt in app stores they will support the multi-computing environment all right I'm going to move on to the next is there any question let me see just checking can we use the CSV and accelerator for service now instances as well um that itself currently is developed for Azure and your um AWS environment so it's not for service now instances yeah but that's a great question I think we'll definitely take it back to our cspm team the second Ops Team and give them the feedback but as Ben said it's for AWS and Azure instances uh but we will get back on this uh check-in and get back from this yeah and that's all I didn't mention about Google Cloud hccp that is something that you know works as well and hopefully that's uh something that will release uh soon now then once that's out there that you not only have a degree as in Azure but you will have gcp Google clouds as well all right I'm going to go ahead and switch over to a demo and feel free to submit any questions that you have and which would answer it best we can all right initially I'm going to take the new phone and I'm going to share myself thank you what happened to my screen sorry guys typically difficult teaser it's always the most difficult to join the switch streets which means yeah exactly okay all right so I think I got it here um can you see my screen you know what I'm gonna go ahead and move this in the garage blocking really it's fine let's just go through this okay so I'm gonna give you a quick demo here on the csvm product once you get it installed this is what it's going to look like I'm gonna go to look up cloud and Cloud within there I'm gonna see Cloud security posture management within a cspn product here there are sensor policies I mentioned earlier there are 55 and 51 that are also says associated with right seeing all the screen on the site maybe I should switch use my other monitoring system give me a second guys let me just fix this real quick sorry about that move into this monitor okay does that look better for you guys yep okay perfect so they have all that stuff on the side there okay so this is a cspn and as you can see there are a list of policies that are created out of box trainer IT addresses for AWS and Azure environments eventually like I said and you know you'll include the gcp in there as well and if you look at these policies that are developed I'll just open up one of them as an example and let's just see 1.12 so if you open up one of these policies here this one is specifically is is especially designed for the ABS environment and the purpose of this control config test is to ensure that any accounts that are being dormant for 45 days are disabled and obviously there's the maps to one of the CIS control or PC control now if the way the the policies or ins are conditioned based and that's when I think about it because now you can modifies it as you like say for example a you know what my company policies is a little stricter I don't want to have 45 days before I disable the account I wanted to leave 30 days because based on our usage and our policies any users that's beyond three days should be disabled so I can just come down to where it says 45 days and it's pretty easy to understand the conditions that are developed here I can set that to 30 days instead so now whenever there is a calendar has been enacted for more than 30 days whether it's using a password or a access key uh it will then it would see something that's been around and still active for more than 30 days it will set it as a failure and they'll create an issue and it'll create a ticket for reputations for you and it will also shows up in your compliant posture that efl is control now the nice things about this again is there are 55 policies for AWS or Azure n51 across respectively but the thing is hey what if I have I want to build more I can certainly as a customer I can add more myself and just based on these samples you can say here and say you know what I have a special group of power user or special users that have pretty much access that I want to lock them down even further so for those sets of users I want to ensure that any accounts are inactive for more than 15 days are disabled so I can go ahead and create a newer policy and based on the condition that says these sets of users that belongs to this particular group needs to be disabled within 15 days and if I see anything that's active within 15 days to ensure there is no compromise of account um you know to weak into my security posture I want to make sure that those are removed or those are addressed right away so I can create those policies so now just because there is only 17 CIS that are mapped to Azure I can now create even more than that in what's out of the box but the thing is is nice things about this is when you what you get out of boxes you have your 3.0 that's where you created content content I'm sorry the authority content that's really created for you and it's already mapped for you so once you get it configured you get a setup you get a link to your Cloud environment account to your resources fire it up run the test it will show you a nice dashboards of where you are as far as your compliant postures against your uh against the ecis 8.0 Benchmark okay so now this is the conditions for um 1.12 around 45 days a government account and once I have it all configured let me go back here with all the accounts and what I want to do is I want to get it configure to my Cloud environment in this case here I've already got that set up here I've got my AWS account set up and I have my Azure already set up as well these are two tests that I run for this demo purpose now once I run the test it's going to run against the resources that I have enabled against the number of policies config tasks that I have set up as well and the test result is going to appear in your and figures and compliance and when I go down to configures compliance I'm going to click on all and that will show me everything that's here but I want to see only my cspm stuff so I will do a quick filter type okay I got my cspn stuff here and just now I was talking about 1.12. hold that up there you go 1.12 and for the purpose of this test you can kind of see the results which one we I we intentionally set some up that are passed and some that are fail so you can kind of you know have you guys see the results of it in this case here I have one here that's passed and this is where tests 1.12 and if I go to the GRC policy statements I can see that it is tied to D says version 8. 5.5.3 disable dormant account and psi4.0 as well 8.3.7 now if I am what you can do is I want to know exactly based on the authority document say for CIS or in future when we release our app you can have your preset 4.0 and your niche as well I'm going to look at my all three documents from there I can see there is a p sample that will Authority document here and for the purpose of this demo I we only created Five um control objectives here for you guys to just kind of get a sample so you know what we're going to be what you're going to be seeing when we release our apps in the store here so for PCR 4.0 we can see that these are you know there's only five control objectives here and one of them was to 8.4.1 use multiple authentic multi-factor authentication so if I click open that I have my list of my requirements for a piece for PSI 4.08.4.1 enable authentications I click on the control objective and within a control objective itself I can see my illicit confusion tests that are associated with it so in this case here for me to pass my 8.4.1 I've got to make sure that I have MFA enabled for root user account MFA enable for encryptions enable obviously we also got to make sure that I have MFA enable for all IM user so if I want to take a look at you know the conditions of this I can go back to my um this is here this is uh 1.10 and this is to ensure that multi-factor applications is enabled for all IM user I'll go to the cloud policies again and this one here is 1.10 right okay I'm gonna click open that and I can see the conditions that are set here now this is for that is not root account so basically all the IM user that are not in your account are enabled with MFA no as I mentioned earlier the nice things about this policy for cspm is that you didn't create any new policy that you want so I can an example would be you know I one for rooted user account one for non-root user account maybe there is another group that I want to make sure that all of them have I uh MFA enable and those who are moving like my super user my developers right so I can create new policies in here and have a map to the particular standard or regulations that I want to map to okay all of this is all map I think I ran the test I you know I saw my test results I saw some that are past some that are fail and that can go to my compliance workspace up here in a second and it should pop up soon it's loading there you go all right I am add my compliance management workspace I can see the result of the test if I click on view all I can see PSI dss4.0 that I have shown you guys earlier you know there's also the CIS control V8 SP for security breaks that we use for the demo I'm going to open it up then I should C5 control objective and the links of the config test now this is a nice dashboard that comes out of box for you as well this is not something that you got to configure it's it's very durable for you and I'm going to hand this over to initially to kind of walk us through a little bit more around this compliance workspace thanks Ben all right okay so as Ben mentioned this is the workspace for compliance manager compliance team to come in and look at your compliance posture against different regulation standards and Frameworks so here you can see uh we have PCI DSS and CIS controls uh version a and you can see the compliance score against it which Ben just explained to us um and if I go down here I can also see the list of entities which are being non-compliant or compliant against a certain regulation and you can see there are a bunch of uh Cloud environments or Cloud entities as well that you can see if I click into list of non-compliant entities you'll be able to see all the entities in this case some AWS environments that are compliant against certain regulations and if I go back I can also look at non-compliant entities which are um which are non-compliant against a certain regulation okay um if I once I go back to uh my home page I can see other indicators as well but let's look at a specific example that Ben just explained right we have our PCI 4.0 8.8 8.4.1 for multi-factor authentication which now you can see is uh associated with the configuration tests here right there are eight of them now this is the mapping that we were explaining that will be part of our accelerator so uh there there are CIS 8 PCI Nest ISO uh regulations and standards which will be the requirements from those regulation and standards will be mapped out of the box to the configuration tests uh and the cspn policies basically the ones that are available out of the box so this mapping will be available to you out of the box in in the accelerator so you don't have to do the mapping manually and of course if you want to map anything additional you can do that or remove the mapping as you like um what this provides is an ability for you to monitor the compliance against a certain regulation in real time by looking at the config data that is coming from the configuration uh config compliance product now in this case we've mapped the 1. 1.0 which is ensuring multi-factor authentication is enabled for all IIM users um so this one provides us the config data against this particular config test so if I look into a specific example of a control so as you can see there are a list of controls that are generated based on the environments that have been scanned right so these are all the cloud environments that have been scanned by uh cspn product and it provides the config data to us as soon as those environments is scanned we generate the controls on the GRC side and if any of the test results come back as failed we automatically also generate the issues so it'll tell you uh the controls that are non-compliant and the issue will be generated but the next time if the scan result is passed and it comes back to to irm this issue will be closed automatically and it will reflect the status is compliant now let's look at one of the controls here so if I look at this control here uh this control shows the list of indicators here these are the indicators which have run on the config data which has come from the configuration compliance product and it tells us whether that particular indicator is passed or failed if you go into the indicator it will also give you the uh the supporting data which is the evidence that particular test result has passed or not so it gives you all the details and it connects back to the configuration test and test data this is where your compliance manager your compliance team can come in and monitor the control on more real-time basis to see what is happening what is a scanned result or what are the misconfigurations that are coming in this is one of the example where you can see that the results are passed but we were also looking at another example uh which Ben took us over of disabling the domain accounts this is a control from CIS version need now this controlled objective is mapped took the uh four configuration tests one of them is ensuring credentials are unused for 45 days or greater are disabled now uh since this is mapped to config s again same thing as soon as the cloud environments are scanned the controls will be generated for each Cloud environment and it will give you the results of compliance on non-compliance against that control which would go ahead and generate the issue if something is non-compliant we will look at a specific example of control here so this control is on the environment um the AWS environment here and as you can see there are two indicators that I've run maybe they've they've been scheduled to run um every week or every month and the first one failed which gave us the failure status here maybe the economist the the configuration test results that we came we we got from config compliance came back as failed this went ahead and generated the issue for us the next time the scan results uh the environments are scanned again uh and uh that the issue was fixed by the conflict team uh this particular indicator would give me pass and it will uh it'll reflect on your uh compliance status of your control as well as on your regulation and citation so this is how we provide the integration between your uh controls your control objective and your cspn policies or config tests which gives you real-time visibility into the misconfigations that might you might catch on your Cloud environments so this is in nutshell of the end-to-end demo of our integration with cstm product as well as the accelerator which provides you the out of the box mapping of control objective and config tests uh if there are any questions I will open it up initially again tickle real quick to show the quick dashboards and wrap it up yep and this is available the question is on the uh release so this is coming up in May as an innovation release will be available on Utah as well uh and it will go uh it'll be General available on the Vancouver release pretty soon in G uh August but it'll still be supported on Utah yes and uh just to wrap it up here's the dashboard that we have developed from security bricks uh well I think that what I mentioned earlier is when we do the config tests the dealers were actually not measured and tested up in the cloud environment the the metadata is once we have the account set up or actually pulled down to servicenow and the checks and verifications are based on the conditions or actually conducted on the servicenow instances so none of these tests are happening up in a class instance environment the datas are the metadatas are pulled out and make that conversion for the interactions here's the dashboard that we have developed and I'm going to pass over to um Raj to go ahead and wrap it up okay thanks thanks man thanks energy thanks all I just wanted to just recap um I apologize my videos and working but um just one recap that what we have showed you today it's pretty exciting is that you've got a set of configuration technical configuration checks that you can now check against jws and Azure against the ice benchmarks you then have the ability to put some context to it against CIS 8.0 and then soon you know as we release more content it'll be against regulations that require that can use these configuration checks technical configure checks so that you can now measure it put some more context towards other regulations put more risk threat levels and things like so that you are able to now measure it and report on it so we are going to put more content so we have a good starter pack we're going to develop more dashboards the exciting thing also is it's one of the first ones in the market where we are now trying to essentially mentioned we are going to bring in we're going to work on CIS 8.1 accelerator for the data center World which used to be the upgrade from the 7.1 that's already in the App Store so now you'll be able to use that accelerator with indicator templates to measure data center controls you now can use these ones to measure Cloud controls and all of them is harmonized against the regulations so multi-cloud multi-computing multi-regulatory all of this is going to be you know part of this accelerator Journey that Andrew talks so this is one of the first ones that's gonna I think it's out there it's pretty neat because you'll have one view here of course they're different people managing different environments but at least you're able to set the guidance set the regulations that are required because they all Impact your all of your Computing environments so we are able to do that in one so that's the idea for this accelerator uh we're excited it's going to release in August I I appreciate if people can start to download in May so that we can get some feedback at the same time we can add more content um I know we we talked about U.S content but happy to add more other relevant content and also some of these tests you know they're coming out of the box but you can add more so it's a lot of it's a good starter pack a lot of things to get you off the ground but the you know what you can do for environment is going to be whatever you choose to and how much more you'd like to customize it so thank you and if you have any questions and Theresa understory yes thank you very much everybody for joining us thank you anushree and Ben and Raj for a wonderful presentation
https://www.youtube.com/watch?v=_YBb5M33ebw