logo

NJP

SOAR as a Foundation for Zero Trust in Healthcare

Import · May 09, 2023 · video

hello I'm Jonathan albaum the federal CTO for servicenow and I'm pleased to be joined today by my colleague Arun Ayer one of our field ctOS and we are going to talk about how servicenow can serve as a security orchestration Automation and response tool and how that is a foundation for zero trust in health care now the the digital economy has had a huge impact on people's expectation of how they receive Health Care in in all aspects of our life we have expectations about how we receive service that it's digital that it's based on uh the consumer experiences we have from our favorite brands that when we interact with government it's seamless and when we think about the effects of of the pandemic on on our lives and and health care we expect to have health care from anywhere telemedicine became a part of just about everybody's life during the pandemic and that's changing the way people receive health care and how we secure it now that creates the the required to store protect large amounts of personal health information and the collection and protection of that data is really critical and an important part of any Healthcare agency zero trust Journey that Healthcare data is is an asset that bad actors are interested in stealing and acquiring and monetizing this against our our wishes and against our knowledge and you know this overall creates a real threat and impact on the way organizations are trusted especially government organizations it impacts the reputation of government and can create a real Financial exposure and tremendous risk for agencies and the people that they serve and servicenow has a role to play in supporting zero trust architectures across government and healthcare agencies like a room to talk a little bit more about the role we play and how we support these big initiatives thank you Jonathan so you know just so that we set the Baseline on what is zero trust uh by by now you know there's been a lot of uh talk about zero trust including in the president's management agenda uh on calling out that we should be approaching this issue so there was a time when we said you are authenticated and authorized once and once you come inside the building you can open every door and do whatever you want inside because we already authenticated you but from that we have moved to zero trust what does that mean is that you are authenticated and authorized for each time you enter and each action you perform what that really means is that we have these assets that we are protecting whether it's facilities databases applications various things that we have uh of interest and value and we are protecting that from the signals which are the users devices applications various uh internet of things that are coming in and accessing the assets so we verify them and we allow or disallow based on each and every action for each you know each time they come in so what does uh that really you know entail Jonathan you want to talk about the the pillars sure um you you mentioned uh really the the core idea it's that asset protection and really understanding what we have in our environments and we when we look at this maturity model from cisa you notice that you know the pillars are you know these key ones are about the devices on the network the network itself the applications and the data of the um you know that that's running across the network that's in the applications it's on the devices and and really who's interacting with them and those are core ideas those are core asset Concepts that are part and parcel of what we do so well in service now servicenow is a great platform for connecting disparate systems and data sets Connecting People connecting applications and being able to store that data in a single place so we can begin to take action on that data and really understand it and protect it in the best way possible so you know that's a lot to protect and there's a lot of things in the organization and we've simplify it in this you know we verified in the middle from a single platform automated access verification vulnerability management Etc what does this really entail um so nist has come out with this model let's say you know you really have to look at this whole thing and the challenge is that every organization has is that the the the assets are disparate and the organizational division or business units that manage these are disparate so you really have to orchestrate the whole thing which is where we're talking about security orchestration Automation and response and those processes need to mature and we need to protect the data and services all Enterprise assets so this is the model but where do you actually start so that's where we talk about the Enterprise configuration management database Jonathan you want to talk about that the cmdb is really uh the core to service down again a service down is a platform and there's lots of technologies that are part of the servicenow platform but the most important aspect from my perspective is certainly what we talk about zero trust is the configuration management database the place where all of these configuration items the the devices now software applications where they sit and having a robust cmdb begins to create a tremendous opportunity for the agency not just to be more secure but to become a lot more efficient so you know the cmdb being the repository for all the infrastructure items is good but how do you know what is the criticality of an application that is using the infrastructure items in your cmdb that's where the common Services data model brings all of that together inside the platform in a cohesive way and use then start realizing the sensitivity of an application for maybe the storing uh personal health information and it is more critical because of the services that it provides to patients to Providers to facilities how do you know that and that's what this common Services data model captures so you prepare for an eventuality and should an eventuality occur you know which system to bring back first uh you know whether it's the patient services application or is a timesheet application those are decisions that you're able to make because of this data model and all the dependencies and relationships that are link through it and and once you have a handle on the data in the organization it's criticality along with the assets along with the devices the hardware now you're really setting yourself up to be a very Adept at managing risk whether you're using risk a risk management framework using other risk capabilities servicenows governance risk and compliance capabilities built onto the servicenow platform provide a great way to make smart decisions about those assets and how you're going to protect them okay and this you know we see we talk about policy and compliance management and audit management all of these these tend to be documents these are policies and procedures and documents but service now gives you a way to automate that and actually make it controls within the organization that you can task people with and manage and monitor right so that's this the the user interface that allows you to manage all of these with the ingestion of different content from content Partners technology partners and really bringing all the risk audit vendor risk management all of that within the platform with the same simple user interface again everyone's servicenow is a great platform for integrating Technologies and we'll talk about this a little bit more but when you think about uh that diagram or you know similar kinds of approaches where we're integrating security uh instant response Technologies or vulnerability management responsibilities you can really see how servicenow is a great place to begin that sir that zero trust Journey from the perspective of security uh orchestration security automation security response when you look at the products on this page these are things we have in every just about every agency has in their environment so some if not all utilizing the data from these to automate actions is really critical to being able to respond fast and make sure that bad things are quickly remediated before those bad things become really really terrible things so we have a tremendous opportunity to to work with these products to to take action that can make an agency much more secure right and if you see the the way we have kind of categorized the detection the vulnerability the FED intelligence orchestration all of these products each of these products are good at what they do but they are specific they are local they are Point Solutions and they are not aware of each other and what servicenow is able to do in the platform is provide that integration the interoperability and bringing all of that together for consumption by strategic individuals as well as operational and tactical individuals right right it works for vulnerability response it works for um security security Incident Management and you know even even more broadly it sets the uh the stage for process optimization and it sets the stage for utilizing AI machine learning kinds of capabilities also built into the platform to be able to take Opera to operate on that data and and do big things so it's interesting point you have kind of led into uh Jonathan you know we can automate it but what is the point if we automate it and don't learn from it and that's what this really allows us to do is it allows us to learn from what happened before so we are prepared for the next time we might see it so predict prevent automate these are kind of progressions that we can go through because we have it in the platform we are recording it and we are learning from that to prepare you know in a continuous learning feedback right so that's kind of the approach uh let me talk a little about the interoperability and integration because we've been talking about servicenow is the platform which can bring everything together how is that we make it happen is by this component we have named automation engine within which there's an integration Hub that allows you to have pre-built spokes to various different products so you can in a no code low code manner configure the Integrations to different point Solutions and bring it into the platform uh there's the modern API based integration there is the RPA which is a robotic process automation for legacy or other custom solutions that we can integrate with as well so just a quick list all of these are Point Solutions but there are out of the box Integrations for almost all of them uh and if you if not you can actually build out your own Integrations very simply with a low code kind of approach to this this is how that complexity that exists in different data models different user interfaces different point Solutions all bring are brought together for a seamless experience to the Strategic operational or tactical user so and we're talking about hundreds of out-of-the-box Integrations that can be applied in this manner and when you think about those Integrations um and the ability for the servicenow configuration management database to serve has that asset inventory that repository of the devices of the hardware we think about the data management capabilities that everyone's describing that give meaning to the day to those um to those systems what kind of data is stored in there the criticality of that data can really take a a a very smart approach to managing risk and Remediation from vulnerability management to security incident response you can prioritize and triage your most important systems your most important data first and uh foremost and what does that lead to it it sets uh up an environment where we can have that conceptual single pane of glass where people can go one place to understand the uh status of an agency's operation it's risk it it creates the opportunity for automation of uh end-to-end business processes and digital digital uh workflows it creates the opportunity to change the way people think about the it organization and how it secures the state the data of the agency and and really gets people focused on the most important things so we're able to change not just the way we work with systems we can really change the way the agency operates and that's I think a really key takeaway when you think about servicenow and zero trust and the role servicenow plays in security orchestration security automation insecurity response that transformation that digital transformation that's taking place in so many aspects of our agencies using servicenow can be applied in security and applied to this big mountain big set of projects we're calling zero trust we're able to adapt very quickly with a platform like servicenow and we can orchestrate Enterprise processes Enterprise automations using Technologies built onto the platform and and in the end we're able to bring together the security teams the risk teams the it teams and and really remove the friction that sometimes very naturally there we can eliminate human error by automating processes and and create a a much uh less complex and more secure environment in which we we're delivering health care and other vital Services across government oh I just want to add that you know I I focus on the people a lot and the fact that um by hiding the complexity you have you don't need individuals to learn different products and tools and Technologies and the intelligence does not need to be outside in individuals you can actually build it into the platform and thereby reducing the the risk and the complexity you already mentioned simplifying the whole thing and I think zero trust not a single solution but servicenow enabling and facilitating managing uh the preparation and the remediation for the uh you know any eventually that should occur so back to you I think that's a great way to conclude our presentation and say thank you to think about those Integrations and the role that service now plays on this long and complex zero trust Journey so with that I want to turn things back over to a rune for Q a thank you thank you Jonathan thank you for that presentation now we have a few moments for some q a so I know the audience has heard me a million times but if you can use their chat function to ask any questions you might have but I'll get started with one I see already here uh first question we have from this presentation it sounds like zero trust is primarily a responsibility of the Chief Information Security Officer is that the case yeah thank you thank you Jamie and thank you everybody for attending this presentation and uh yeah it does sound like that but you know if you sell one of the slides where we talk about uh uh common Services data model we talk about how the uh linkage between what we are trying to protect it as Assets in your organization in terms of infrastructure items and how they all connect back into a business service uh that also expresses the criticality and the sensitivity of Phi pii uh it is not only a security uh issue right I mean the the system needs the information that identifies the applications and infrastructure and its criticality so I think there are many stakeholders and they all have to work in cohesion and uh you know make that uh linkage so that you protect the one the the infrastructure and the services that are more important to the organization I hope I answer that question yes absolutely thank you another one for you it seems like there are just so many moving pieces here where do we start and and this is a one that we get a lot and uh I I do when I do these presentations um I think the most important thing is to identify what you're protecting right and when you want to identify what you're protecting in your infrastructure the cmdb or the configuration management database is the first effort that you want to address and that's where you're Gathering the things when I say the things that the CIS the configuration items that you track manage and monitor in your organization and that's the cmdb uh you got to be careful a cmdb can become very exhaustive and daunting but focus on those things that are important to the organization and capture those so that you can track management monitor thank you Jamie of course and one more for here for you while we have you here for those who've already implemented some of the pieces of this that you describe and to a great degree of maturity where can service now still help right so um you know when you went through the presentation and you saw that uh we are not really you know there's no one solution for this whole thing right and you definitely will have organizations that have done more in one area and less in the other uh but the single system of Engagement that brings everything together and takes out the complexity of managing it from a strategic operational and tactical approach um that's where service now can help by integrating to those already mature implementations maybe you did endpoint security and you thought that was very important and you did that so bring that data in provide dashboards provide operational and tactical dashboards for managing that uh while you're building out the other pieces which need to dovetail into the overall picture so yeah service not can help because now this is going to be flipped like a switch on one day and everything is going to work right so it has to be phased and and use the ones that you already have as mature Solutions as phase one and then continue so that's the way we can kind of bring everything together thank you great well thank you so much for your insights and for your presentation today we appreciate you being here thank you Jimmy and thank you to the entire team uh for giving us this opportunity thank you

View original source

https://www.youtube.com/watch?v=qqHF60RYi4s