logo

NJP

Platform Privacy & Security Academy: ServiceNow Security Center

Import · May 10, 2023 · video

hello everyone good morning good afternoon good evening thank you all for joining our platform privacy and Security Academy session I'm very help happy to welcome you all to learn more about our today's uh the topic Iran servicenow uh security centers particularly how to improve your security posture with servicenow security Center my name is Fergus Saleem I'm a outman PM in platform security team I am also joined by Stefano who is our main pm and security admin to give us a little bit more insights around today's topic before I hand it over to you to Stefano I'd like to highlight one more important thing to let everyone in this call to be aware of which is our uh Safe Harbor notice for a forward-looking statement as always we have to start by reminding you that we might talk about things that are on the product roadmap and since we are publicly traded company There are rules about making forward-looking statements so uh we just want to remind you to please make your purchasing decision based on the product as it exists today with that I would like to hand it over to Stefano floor resource great thank you forkett uh good morning and good afternoon and good evening to everyone thank you for joining my name is senior principal product manager here servicenow worked in security for a number of years and I'm leading the security Center strategy and execution servicenow today we're going to introduce the serviceness security Center which is a brand new product that is launching tomorrow actually the let me start with a big picture so you know service now and service that is intelligent platform from end-to-end digital transformation it will allow you to reduce costs and drive growth while management risk it is a single platform it's very unique in its Marketplace it is fully integrated with external applications it has a number of application that resides on top of a core platform you can extend and even create your application both with Pro code or low code capabilities it allows you to increase employee productivity you can digitalize any process improves your operational excellence deliver customer growth all from one single platform service now also provides comprehensive security controls recently we have launched a premium line of security products it's called the service now Vault with five products in it and more to come we've always had a very comprehensive functionality across all the different security areas authentication identity security module data privacy we have the reach a set of security controls in the platform of any cloud anything from certificates and settings and login policies access controls auditing and system-wise Antivirus and we do conform with the some of the most stringent Regulatory Compliance mandates in the world including stock 1 and sock 2 Department of Defense ielt for fat ramp ISO 2701 and more but with breath of functionality and we buy for platforms also comes a certain level of knowledge and understanding for some customers maintaining comprehensive security compliance can be hard there's so many features so the so many different settings so many different capabilities to make sure that your environment has an extremely secure posture the almonds are asked to manage the all aspect of the platform the business Logic the growth of the applications the development of the application performance and security compliance the admins are responsible for security configuration but which of the many configurations do we need to pay attention to can we scam environment and find misconfigurations we're also responsible for monitoring for potential security attacks but what to look for and how can be alerted versus having to continuously monitor for events and how can we analyze events that look suspicious admins are also expected to follow security best practices but where do you find them and how can they learn as a as a you know as a maintain this very large Cloud platform well serving now security Center was built from the ground up to help the admins achievous challenges or or improvables challenges it specifically enables admins to maintain the highest level security configuration and security margin it's a set of purpose-built and integrated Tools in one Consolidated app the app will be available tomorrow May 4th in our store .servicenow.com the current version will support the Utah family release in the next families Vancouver it will be installed and activated by default you don't have to go to the store but um in from now on every quarter we're planning to release functionality so in between family releases you're also going to be able to install a mod updated release from the store because we're going to continue to enhance and provide more tools and more functionality to this very important application and security sun is free and will again be available tomorrow security Center is an application built with four separate tools integrated into one single lab security hardening security scanner security metrics and security learning security hardening is what we provide are recommendations on how to harden the environment security scanner will give you the ability to scan the environment I guess a set of checks or potential security configurations and behavioral of Interest security metrics where we allow you to monitor for security events that can be indicative of a risk and be able to both be proactively alerted and also to analyze the data and then finally security learning as well we provide a comprehensive list of resources organizing a manner that allows you to learn over time and I will demo all of this in a few minutes but let me talk about this still four different tools with the lenses of the challenges that we discussed earlier for the admin let's start with the security holding tool this was designed to answer the question how how do I Harden My instances how do I know how to make it as secure as possible hardening is always the place where security starts whenever you get a new device a new system new environment that's what you want to make sure that it is as robust from intrusions as possible servicenow provides 175 recommended configurations now I know it sounds like a lot it's a big platform but also most of this configuration has set to be compliant by Design as you upgrade to any family release or as you start with servicenow and I said most we score this this tool will score will scan your environment and then measure how the system properties and plugins that we have identified as highly important meet the recommendations and then we'll provide a Pneumatic score between one and 100 percent the application default configuration service now core platform configuration yeah is we'll start at 86 percent so there's not a 14 of improvements that we look to the companies to make their own decision these are certain settings that depending on your own security policies your own environment the applications that you have you need to make a decision on the highest score of course it's a more secure posture within the hardening tool not only we score and provide a clear indications of how you comply with our recommendations but also we allow you very easily to identify what are the potential gaps and then allow to change them very quickly if you so desire we also allow you to at any one point in time see why the score amount of change and what settings might change in your environment so you can take action the next tool the security scanning tool answers the question of how do I scan my environment how do I find misconfigurations servicenow provides in this tool a suite of 65 recommended scan checks so the checks will be modeling score focus on system properties and plug-in the scanner focus on some of the more settings that change a little more often and but a little more valuable and it's good to scan a little more frequently and specifically we're looking at table configurations and script configurations with 65 checks we'll check for apples and tables and permissions and things that could be highly Dynamic and it's good to keep an eye on you can schedule or run scans on demand you can also create your own security scanner your own Security checks so you can adapt and use this functionality of a scanning tool to comply with intramural external audits or if you want to even create your own suite for specific regulations that you might need to follow and you want to make sure you can scam environment for it the third tool is the security Matrix tool and this answers the question how do I know what to monitor when it comes to security Trends and security events again service now provides recommendations and best practices we include 56 security event analytics across many different areas including privileged users authentication export uh data and even sensitive data antivirus email active session and more and again I will demo this in just a couple of minutes we also allow you to set pressures this is very important because as opposed to having to keep an eye on them constantly you can put in the system what you consider to be a you know a a threshold at which point you want the system to email you and notify you that you need to go and look at a specific metric one of his 56 one or more and then do some analysis you can also create your dashboards which is a way for you to organize which of these 56 you want to organize in a group and be able to see and look and watch all at the same time in a single view very easily the fourth tool is the security learning page and this of course answers the question of how do I learn security best practices in the security learning Pages we have included all the links to all the sources security compliance that admin would want to use and we organize them in topics so it's easy for them to find but also easy for them to progressively learn so we provide foundational guides which we feel all the admins should be very familiar with we provide security in Dev guides that almonds over time should learn if applies to them things like encryptions and safe coding practices we also provide links to internal politic mutation as well as portals that provide more information let me switch to the demo let's set the demo the first thing I want to show you is how to install service now security Center SSC on United States as you see is released as a store app on a quality basis you navigate to one store store.servicenow.com click the name or the application click on the widget the installation page will appear on May 4th the request install button will be activated you click on the button you type the name of your instance and as long as it's compatible with Utah that's all you need to do shortly the application will be installed and you can still use it let's navigate to the application the first page you would see is the home page a home page includes the navigation typical different tools auditing scanner metrics and learning it also shows you a current auditing combined score we discussed earlier how this is a critical aspect of your security departure we provide 175 recommendations for your ali um security system poverty and plug-in relevant system poverty and plugins but we shook most of us by default as compliant in fact the the score that you will see first installation for a you know vanilla implementation would be 86 percent but we leave a number of settings up to the customer to decide what do they want to turn them on or not um and that's because depending on your own certificate policies your own applications environment and other factors you need to make a decision for that is something that is important to you or not and we make it easy for you to go through that process in fact we show the top non-compliant hydrogen settings right on this page we're ranking based on criticality the most critical is that the top uh also the most critical has a highest impact to improve a score typically you will click on the first one evaluate that and move to the second one and so on so if you click on account recovery you will see real hard learning settings Details page this page has all the details that you need to make a decision provides this core impact the priority if they had a functional impact that was shown there it will also show the details of a functional impact they give you a description of what that configuration recommended configuration looks like in this case we recommend live.sso.acr.enable to be true to enable the account recovery if you click on the documentation link it will give you the details on this setting but also about the all account recovery functionality and why it needs this needs to be set to true to enable that and what you can and can do with it if you chose to go ahead and comply with it all you would have to do is to toggle this uh toggle to the right and then click update you can include some notes for audit purposes or for letting out I'm a no and record why you chose to make it compliant or you chose not to make a compliance you will go back to the home page click an update score and the score will be increase by 0.85 and then you move to the second one and so on there's another way that you can use the ordering tool to improve your heisen score and that by using the hardening score comparison this is a tool that allows you to compile any two score on any two dates and tell you what's changed in this case I'm showing the difference between April 27 April per view and the score decreased by one percent it's a single setting so it was critical and it was authentication related uh it was account recovery which already covered for sake uh mid ammo uh you will click on it again you will evaluate and you you would choose where why this was important important you would choose whether you wanted to make it compliant again and increase your score and increase your security you can also see at the trend are your score over time all the visualization Leverage the analytics Hub capabilities of performance analytics that is a standard analytical capabilities in the core platform available to all our customers it has a lot of interesting and visualization capabilities allows you to change a chart do some forecasting do some statistics you can change the time frame the frequency of the data you can set some targets you can set threshold and I'll discuss this a little more details in couples minutes and provides all the events you can export them you can filter them you can manipulate them and better understanding why your score change over time let's talk about the second tool the scanner this camera gives you the ability to scan your environment or configurator security configurations or tables and scripts well the coordinates focus on system properties and plugins the scanner complements it but looking at some of the security configurations that are a little more dynamic and specifically we include one set of checks called the audit tools this week so checks are collected in a group into Suites auditor is the out of the box Suite that service now provide with our recommendations there are 65 checks or configurations that we recommend you look out for and includes things such as looking for users with a limited access users request the main visitor um unintentional cross-code prevalences uh table that are accessible from all internal users all external users but that would be a problem when you run and Suite like auditor and you can choose to run it manually or on a schedule again you can choose a weekly monthly every two months it will create um findings which means every time a check failed it will show you a pending for it in this case I just plan the auto Suite I found 131 potential insecure cable or script configurations each one of these findings will tell you the check the priority the table the same tracker run over multiple tables which stable actually failed which also details here the details on how to resolve the issue documentation provides more information just like with a compliance score we also provide a comparison of a scanner in this case I'm showing the differences between April 24th and May 1st I ran the same sweet auditor 51 checks but there was one incremental finding that was not uncommon between the two different results it's high it's I've got the global scope it's in the access control domain and it's listed right underneath it and that is it's an access control tables basically between April 24th and May 1st I either added a table a constant table for example for the lab again like just before all a change or configuration on an existing table and remove articles controls on it very important to know let's talk about the pro tool security metrics security metrics provide out of the box 66 security events that we keep track of and visualize as a trend over time so you can identify potential risky Behavior or attacks to provide information about privileged users including an active lifestyle for my failed to login when I have not logged in for a while we provide information about authentication for example keep track of your MFA program over time how many users enroll who's bypassing it who's locked out we show you the information about experts both for overall actually records outside of your environment as well as classified outputs look at antivirus type of information such as quarantine piles station management Etc lots of different information I will give you also the ability to create your own dashboard this is standard service now dashboards called my stupid metrics and this gives your ability to just include a widget for the Matrix that you're most interested in you can edit it you can create multiple tabs and you can have a quick glance of things that are most important to you in this case I'm just just for demo purposes I picked some metrics and to depict a couple different ways that you can use this capabilities for one of them is to measure your security functionality adoptions and program for example MFA so in this case you'll see that the number of users in one MFA is increasing all the time but it's not quite rich in your target if I were to click on that widget and go to the details I I get to again a visualization standard visualization lots of capabilities for analysis but you will see very quickly that yeah while I'm increasing the number of adopted users I'm not quite meeting my target my target is set of 500. another way to use the metrics is to look for potential insecure behaviors one of them is classified exports the classified export allows you to choose which classification we have a classification system that is customizable so you can assign to different tables or Fields a classification this is um super secure this is a absolutely secret and you can choose which of this label you want to include in this report and then it will monitor every time how many records are exported on that day in this case you can see that there was a spike in um very recently in fact their current over a weekend while the typically classified experts are very low or none on Sunday the actually 200 records were exported which definitely calls for concern and investigation another way to use the information or similar way is to look at fluid uses fail logins typically if you have a normal number again especially for privileged users um is one of a number of potential security concerns might occur one is group Force attack people are trying to get in as they enter different password the system fails it could be a signs of potential compromise of login information about whenever you see a spike um it's another area where you probably want to look into it a little bit you want to see if anyone will feel like um privileged users actually then get authenticated and in particular in this case you want to see one of those is associated with that spike in classified Explorer records which would be clearly very um concerning back to economy capabilities I want to point out the ability to decide pressure is very important so for each one of these security metrics you have ability to say semi-freshold which is a number above or below or which you want to be notified in this case I set a special pretty well and if this was a real life environment on Sunday when the number of failed logins exceeded a threshold and I would have received an email I was immediately known to go look for more details let's not talk about the last two the security of learning secure Learners it's simple but yet very powerful it is a collection of all the security and compliance resources that you would ever want to find and it's organized uh in a manner to help you find information but also learn more about past practices over time we provided the top released notes for both the family as well as for the app we provide the foundational guides these are the guides that we believe every admin should be very familiar with such as best practices they did an ebooks a class secured the ethic too then we provide security depth this is an area that most elements should also be familiar with your access controls your encryptions spam um if you do your own custom application secure coding guides we also provide specific guidance for regional and industries such as gdpr the very common and interesting resource and then on the right side we provide links to additional sources of information such as product documentation for Skin Center servicenow vault which is a bundle of Highly integrated and secure Advanced functionality health and security and also portals uh for example you can have you know Finding quick access to our Cloud security trust and compliance Center that then provides additional resources about privacy penetration tests and application security and more uh very very important to have all these resources and use them to improve and understand better what service now provide are some of the best practices build them you know a large security team and interested in best practices as well and this concludes the demo I mean the presentation mode for the slides just one second sure thank you awesome thank you so much for example Stefano it's really wonderful and I see there's a lot of questions coming up regarding to the old version of uh instant security Center versus this the new built security Center that's on some of the transitions on the hardening score related so I think he already answers some of those as well so if you all have any other questions regarding to the new product uh you know feel free to type your question there and then we'll happy to answer yeah and there's only a couple of slides and then we we on purpose we laughed a lot of time for Q a we understand that it's a new product and it's going to be um probably fundamental questions and we'll be happy to answer as many as we can live one one notion I want to make sure you understand is the the service now security Center is a new product um it's a version one we have a rich road map ahead of it we're going to release new functionality on a quality basis we're going to add tools we're going to improve and increase the content in the application and there's a lot more to come so stay tuned please start using it not only is immediately valuable but it will also expand and provide much more value over time and again on a quarterly basis on a pretty rapid pace so let me just close key takeaways um security Center was designed from a ground app to help admins do the security compliance jobs it is very intuitive it's easy to use any M bad service now security best practices the 175 hardening configuration recommendations the 65 auditor checks with 56 metrics the number of guides that we provide and recommend for instructional purposes and it's free and it's available in the servicenow App Store now well tomorrow and there will be a new version in every quarter and it will be again deployed and installed by default with the the next family release book it you want to take it from here sure all right so if you go uh to the next site I'll just uh happy to to talk a little bit more about some of the available resources how you can reach out to us so we have uh social media platform uh which is YouTube channel where we're going to be uploading all our uh the content for previously um the mate Academy session topics as well as incoming ones plus this one too uh you'll feel free to scan that QR code and you'd be directly to our the YouTube channel where you can see all the the recorded content there as well as always we have a documentation there and you feel free to scan that QR code as well to understand learn more about uh some of the other components that uh the Stefano introduced earlier regarding to uh the the service that volts some the identity and access management as well as the security Center related products there as well at the same time we have our community site where you can post your questions and some of the concerns regarding to plugins and when will that be available whether it's the free or paid version or not so I'm just going to add all the the links here on the zoom chat so if if you haven't scanned that so you feel free to click that you'd be directed to that page as well so the next slide and I'll I'm sure you all are aware that we're going to be having our uh an another session coming up uh two weeks from now May 15 to 19th I think the the registration link as well if you're interested in going in and understanding more about our not only the security products the offerings that we offer but also uh generically on all uh the service now platforms so you'll feel free to register and then uh it would be in Vegas as well the last but not least uh I just want to highlight some of the platform pricing Security Academy sessions and incoming topics that we're going to be covering in the June 14 we're going to be covering project employee and customer personal information with servicenet data privacy which is one of the major components of servicenow volt with all uh Regulatory Compliance like gdpr and HIPAA and on July 12 we're going to be covering protect service now platform with uh this servicenowable uh mostly focused on financial service operation as well as Healthcare operations in August 15 uh that's definitely is going to be covering um more about uh the login Analytics tool like we call it Las a log expert service which is one of the major component of our service network as well and in September 15 we're going to be covering uh exploring the benefits of and the challenging of cloud identity and access management which is another product area that we offer as well so with that I'm just going to jump to q a I think we have pretty much a lot of questions povert while Stefano is presenting but if you all have any other questions feel free to type on the zoom chat and we'll be happy to answer yeah there's there's a question in there about can we when this launches into the store tomorrow we'll be able to install it onto our pdis uh I I assume that is yes but I I just hope this is the standard core platform capabilities so yes you will be able to install this on a personal development instance uh which is a great way to familiarize yourself with the capabilities and functionality NSC was another question but I think I click on the wrong button um John asked if creating a custom Suite or checks is that ability to copy an existing suite and modify the copy and the answer is yes um the way it works is any checks that we provide and we provide was 65 auditor checks we also have translated all these settings the auditing settings in check so 175 checks for the settings any any other checks that you create yourself you can associate that with any one Suite so all of us are reusable so you can create a suite that includes all 175 checks that replicate the hardened score and then modify them and change them exclude some add some of your loan you can also mix and match uh checks from the auditor that is very focused on tables and scripts and hardening with focus on system properties and plugins and add your loan so it gives you lots of flexibility to reuse any checks that we provide out of a box as well as use multiple times in different Suites checks that you create yourself and you're associated with Suites it's very easy to create a new suite and then you can schedule or on-demand run any of those Suites as you choose let's see another question does the security Senate work in GCC environment and the answer is yes it does work in GCC environments I know that let me see what else um I answered earlier in the chat and I just wanted to say live lots of questions about the a earlier version of security center from servicenow called instance security Center the instant security Center is our Legacy Center it was built a number of years ago it's included in all our family releases it is also an app that Legacy security Center will go and those the end of sale process will start tomorrow and by 2024 we're gonna remove it completely from the environments starting with Vancouver uh instant security Center ISC as we call internally will be removed from a family release but existing customer will continue to be able to use it so you will have both IC and SSE in your environment we clearly would prefer and recommend that you use the new version not only because the capabilities and user experience have been greatly expanded and improved but also because it is the only security Center that um embeds the latest recommendations uh from servicenow just to give a quick example the in ic you will have the existing 95 settings recommendations coming tomorrow with SSC we've expanded that to 175 and that's because we are continuously monitor an environment we consistently audit an environment and our internal security team continually improves whatever six months uh improves what we call the Baseline so that customers can always have the latest and greatest recommendations from servicenow let me see for a lot of questions and then there's three more uh questions stuff you know I think yeah I think there there's two more right now so I think I answered the one so the one is if creating a custom Suite of checks is your ability to yeah I answered that earlier yeah so that was my first answer and I stopped flashing by it questions about Health Scan that's an important question Health Scan also provides a security score and yes the Health Scan score will align with some now security Center they're both going to reflect the exact same what we call the instance security hardening settings the same Baseline and it will um he will reflect exactly the same score not immediately but in uh pretty shortly they are going to uh sync back and we're both gonna represent exactly the same set of settings and the same schooling algorithm all right so with that I think we answer pretty much all the questions if you have any more questions feel free to type on the zoom chat and just it's scanning for the question I already answered in line to see if it is something that one thing that I want to reiterate but it's important is the the 100 settings compliance score which are up at the highest it's going to be 100 very not many of our customers will have an environment and have policies to achieve a 400 percent it doesn't mean you are an insecure it means you are secure as you know whatever score that you uh can improve your settings and plugins and the tools makes it very easy for you to do so it is the right answer for you um not having most of a customer will fall between 86 percent 100 percent um and again the the choice uh it's it's up to you is always trade-offs with security but but you will be able to uh monitor your compliance we're gonna continuously provide additional recommendations over time so you can continue to improve your security posture with this tool um and reflect in your own environment the best and latest recommendations from servicenow and I don't security team right like that old saying that that you can unplug the server from the network and from power and it will be perfectly secure but it won't be much use to anyone so that that sliding scale of usability and security definitely applies here with that score yeah that's the way we put on it well thank you Stefano thank you Jared so any other question um Stefano that you you would like to highlight a little bit more where uh what would you like to end here uh no the Highlight is you know please um tomorrow uh uh go go to the store install it you know put on a sub production system uh get to know it um and as always you know feel free to reach out to us and provide feedback or you know ask questions through your normal you know channels it's new and exciting I think we'll deliver a lot of value uh and and in a very seamless and intuitive way and again um keep keep an eye on it because we're going to continue to provide more value more tools um and we it's part of our commitment to service not commitment uh to your security and compliance and we hope you'll um you'll endorse and use it and provide feedback so we can continuously improve it well thank you Stefano for joining in I appreciate it for your walkthrough on all security Center so thank you all for joining this session and I'd like to conclude this session here and until next time stay tuned a wonderful day bye-bye okay

View original source

https://www.youtube.com/watch?v=_4tOfP4liRk