logo

NJP

ServiceNow Federal Forum 2023: Challenge the Digital Status Quo: One Agency’s Approach to CDM

Import · Jun 14, 2023 · video

[Music] foreign welcome everybody my name is Scott Spitzer I do strategic business development for servicenows federal civilian group with me has been Prime and we'll talk about him here in a minute uh it's nice seeing everybody dressed up again you know I came in this morning for a breakfast meeting and one of the executives of servicenow federal came up to me says Scott I've never seen you in a tie I said well I've been here three years and I've never worn one so yeah that kind of worked out good it was it was so positive I went and got my shoes polished I'll put the guy up there so things work out good but um today we're here uh to go through a case study of challenges of the digital status quo one agency's approach to CDM servicenow is presently in discussions with multiple agencies on utilizing servicenow in support of the continuous Diagnostics and mitigation program in the next 20 or 25 minutes bin Prime will show you how one agency utilized servicenow this agency and by the way we will not be mentioning the agency's name at their request so don't ask us reimagine its approach to CDM in line with their overall modernization plans the session will demonstrate how servicenow's integration and Legacy systems in modern workflows enable the agency to combine several layers of the CDM process to work better faster and less expensive before we get started there's a few CDM notables in the audience that I'd like to draw your attention to the first one is Robert Gaelic sitting right down here Robert presently is the infosec lead for Federal Emergency Management agency Robert had designed an architecture to meet the key requirements of CDM utilizing servicenow Daniel Joyner is also here on the front row or DJ from cgi's defense C program and is their lead systems integration manager who integrated this traditional Arc this transitional architecture we're going to discuss we also have Ivan Wu from titanium here we work very closely with him he's the director of strategic accounts for tanium bin Prime has spent 15 years as a cyber security analyst Senior Solutions architect cyber regulations contributor most of Ben's Focus has been on supporting the federal government and the federal government agencies in their cyber Journey architecture and transformational across the mission and the Enterprise and he has been involved in the CDM program like myself since the Inception over 12 years ago so without further Ado Ben and we will have hopefully some time for questions at the end um it's all yours thank you thanks Scott all right um so quickly to get started since we only have 35 minutes it's going to be a pretty tight quick agenda right just in case there's anybody in the audience who's not familiar with CDM we will like touch on the CDM Basics some of us might have been doing it as long as I have and it's kind of a little wishy-washy we're really going to spend most of the time on some of the foundations of technical capabilities volume one and then what was actually the cost savings methodology here and that Simplicity and then if we do have time for questions and answers which if you want to I can go fast or we can always have a follow-up uh in addition there are uh papers printed out in the back of our white paper outlining this also so those are free to take if you want content to lead with um first things first is just in case we talk about anything or have any uh questions that come up Safe Harbor if it's in the future there's risk they may not be exact so don't quote me on it president's present but Future's future um so small to medium agency uh can't name any names don't want to give out exact but I mean how much would one agency could agency uh save over that time right if an agent's small the medium agency saved 200k would that be a good year for budgetary finance to reinvest or 400k I mean and think about what you would save how much money is uh your foundational layer of layer B costing you right what what does that cost to you today right how can you uh take that cost impact and accelerate it uh I don't think of too many people in here for the working for the government wouldn't want to save money and we allocated to the next uh programmatic budget spend um so that's the big thing the that's a quick the opening why see I said we would get through these both really quickly uh CDM Basics um so first things first is definition it's a dynamic approach to fortifying the cyber security of the federal government right and that's the main leadership thing it does come from the foundational layer at the bottom though which is fisma you know the Reporting Act and everything else the law that we follow that provides all of the nist as guidelines right and that gets into one big thing is CDM might be a funded program for agencies to comply with cyber security but it follows the traditional nist type architectures we don't want to lose these right we we have a lot of operations going on and that's a good key foundation of the data we're going to roll up to the dashboard but it is part of the mission and business process rolling up to the organization because it is cyber it is risk and we're trying to tie all those things together strategic and tactical right um so as we go through there I can't cover all of CDM but if you're new we can always have a conversation in the middle column on what's on the network who's on the network what's happening on the network and then we can figure out how to protect your network um and all the future ties we could talk about binding operational directives to a blue in the face because they keep coming out like once a month now but predominantly we're just going to talk about the layers just and we'll get into the layers so if anybody's not familiar with the CDM architecture of the tools layer a uh data aggregation layer B dashboard layer C and then ultimately reporting to DHS at D that's really we're going to focus our attention on layer B uh and c and then just to bring that out to CGI because we mentioned DJ and Tyler uh CGI does have a booth out front so uh definitely stop in there if you want to get more technical uh there you go check out this is where we get into the depth and breadth of uh the foundations of CDM right the big thing is CDM is that middle layer the data aggregation layer no matter which group you're on it's an elastic database right that's the current architecture we knew that there's a lot of data in the federal government elastic data storage is great for getting a lot of data um there are Pros to why we use relational databases relational databases have their place and everything so when we've looked at different customers and we looked at different uh architectures and different implementations there we do find that certain data points are missing because we're putting it into elastic so maybe not every tool is giving us the data structure we need to get the data out um it is schema free so there's probably a lot of extra data in there and a lot of these elastic searches pay for data content um it can be good for the things like document orientation but we don't have documents that we have to feed up directly into the CDM servicenow and we'll really get into where relationships are important in the techcat vol 1 architecture right is oh well that's the sorry my missed clip that's elastic to me you can throw a lot of data in there and you can organize the bits and pieces that you need but there's still a dump of data um in the servicenow is a structured database at a fundamental core we still use elastic if we need to to expand on certain principles but at our true foundation all the data coming in comes in and as a structured so when vulnerabilities come in they attach to the asset the asset is part of the fisma boundary things like that we have the data Integrity so whoever is updating the data whatever you're using in your environment we know when and where it's updated and things like that from a database model along with the transactional security so CDM is a and we can't talk about extras like zero trust but CDM is a foundation of zero trust so we're going to need to get into transactional Security in the future along with this this is more like a library to me when data comes into a library the books get cataloged they get a number they get a card you know when they're checked in when they're checked out you can walk into any library and go get data if you were to walk into somebody's garage and go try to find something in their garage you would never find it right so those were one of the big key fundamentals of understanding what to do with the CDM model that we're about to talk about um click so why did we come to this data structure thought process this is usually what I talked about with customers is if I go into a customer they're going to tell me oh we have our asset inventory in one place and that's our Master device system for um architecture our users are collected in a totally different place HR manages those and they're they're in HR Silo and people can't see their data because it's got Social Security numbers and other stuff fisma boundary oh the risk people don't want to talk to any of the other tools they get their risk in reporting type stuff so there is a lot of places where a lot of organizations have this data right but they're siled from each other right even in vulnerability and configuration Security Management the scanning tool just gives the the scanning team just gives their data to the asset inventory team but there's no complete Master device record right you need that Foundation um same thing we talked about with users there might be other systems and uh two-factor authentication bring your own PIV cat card there might be a whole bunch of data points about the users in totally different siled systems um and then that list just keeps on growing and growing maybe you get some things connected like I want to make sure my system boundaries are protecting my assets and I'm managing security incidents on them but uh my security guys have to go find the assets right and the person who owns them if I have a security incident maybe you've been bringing them in to write your poems and Report up to whatever reporting mechanism you have to do csam or internal um and you've been bringing some of that data in so you have poems but it might not be the whole complete architecture picture right so as you can see we're starting to build out the diagram lines those the reason I made the line so big is because a lot of people don't have the lines connected right because they're throwing data into that massive elastic database and they're trying to get those lines connected on a lot of the finite data because not everybody's perfect in the CDM dashboard is what I hear and completely seen it but not everybody's perfect in the CDM dashboard and has everything connected um so that's the one thing that servicenow does obviously we're here for servicenow hopefully everybody has a good premise of service now but we already understand these types of data right we want to be the master device record right off the bat so we connect to application scanners vulnerability scanners Stig scap compliance scanners we have the cmdb and standard processes for getting all the hardware and software listed on them um along with the risk and cloud-based assets everybody's going and sprawling um and there's been some new orders and other things going on with not just your traditional devices but now you also have to report up all your OT iot devices and starting to get into that so how do you get into those things and have one central place that's the one nice thing about servicenow is that Central cmdb and I'm way fast um so the stack right this is where we get into CDM so anybody who hasn't seen it this is the ABCD that I've been talking about right layer is the tools layer servicenow out of box we have hundreds and hundreds of Integrations to the tools layer already right uh C Master elastic and that's the dashboard the one big thing that I noticed in the newer architectures I'm using the old architecture on purpose the one big thing that I've noticed in the newer architectures on the newer task orders is the left hand bars are gone if we go back to that nist 839 and we're trying to talk about strategical risk and tactical risk and pushing up policy and compliance up and down and I'll put it back there for a second in case that's the policies included risk scoring the policy manager and orchestration and all this stuff that they had a vision for when when the attachments came out even before techcat volume one and two attachment end and all those other things they were planning on having policy driven down right and now it's just happened to disappear I don't know if organizations are supposed to do that just manage it internally or there's no way to push it down because it's elastic and elastic isn't really a thing anymore because RSA Archer used to be in that layer B used to be at the top and RSA Archer is a GRC tool so you'd have that Vision but now it's elastic um so those are that's the biggest thing but what this one agency did what this one agency really wanted to know is what does it really do here right so the Bops um that's really I mean it's a data aggregation layer right it's I take the data from the tools and I give it to the dashboard right and then for some reason like wood what is that why are you doing that um so what we came up with is a long-term Vision goal there was stages in between all this um but servicenow as a middle layer it's a dashboarding tool so we don't need to like take it from the data aggregation layer and put it to the dashboard we don't need to have any other collection tools come in because we have all of the Integrations and even if it's something that's not in the store and you're using a tool that you want to use we have those data integration layers right there also where you can connect to your own applications and your own services and your own data stores and get that layer a your Hardware software your master device records your master user records on your trust behave cred from your pivcac servers or whatever else you want to do and get that data up to the dashboard at the layer D the federal dashboard and push it up because we're open API those two things are supposed to be talking so this means no more elastic in the middle you're using servicenow that you're already using to get your visibility to get your dashboards to get everything in one place and then still have the interoperability to go to the top level Foundation to CDM sorry first thing you have to comply with when you're a tools vendor is interoperability you must be able to talk to the other dashboards right so that I think that was probably one of the biggest things that was proven out in this architecture going from the first phase even into just getting the first bits of data up to the dashboard is getting the data from the tools through servicenow um getting it transformed and getting it up to the dashboard so we add interoperability what this says though is we still have GRC on our application we're in Gartner magic quadrants and other magic quadrants for integrated risk management or governance risk and compliance we can put those bars back in there if there's push down governance like control objectives or like uh bod 1902 they just switched the critical assets must be patched in 15 days if they're public facing right so if you're pushing down governance policy like that then you can be auditing yourself and dashboarding where you're not in compliance with any type of mandate that comes down too and that's the main point of this and I did go I timed myself and I'm talking faster than I thought I would but does anybody have any questions so far on this no no questions on this wow I thought there would be like at least two or three is anybody in here thinking about what this could mean for their organization you are are you thinking short term long term that's a good answer um so if we come back to what you guys would think about short-term long-term what what are your major goals um I would break these down in phases um the effort took uh less than a year to at least prove out the concept um let's do a half a year if I'm not mistaken six to eight months so if you've been doing CDM as long as I have it's taken you that long to get it up to the dashboard getting this interoperability if you're already on servicenow and you've got your cmdb and and you've got some of your assets in there you can start this journey um without thinking of it as recreating the wheel and starting over in another 12 years just want to let you know so the big picture is I put a question mark in the beginning of this show of how much do you think it could save so ballparking not actual figures but for a small to medium Agency on that layer B um based on removing the complexities gaining technology and cost and improving the longevity of the CDM program that's one of the biggest things with the new requests for services coming out um or the new RFI coming out is that you could probably in a small to medium agency see like 800k 700 800 900k in your layer B is what we're estimating most small to medium is on a yearly basis I'm replacing layer B and using servicenow as your data Lake layer and your upper layer um if you're in the higher range we have customers who have 500 million vulnerable items in their cmdb alone so uh because we have gotten into that some of the larger agencies and everything else have said hey can we scale to this level this is small medium right could you do this on big yes we can hold the data for big we have Enterprise customers globally largest Federal customers so we could easily scale to that area um that was the last one I thought there was going to be more questions any questions yes actually Tim I'll get you a second that's going to be an interesting one um we are in discussions and this is where the road maps like thus the Safe Harbor slide comes in we are discussing with our product management um some of it is as a product vendor we don't have access to the the data mapping standards in the new RFI there is a note that says that the prime incumbent if there's a new RFI DHS releases the prime incumbent has to share certain things with this with the software vendors but we also go back to the group incumbents so that's where DJ comes from like DJs uh CGI owns Group C as the prime so they have to facilitate uh the federal agency or the Department's request for service to get the funding if they want to do it that way and then architect this but based on uh how many all the different primes being servicenow partner certified all of them are we're talking to all all the Primes on their contracts they would be able to know what data is in service now and know what data needs to go up to the dashboard so they can make that architectural shift and we would support them on that um and things like that or definitely stop by cgi's booth and see how they could do it can actually uh they've got a demonstration capability of what they what they built for this particular agency being demonstrated right here in the uh in the lobby over here so if you really want to see what it looks like you can go over there and then Tim you you talked about a phased approach but I don't see anything about that can you talk to someone you need to add established to be able to move forward like cmdb yes um well that's a very good question because when we talk in the servicenow world we talk about the cmdb and we go into customers we say where's your maturity of the cmdb that means different things to different customers somewhat horizontal I just need a complete inventory of my assets so I want vertical I just wanna I really want to know my data centers but we'll discover the IP phones later right in the CDM uh thought process what you really want to do is get a horizontal because if we go back to Old attachment and there used to be a quote in there 90 of your assets must be scanned in 70 uh within the next 72 hours if you don't know what a hundred percent is how do you know what 90 is so most people are like oh well I scan 90 of 70 percent okay I don't know what that means but so that would be the first approach is yes get horizontal now with the way service now works a lot of fundamentals in CDM are also I'm gonna pick one tool for my master device record I'm picking Big Fix I'm picking forescout it doesn't have to be that way but service now we use uh multi-aware cmdb and we have service graph connectors which you know they can connect to the Big Fix the SCCM the tenables the titaniums the all those data sets if they're in nooks and crannies of your network and they keep feeding into service now here's another horizontal asset that I know about and you can trust you can really get your horizontal assets collected but then you do need vulnerability and configuration compliance so you got to be bringing those in because that's that's the complete Master device record database if you have a pre-established uh you know given to the agencies that are better what that should look like for this ATM Department wow we have and DJ had to do that for the One customer but all of our data is going to be in the same place it doesn't matter which vulnerability scanner you use we're gonna put the data as a vulnerable item record in that table so when you have to roll that back to the asset the assets always going to be as the core CI and the cmdb it depends on how how strong that asset is is it just a computer or do we know it's a server that's when you get more into the service graph connectors they they get a little better of just you know what an asset is but we automatically map if you're using one of the servicenow or store Integrations for this is my vulnerability scanner it's going to say do you have the asset do you want me to add the asset so I can store the vulnerabilities against that asset then it's just a matter of saying what does CDM want from that you know and mapping the do they want serial number off the Assad do they want what do they want off of it and how that's done right now the integrated pool in the CPM that the CDF has you know we call it uh are you guys use UCI to Therefore your information [Music] but again they require it you know to give a confidence rate of a piece of nature to say no we'll downgrade that we're fine with just uh try to keep up with the IP address and that um so it's kind of two pieces there um one is when we bring some of the service graph and ire which is our reconciliation engine that's really where our confidence rating lives on is this a new asset a different asset or two things four things ten things telling me about the same asset that's really what the reconciliation engine is supposed to do when things come in who is more of your authoritative Source on that is it if if I have Discovery information and we've actually used a servicenow tool to go out and really dig into and interrogate that system and we brought back the information and populated a an asset a CI or and then tenable comes in and it barely gets the host name it can't really interrogate it because it doesn't know what questions to ask then we'll append it with the tenable data that's uh extra right that that's not there but we'll maintain the the discovery information that's more authoritative as you bring in more and more sources we'll have authoritative CIS in that they we also leave the ones that you don't have confidence in in what we call a discovered items table so these are things that we're not going to make a CI yet because it could be DHCP on a one hour VPN and I don't want to just add those to the cmdb and CI so we'll we'll have that structure of what you do consider so and I'd have to look more into this but it may be one of those things where you say yes I just want to roll up my my assets or do I want to roll up my actual assets and some of my discovered items which I haven't really in my cmdb said is a finite asset yet that would be up to you which layer of our data you wanted to push up and don't bring it bring it correct we've gotten past that I think that's a fourth grade when I heard that earlier day we were having that conversation you're saying the only way you can populate this is Win let's go so that's why I want to make sure you answer that one you don't want to talk about it yep and it's and it's because it's a multi-aware cmdb now um one of the root problems was that a lot of Partners made their Integrations for their tool you have an agent on a box you you've got enough credentials and access to say I have an asset and I'm going to tell a servicenow that this is what I know about an asset but they might not have mapped or been completely trained on what data so they put 80 of their data in there and 10 which is supposed to stay where everybody else is putting it they're putting it in random spots oh I got a uuid I'm going to make a random uuid field or I'm gonna make a random field for this um and the store certification Pro uh the way we certify store apps is just making sure that it's not going to break service now and it's not malware but then we came up with the service graph connectors those go one level Beyond it's not just going to break and be malware on our integration layer what they say is let's check the data structure to make sure that it matches the cmdb won't corrupt the cmdb and that they're putting all of their data in the right places in the cmdb now everybody's talking the same tables it doesn't matter if it's SCCM service graph or big fix or tanium service graph connector everybody who's certified of a service graph connector says that that integration will put the data in the right place as an authoritative asset source and then you pick which one of those in ire you want to be the most authoritative if it depending on what data it gets you but yeah before service graph connectors though there was enough of a deviation in a lot of these applications that would say it's not quite you might as well just do a spreadsheet right like you you can mess it up any worse than a lot of these Integrations but now that they're certified on data structure it's a lot different in getting horizontal well I got five I got one other question I thought there was another question over here wasn't there I guess not no anybody else have any other questions or are you totally open to come see us we'll sit down we'll have a longer conversation we'll dive more into the technicals I know I'm gonna go see you soon um but anybody else have any other questions Ben and I'll hang around here afterwards if you want to come up and talk I also as I mentioned before recommend stopping by cgi's Booth see what they've done uh on their system there and we appreciate everybody stopping in today awesome thank you thanks though

View original source

https://www.youtube.com/watch?v=tG3pJj8DM_4