ServiceNow Federal Forum 2023: Getting the Most out of ATOs
[Music] foreign [Music] [Music] [Music] [Music] what's [Music] [Music] [Applause] [Music] account executive I don't know what any of that really means is also a um [Music] acquisition since 2000 uh actually I have it backwards yeah 2009 I'm retired right and then now I've worked on it acquisition since 2010. the significant projects United States Marine Corps ball centers [Music] for those of you are familiar with that [Music] [Music] that you see when it comes to managing atos in the context of different types of cloud models like SAS paths and infrastructure as a service probably that having a provisional Authority or having an as of service designation equals an ATO it you know it's one of the controls that we look at to have an ATO but to get to ATO is is a much deeper dive The Inheritance model is beautiful and we make extensive use of it within the naval Enterprise ATO but [Music] getting to ATO is a long process and that is why we've like we've kind of gone into our Enterprise model so that we can save as many people as possible from that little ring of hell right I mean actually I would I would actually also add when it comes to that sort of explanation the the misconception that I've seen is an area of like the shared responsibility right yes so shared responsibility is a big thing and so it's really critical to have like say what what service now has is a customer responsibility Matrix so as van and Alex they kind of maneuver through the waters of an ATO they're able to take a look at our our CRM or customer responsibility Matrix to understand what responsibilities does the service provider has but also what Vans organization will consist of or what they're going to be on the hook for and I think with that too the challenge that Vance team often faces is they have to digest that customer responsibility Matrix not just for how the peo operates to get the ATO but then how do other Navy customers who are now a servicenow customer and a peo digital customer what are their shared responses abilities what do they have to accept and how does the organization the Enterprise organization support that and then the other side of it too is time to Value time to ATO uh you know a lot of times the averages you're looking at a year and a half or so they did it and I want to say it was like 92 days now it was a it was a crunch but it was accelerated and I think because a lot of things already exist because it it was the number one priority of dnao at the time and they put it to the top of the list because it's a very it's a long list and I won't even say it's distinguished but um getting to that really what I want to talk to folks about today is the business value of our Enterprise model and Alex's point there is that it takes 18 months and we've estimated anywhere from 1.5 to about 3 million dollars to get to an ATO so if somebody else already has an ATO why would you want to do that why would you want to spend that much time that much money that much effort um live that much time in that outer ring of hell that I spoke of when like you say somebody else has already done it so that's what we've done with our within the naval Enterprise is we took your provisional Authority we added the disa controls we added the scca controls then we went and answered the last little piece of that for the the naval authorization office the Nao so that we're dealing with maybe 10 percent of the total controls to get to that ATO and our customers are dealing with maybe one percent of the controls they just have to make sure that they're complying with what we're doing what we're providing they don't have to do all that other work and we can onboard a customer usually from start to finish we're done within 90 days so 90 days to ATO fully operational capability or 18 months to fully operational capability we provide devsec Ops capabilities we are you have a second and uh production uh instances and we do that across the Enterprise for both Navy and Marine Corps so that's that's really the the big business value that we get out of this is that we're saving all of our customers literally tens of millions of dollars and then within that just keeping an ATO up every year I'm sure some of you folks out here have to do that annual security controls how much fun is that getting your ATO renewed every three years that's a lot of fun too well if somebody else is going to do that for you how much you willing to pay for that every year we charge our customers you know we've got we've got some different instances but less than fifty thousand dollars a year for that service so again multiplying that across we've got about 25 customers onboarding we've got another 10 to 15 in the pipeline that's two and a half three million dollars a year that we're saving the Enterprise cost avoidance you know million dollars here a million dollars there pretty soon you're talking about real money it definitely is yeah it's adds up right yeah yeah yeah um actually it's a good segue I was wondering I know you shared a little bit I was wondering if you can share a little bit in terms of you know what sort of um sort of Lessons Learned or things that were overlooked you know as you kind of maneuvered or just kind of gone through that whole journey of of obtaining your authorization as an agency can I pivot a little bit here to the so I think I think the RMF process is pretty well understood what you've what you need to do the issas the isscs they they know what they need to do to get you there it's not a fun process it's painful and it's time consuming and it's expensive as we've talked about but there's not a whole lot of mystery in getting an ATO it's just you know a lot of little death of a Thousand Cuts kind of thing um but you get there the thing that we're struggling with is is the business model of how do you implement that and make it pay for itself when you're not a service center you know I don't know the the Navy has service centers and they've they're set up to bring money in and but we at po digital and particularly down at uh um the platform application Services which is the branch of peo digital that provides the [Laughter] that's that's my project it's the service now as a service Enterprise snazzy and you gotta say it with jazz hands otherwise just not as much fun um the thing that we've struggled with the most in implementing that business model is the fee for service piece and so what I would advise anyone who's going to go down this path and I think really everyone should is make sure you have a fee for service model that is efficient and effective we got there but God bless Laura Reed who is our business Financial Manager The Way We Were currently the way we are currently set up and we're going back to the drawing board to revamp this entire model but it was literally a series of one-off processes everyone depending upon color or money depending upon what Echelon they were etc etc made it a different process for each individual and what does servicenow do it gives you you know nice processes and it's process oriented all that well maybe we should have got the product before we developed the the pay model but um it was very painful and we like say we backed off this year and and we're looking to re-implement the P for service but that would be the number one thing is figure out how you're going to pay for it everyone says oh it's fee for service well that brings a whole nother set of uh of challenges to work through to get to an efficient an efficient and effective way of doing that so um by all means you can this is not difficult our cost card is you know you start going through there and it's makes sense it's perfectly you know as a customer they go through oh yeah this makes good sense we're we're not over charging we're not charging for stuff that doesn't make sense to the customer but at the end of the day you've got to be able to get those funds no matter how reasonable it is there needs to be a way to do that so the one the biggest lesson learned for us is to to start with uh the end in mind in terms of your fee for service model and how do you do that um it's all well and good to to say you're as a service but yeah and unless you're in an organization that is not adopting the operational model that DOD is which is that you're War Fighters your your operational forces pay for the services you're only paying for things that you're using that way and that was what we had in mind but the the hierarchy of Administration if you will the the financial hierarchy within the Navy just did not was not conducive to that fee-for-service model so gotcha that's our biggest that's the biggest hurdle that we're facing right now and um that's so the advice that I would give in terms of Lessons Learned know how to pay for it that's a good point Alex yeah I think to that vein too though it's uh it's also you know we're asking a an internal organization to sell itself you know so really was uh some of the things we learned is communication how do we you know collectively as partners make sure that the other parts of the Navy and Marine Corps understand what the ATO is and what their responsibilities are um so to like to the point where I was you know now as the account executive I have no RMF experience I will tell you that I tried to avoid it when I was in the Marine Corps and now I feel like I'm uh eyeball deep in it almost every day and uh creating a document to share with my own internal team so that they can understand hey when your customer asks you this is this is what this means so some of it is also how do you sell that to the to the rest of the Navy because a lot of times people just don't understand they see service now they're like okay we've got an ATO but what does that really mean wait why should I pay PE digital for an ATO and it's like well because you could alternatively do it yourself and to Van's Point you're going to spend you know 15 X or more on a uh on an ATO to do it yourself so it's helping them sell the value in an Enterprise offering but but the time to value for everything is is way faster so I think the biggest one of the biggest hurdles from my side that we faced was just that communication aspect internally amongst servicenow right between servicenow and peo digital and then with the rest of the with rest of uh Navy in the Marine Corps as well cool he brings up a point that's something that I'll play off there the internal communication is another there's a value added piece there in that when he talks to the naval Enterprise he's talking to one there's one belly button to push that's us when you talk to other organizations there's multiple atos that you have to deal with and so that that turnaround time between oh we've got an issue to okay we've got the right people working it and we've got a resolution is much shorter when you're dealing with one ATO and in comparison to multiple atos across the Enterprise so you're really um you're You're Building or you've built a blueprint in terms of how other organizations aren't able to create their own um I would say what an ATO as a service right and now those sub agencies or sub Works can essentially you know adopt or inherit you know that respect of ATO um Alex a question for you so you and I we've we've collaborated a couple times we shared ideas um what sort of things that you can share maybe we haven't talked about today that we that you were able to help van navigate as they were kind of going through this sort of phase um so I think you know some of it is the communications like I addressed uh other sides of it is also just making sure reach back to you know to our collaborations of finding the right people internally like like I said I'm not a security expert you know I I rely on David for that and uh and making sure that we're pulling in the right resources and it does make it a lot more efficient and we got greater buy-in I'll say from the rest of servicenows as a company because now to Van's point we only have that one belly button that only one organization that we really have to work with all the scans that need to be done you know like they want to do scans all the time well if any of you are familiar with the sort of our scan policy you get a 30-day window for once a year right well what we proposition to them is like look we have one entity that's managing the authority to operate for 30-some customers so how about we just allow instead of 30 different customers coming to you each with their own 30-day window how about we just get peo digital the year window to do scans and it's like okay we can we can that's actually less work on the security team oh I was going to say yeah that really would help us out a lot so yeah especially our support teams right that are Fielding those cases as those pen test record or requests are being spun up absolutely I love that yeah um [Laughter] oh I know you can um uh van I was wondering maybe you know this is this is something that I get I understand but yeah so someone out here was like are you gonna go deep in the atos and I'm like no don't do that but this is our what you're seeing here is our basic architecture um so we're the the green box is the service now um element of this and that's the their government commercial Cloud offering and the FED ramp and all of the bits that we inherit from them we then from the green box you slide over into the light blue box which is our now nap back Azure environment that's the authentication piece of the puzzle so we have it set up so that anyone with a cat card whether you're in a government computer or whether you're sitting at your home computer as a as a contractor can take their nap their their uh card their cat card and with that they can log into our portal into the cloud.navy dot mil portal and that will give them their uh servicenow account on the Enterprise server from there if if they're a basic user all of their permissions are automated and put on that on that account for them then get in and they can start doing the the whether it's an agile uh using the agile module or whatever they want to do within at within the uh the Enterprise instance they can they can do that if they need additional permissions or if they're going to one of our dedicated instances which is also in the green box there so we're kind of set up we are set up so that we have our Enterprise instance and then we have a number of dedicated instances and that's how we divide our customers so our Enterprise customers are the folks that only need to use the modules the servicenow modules that we offer at the Enterprise level that we're licensed at the Enterprise level for and they're willing to give up some degrees of control to our to my Enterprise team we also have our dedicated instances and that's the folks who want to do something that we don't currently offer as an Enterprise capability or that they want to maintain control of or that they're they're doing what we call a use case three which means they're connecting to outside services control mechanisms there so if you're a dedicated user or you have a dedicated instance your dedicated customer that's your instance it's under our ATO but you own all the admin underneath there you do all your customer all your user management all your user admin you have your assist admin in that dedicated instance and then you inherit that last level of controls for that capability but you're still falling underneath our ATO under the SS scca capability disa Etc so all of that it gets inherited as a dedicated instance and um that's that's there in the green box but so that's the and that's where you get your as a user that's where you get your uh rights you know where you need to go in if you need to be able to write if you need to be able to do coding etc etc you get those admin rights from your administrator whether that's us as the sorry about that uh whether that's us is the Enterprise or as a dedicated user you get that from your your team there so um and that's really the from a ten thousand foot view that is how simple our our architecture is there and that's typically the architecture we see I mean Alex and I we've we've talked to multiple customers you have users from the internet how are they getting in maybe you have a Warfighter whose spouse they need access to their service analysis how do they get through because they don't have a CAC card well there is a white listing process that exists you have to kind of go through it get approval from the dodcio and off your running but then if you're in the nippernet right you're you already are vetted yep right so there's this uh you know so we have you know um implemented or supported this zero trust there's that word again right that Ben talked about earlier right that Kool-Aid so at every level there's there's different you know sort of implementations or principles of zero trust nesting in each and every one of these boxes so it's definitely something that's there um so the question I would have is how many grain boxes do you deal with with other agencies a lot we have one green box and a whole bunch of little blue boxes everyone else has a whole bunch of green boxes so that's really I mean in a nutshell that's the difference between what we're doing what we think out of agencies and I love how you have the bottom um labeled the peod or Dex right is that what it is yeah um that's an ATO boundary this is really you know um interesting or distinct in that servicenow we have our own provisional authorization which it's a it's a Pato um that gives the assurances for agencies like Vans they're able to inherit our controls and now they're able to kind of like I wouldn't say fast track but more more so streamline their ATO Journey right so we have all the documentation a lot there's been a lot of work a lot of Blood Sweat and Tears you know poured in from our compliance team Justin Mario and uh Shamir in the back there you know kind of just looking at me making sure I'm saying things correctly but um but yeah I mean it's it's a team effort but in terms of these boundaries I like the the fact that you have your own ATO boundary to really accentuate the fact that you have leveraged servicenow's ATO and now you have that last mile of security controls such as implementing multi-factor authentication and so forth it extends back to the customer responsibility Matrix that I talked about earlier right so we're probably going to do 75 percent of the controls as a service provider but then the other remaining portion this is where Vans organization will step in in route to their their ATO the interesting thing with this though too is so there's there's cost benefits associated with this so one of the things actually getting back to like early challenges uh the nav fact if it sits on an F5 and that's what does break and inspect it does authorization or it does uh yeah authentication uh for the users that was sitting in an Azure tenant that regularly went down so now the ha that we would normally provide isn't there but it's not a servicenow problem and it wasn't a peo digital problem either it was another organization that they were leaning on to do it so that took uh that took some time and coordination and some understanding across the board to get it up to speed where now it doesn't become a regular burden on everybody um and with that you are reliant on the Authentication um tool set that that ATO service provider has so uh you know but we're even over the course of this next year we'll be looking or maybe two we'll be looking at different ways to do it because now we have uh Integrations into like their Azure active directory so now we can look at things like single sign-on and other ways to do it so um but the benefit of that is Integrations across the board so like that Azure active directory integration even though it goes into peo digital's instance well any other instance that's in that ATO boundary can now use it right uh mid servers if your point deploying enhancement it's it's a uh as long as it's on a 443 important protocol uh the only thing that needs that uh Vans issm Barbara needs is an ATO of that mid server on wherever whatever environment it's sitting on and then she can improve it so the streamlining of a lot of these things is store like if we um if a customer needs to use a store item that's not serve if it's servicenow provided it's it's a use case one approval and then if it's in the FED store if it's in the FED store right yeah and then if it's a third party as long as it's a as long as it's a U.S made bed store item it goes through the use case 2 process I think and goes through the Nao for final approval but we're talking weeks of weeks of time to Value Vice everybody having to do it and once it's approved now everybody can use it so you get economies of scale across the board that way too right so we I know we are coming up on time we've got seven minutes left so maybe we could take one before we go there sorry honest like get on my soapbox okay go ahead go go for it because I think what we did is really good I like the idea that so you're bragging right now and I I say weed but but I'm I'm riding on the shoulders of many other folks I'm not I'm not a smart guy and you can't make me so [Laughter] but what what we've done is the Navy not me but the Navy the naval Enterprise Navy Marine Corps we've created a model that as we've talked about here today avoids a lot of cost for a lot of people cost in time costing money cost in Manpower cost and Miss opportunities so as we and one thing we didn't talk about here it's on the slide we're an il-4 and il-2 right capability we're on the cusp of il-5 and il-6 implementation across the dod I imagine there's some other DOD agencies out here today anybody anybody from other DOD agencies out here what have we applied this model instead of just across the naval Enterprise and started looking at it as a DOD right thing and we sat down with the Air Force and we sat down with the Army and we started saying hey if we developed this this ATO let's have reciprocity let's do this at not as an Enterprise Naval Enterprise but as a DOD Enterprise so that we don't all have to do this and we don't all have to go through the pain of getting to an ATO and the we talked about this was kind of a light bulb it was like I knew it but it didn't really ring for me you guys have all heard that you know the the idea of the data Lake well this ATO allows us to have a unified data Lake that allows us to to delve into the data that we're creating as we populate all of our servicenow applications and if we can do that at the at the naval level why can't we do that at a DOD level and and what kind of value can we drive from that if we turn Ai and machine learning onto that data Lake there's I don't know I just think that there's a huge untapped potential here that not only in just doing the ATO piece but what are the follow-on what are the knock-on advantages that we get from thinking outside the box from starting to to not just be these stovepipe organizations that do everything on our own I know I may be this kind of crazy talk I know but uh you know what is the realm of the possibility here what can we do right right so we got four minutes left so is there one question oh she wrote she raised her hand first all right all right you got the floor what's your question so I'm going to use like our we've just upgraded we've our Serv our San Diego upgrade we'll go live I think uh tomorrow um Tokyo Tokyo I'm sorry yeah we already did San Diego all right well the thing is the thing is the advantages that we're doing here we had Tokyo scheduled for October on our timeline and we will have it implemented I believe it fully implemented tomorrow um which is again two days ahead of schedule because we had uh said we were going to do it by the by Wednesday of this week so we're we're ahead of schedule ahead of schedule which is a great thing but for for our Tokyo upgrade what we do is we put out a schedule to all of our customers whether you're an Enterprise customer or whether you're a dedicated customer we say okay this is the day we go to code freeze so have everything backed up by then give us for our dedicated customers give us your timeline to implement the changes we give them a gold disc that has all of the ATO upgrades all the changes that we need to do for our controls that's given to them all they have to do is implement it and tell us that it's done does that answer your question yeah so the the gold disc that van talks about is really just a separate dedicated uh Dev instance of service now so we set that up for them um and that is solely dedicated to the security controls that they have to push so all that so that's where they drive all of it out of is to every other instance they push it into Dev and then those customers run it through their stack yep yeah okay well thank you guys I really appreciate it I enjoyed this session yeah uh thanks everyone for your attention uh Happy drinking and uh thanks for joining us yeah good good
https://www.youtube.com/watch?v=61bUmSXcVGk