logo

NJP

Conversational Interfaces Academy: Use Vault for added layers of protection to Virtual Agent

Import · Jun 15, 2023 · video

today's topic is on how to use Vault for added layers of protection to the virtual agent I'm Victor Chen and with me today is guest speaker for COD selum I'll let him introduce himself thank you Victor for inviting me for this session my name is verca Salim I'm an outbound product manager in platform privacy and security session uh the team thank you all for joining the session as always we have to start by reminding you that we'll talk about the things that are on the roadmap and since we are publicly traded company There are rules about making forward-looking statements so we just want to remind you please make your purchasing decision based on the product that it exists today the agenda that we're going to cover so first of all we're going to introduce the servicenow Vault and then we'll quickly jump onto the demo with uh how volt will protect or add additional layer of protection or privacy to Virtual agent not only on the uh the application layer but also in the database layer as well and I will talk through some of the resources that we have and I will jump onto q a with that let's get it started customers are wanting to do more with servicenow and in doing so they're also trying to store more sensitive data in the cloud at the same time regulations and class security expectations are changing around the world for how data must be protective in different way by industry or Global region this means that we're at an intersection of providing Advanced capabilities for sensitive customer data while continuing to deliver on the functionality that they need from us you can see for some examples on this slide such as the customer data with customer service management and financial service operation in b2c or b2b2c applications Phi in healthcare operation pii and human resource application procurement data critical infrastructure data and security incident information and much much more in parallel there is an increasing number of security and privacy regulations like gdpr HIPAA and the others as well in the past we used to see things like encryption only applied to heavily regulated industry now we're seeing them applied to almost every industry of business units applications or geography and much more this also means that this is a great opportunity for servicenow uh because almost every customer could benefit from the solution that we are releasing within servicenow Bold And even today we're just scratching the surface with uh what we can offer so there's a huge opportunity for all of us as much as we want to meet the default needs of every customer in every situation what we are seeing is that all the customers have slightly unique implementations and configurations and I have different expectations when it comes to the security of the platform so volt allows them to apply customer specific configurations of security and privacy capabilities to meet their individual needs now let's talk about what service now world really is and what it contains it is over Marquee security enhancement Suite intended to provide additional layer of security and privacy capabilities for the now platform and it consists of five key security elements so far one platform encryption native standard based data at rest encryption with customer controlled key life cycle which allows organization to comply with industry mandates and it platform encryption does contain two uh premium products which I will cover in the next Slide the second data privacy to ensure data privacy by classifying and anonymizing specific data fields containing personally identified information the Third Secrets management to securely store and control access to credentials in servicenow like password certificate API keys and tokens and fourth co-signing to validate authenticity and integrity of the software on the mid server and the last premium product is our log expert service or we call it Las which improves the security threat monitoring with easily integration of servicenow system logs into larger Enterprise security analytics system so this comprehensive security solution has been packaged to make it easy for organization to order and consume the solution so now let's talk about the platform encryption the platform encryption addresses the key customer need of balancing how customers protect and share data in the cloud by ensuring servicenow data is encrypted at rest with only authorized users who can access it it consists of two encryption products Cloud encryption and column level encryption Enterprise or we call it clay Enterprise let's look at some of the underlying fundamentals to understand the customer value and differentiators for the platform encryption Cloud encryption works at the database level meaning all the data stored for the customer instances at this level is what we call encrypted at rest the protection this is giving similar to our older products like database encryption or full disk encryption is that if a hard drive was physically stolen from our data center and someone tried to plug that hard drive in outside of our data center the data will be encrypted and unreadable this this is great for protecting the theft of physical piece of Hardware however this doesn't give any additional encryption protection for the app itself if someone is logged in this is where the clay Enterprise coming to play it encrypts the data within the app and the customers can configure who should see the encrypted data or not if we look at my instances again we can see in the green highlighted section that certain information has encrypted in parenthesis this means that I'm logged in as a user that's been given access to this data in the in the app but other logged in users would not be able to see this information the additional benefit of clay Enterprise is that the data stored in the database is also encrypted so the customer is using this get the value of app level and the database level encryption with a single product the difference here is that the benefit is only for the specific fields that customers have applied clay Enterprise to like what you saw in my instance example it won't be all data like what we get with Cloud encryption but it does provide additional controls to restrict what information can be seen by people logging into an instance and even by our own servicenow employees I know this is a uh called layering or defense in depth approach by applying both uh the cloud encryption and Clay Enterprise uh all together customer get the benefit of uh protection for all data at rest in their database with additional app layer protection for specific extra sensitive fields and for uh for where their additionally concerned about like who from their end or over and can access that data both of these also known uh customer managed encryption keys that they can control from right inside their instances with no uh with no need to interact with anyone from servicenow so finally remember that the competitive differentiator for us is that we can provide this app layer encryption while still allowing those encrypted fields to work with app functionality so the next slide is more like the plugin guide and some of the uh the available plugins and pro product name and product plug-in name some of the auto out of the box dependent plugins that you can install while you're if you're interested in uh installing the platform encryption that has two uh the plugins one is for the cloud encryption as well as the column encryption Enterprise so after you install it uh you'll get a few uh the features uh that you can uh double check the one is the kmf uh keyme Key Management framework so that's this uh the first uh the the feature that we'll you will see the second one is uh cryptographic module where you can create different modules based on what you need and the second one uh the third feature is module access policy and after you create the module you will create some sort of uh the policies that will go together with the module that you created and and the module will have different types based on the scope and role or uh the script uh or group based as well and the last piece is the encrypted the field configuration so basically you will pick the table that you want to encrypt uh with the column name and then uh you will after you create the encrypted field configuration piece and then you will uh need to apply those to the module access policy as well as the module that you created earlier as well so with that I'll jump into the uh the the demo uh before that I'm just gonna show a feed Persona here that I created the one is the Mike Salem who's a hospital staff responsible for creating case for patient uh the second Persona that I created is John Jones uh who's a case scheduler responsible for monitoring the open cases with different statuses uh the third is the Tom Holland who is our I.T admin uh responsible for maintaining the it platform as well so I'll jump on to the the demo itself so here I integrated Three core servicenow product one is Healthcare life science tool that we recently built uh the second one is virtual agent the third one is Vault especially uh the platform encryption uh behind the scene as well so here uh this is the mic portal uh who is our uh The Specialist to create some procedure requests for existing customer called uh Gina Parker so here Mike simply can go to the virtual agent and then type I would like to create a procedure request for Gina Parker and then the virtual agent will process it and I will populate with some other options and here uh the mic will click the MRI for arm and then simply the virtual agent is already created the procedure request for Mike on behalf of Gina Parker now Mike can see the the request is already preceded and now it will pass it over to another Persona called John now I'll switch to persona here's the John's Works workspace as he is a scheduler so he needs to make sure that all the the case is already created with the statuses as well as some other detailed information as well since John is working in a space where he can get exposed to uh too many Phi data so as you can see there's a procedure the patient and a requesting practitioner and primary diagnosis as well as other detail and patient information as well at the same time you already see that uh the other column level encryption Enterprise is already embedded and applied to protect some of the Phi data here if you see take a look at some of the PHR data especially in this section you'll see with the practice is called encrypted meaning our Recon level encryption is already applied to these Phi data to add some additional layer of protection and privacy there as well the reason why you think that John can see is because who he has a right privilege access in order to precede his work as well all and I will switch to another Persona who is Tom uh to see how that data will look like from in his workspace as well so here the John can check the details as you see there's a lot of encrypted uh the the data that clay clay Enterprises already applied to and patient information here as well as you see that all the data is identified and Phi in a world protected here on the application Level as well now let's switch it over to Tom Holland so as we all know the Tom Holland is our I.T admin only uh responsible for I.T operation so he's not a doctor he's not a nurse and he has nothing to do with uh the Gina Parker's uh the procedure process so that all he cares about is just to maintaining the platform to make sure that the platform is working properly so in his case he is not supposed to to see all the Phi data so if Tom if we change the Persona and this is the table that the Tom is planning to maintain if there's any issues but Tom cannot see any single Phi data uh just like uh uh the I presented earlier and and um to John as well as the the mic uh both of them are has their nurse as well as Dr Persona so they are able to see all some of the Phi data but here in Tom Persona so the Tom may not be able to see any PHA data on the database but he still have access to the database to proceed with his maintenance work this is how clay uh applies uh to encrypts on the data not only on the application Level but also in the database level as well so now I'm going to show one more uh the area of how virtual agent can protect some of the Phi data as well now Tom jumps to the virtual agent and he starts typing I would like to check the status of the procedure request created for Gina Parker and now virtual agent can proceed it and virtual agent is already known that the Tom doesn't have a right privilege access to see those Phi data and he Auto the the virtual agent will automatically populates with I'm sorry I cannot provide you the information that you're asking because it contains a prj data and you don't have that privilege access but all he can see is some of the the procedure request which is already created with other uh non-phi data related information there as well so with that I conclude that I just covered the platform encryption that contains two premium products the cloud encryption as well as the column level encryption Enterprise to see how it protects not only in the database layer but also in the application layer for a virtual agent as well so I'm just going to switch over to my presentation and here's what is available for us to uh uh the in terms of the social media platform that we are covering as well as on the documentation if you're interested in to read more about servicenow Vault and some of our community side as well and again for the sake of time I just covered the platform encryption uh there's four more premium products like code signing Secrets management log expert Service uh uh as well so if you're interested in uh you can feel free to join our platform privacy and Academy session with covering all their topics with a little bit more in-depth uh uh with the details as well so with that I will pass it over to Victor to see if there's any question that it can address yeah hi So yeah thank you that was a lot of good information it just shows how rich Legend is really native to the now platform it respects encryption it respects the data protections that you put on there it doesn't kind of it doesn't do its own thing you don't need to in do any Integrations that just works natively on a single now platform so with that uh we'll go I uh we'll go to a question I answered already but maybe you can provide more details for a cut someone asked hey Will these slides be shared um this this deck won't be shared however all the info that for cut showed first off is recorded uh secondly all this info is available in the docs or Community is that correct that's correct yes at the same time you'll be uploading everything on the YouTube as well right great awesome um so um ekta asks in chat uh what are the other four encryptions uh that you mentioned that that we didn't yeah so I will go back to that slide one more time so that I can cover this so there are four other platform uh the servicenow uh covers within that bundle I just covered the platform encryption but there's a data privacy so we're going to be having Academy session I run data privacy in uh 20th of this month and then um if you're interested in you feel free to join to that session as well and secrets management code signing as well as log expert service so these are the four remaining items that we will cover in the next Academy session as well awesome so um Adam asks um is that I'm sorry I kind of provide Etc a message in Virtual agent assistant message um or are we having to manually check that access and respond with the message accordingly uh let me read the question properly is that okay foreign yeah it's a system message okay uh okay so I'm guessing that this message was in like CIS UI message and should be there by default that's correct yes cool awesome and then um you know Mark says thank you and says key is also of course the French word for key or CA I think sorry to mispronounce that if I did uh Clay is column level encryption that's what it stands for like we usually call it clay Enterprise that's one of the uh the main features that I just uh the showed uh CLE Enterprise we call it clay or on the column lava encryption Enterprise but that's what it does stand for got it and then Eric asks what happens if the admin impersonates someone who can see encrypted data or is that possible oh no that will not be possible uh because uh there's a whole Key Management framework so uh if that person doesn't have the rights uh uh Jack says to see that particular module as well as the policy created within uh the the any field that we uh encrypted to that person so even that person marks himself as a admin that person may not be able to see the encrypted data unless they have the right key to uh to decrypt the data there which is another concept of Key Management framework so that in order to encrypt and decrypted data uh within the instances they had to have the right to keep to to use to the encrypt gotcha cool thank you any other questions feel free to put them in the Q a um in the meantime as we get more questions I did post the community site with all the previous recordings in the chat so if you're free to take a look at that I know we've been off for a while so the one before this was was back in April before knowledge but we do plan on continuing uh the the sessions in the next two weeks where we'll go over uh how we built the virtual agent used at the knowledge conference um so yes uh you know hopefully you guys can join in the next uh two weeks or the fall not next Tuesday but the following Tuesday for that uh Adam asks what triggers the check for encryption access when you install Vault will with all conversation messages automatically be checked for proper access really I'm wondering how much configuration is needed on the virtual agent side so to be honest it's a little bit generic question but this is a really good question uh for the sake of argument I just built the very uh the simple flow on the virtual agent designer but it gets complicated and it probably requires some sort of scripting process uh uh if we need to add more encrypted layer to the conversation as well as with different personas uh plus uh depends on how many uh The Columns that we need to encrypt and how many details information there that we want virtual agent to disclose or not disclose so it really depends upon uh the the use case that we are trying to drive through the virtual agent so I cannot answer like the the level of the the process the how much will that be complicated but some process will use like the card on the virtual Asian designer to just check the thief system for example assist user table if you want to check someone uh personal information to see if we can disclose that through the virtual agent or not it could be easier to build on Virtual agent designer but if there are any other platform like pit to more like kind of like exposing Phi and pii data it might be a little bit difficult uh to to answer to see if we can quickly build on the virtual agent flow designer or we use some script as well awesome yeah in terms of um creating and showing creating the procedure request record and showing the proceeded request record I mean that's pretty straightforward right like that's so for creating a procedure record you would use I assume an action a record action yeah topic node and then for showing or displaying the procedure record you just drag and drop in a card you select What fields you want in the virtual agent designer and then let the Vault encryption take care of what the user can or cannot see yes that's correct so does platform encryption replace um ad encryption so that we have the cloud encryption capability that which is uh uh data at resolution that will cover uh pretty much bring the same solution to Edge encryption as well as database encryption as well with uh completely you know just a customer can we we call it like byok bring your own key so the customer can bring their own key to uh completely eliminate uh the service now access to any kind of data as well that they can completely control all the data exposure by using their own key thanks and then Karen asks what proactive triggers be discussed in any of these sessions yes it was actually discussed in the previous session on April 18th I could um let me try to copy this link here and put it in in the Q a there we go so yes proactive triggers was copied or was covered uh last time uh yes awesome any other questions for for Katra myself yeah a lot of the folks are typing the question so this is the academy session you can quickly scan the QR code and then any question any concern that you're having around other remaining products around volt would be covered on these incoming sessions as well and feel free to join that as well yeah awesome uh let's see yep that's covered okay yeah so for cut go ahead and take us to the last uh q a slide or actually you can leave this here since you have the QR code but yeah if there's if there are no other questions again thank you for joining I'll see you uh not next Tuesday but the following Tuesday we'll talk about um our knowledge bot and again uh you know it's great to be back after the little knowledge break and I will see you all soon thank you everyone thank you Victor bye-bye thanks for cut

View original source

https://www.youtube.com/watch?v=FSbtTf3VBfg