logo

NJP

ServiceNow Federal Tech Talk: Challenge the Digital Status Quo: One Agency's Approach to CDM

Import · Jun 16, 2023 · video

good afternoon everyone caresoft technology would like to welcome you to our servicenow federal Tech talk challenge the digital status quo one agency's approach to CDM just to tell you a little bit about caresoft we are a trusted government I.T Solutions provider supporting public sector organizations across federal state and local government agencies including education and Health Care markets at this time I'd like to hand the floor over to our first presenter of the day Scott the floor is all yours thanks Heather and welcome everybody good afternoon my name is Scott Spitzer I lead servicenow strategic business development for the civilian government over the next hour we're going to walk through a case study on this Tech talk that talks about challenging the digital status quo one and one agency's approach to CDM we'll be allowing roughly 15 minutes at the end of for questions and answers so please feel free to ask questions in the chat box if you have those or hold them and we'll we'll get to them at the end over the last six months service now has been developing a dry strategy to support the continuous Diagnostics and mitigation program with a condensed architecture we've met with the CDN program office the systems integrators that are the primes on CDM program and many of our servicenow customers as a result we're presently in discussions with multiple agencies on utilizing servicenow support for their CDM in the next 30 minutes bin Prime will show you how one agency utilized servicenow this agency by the way we're not allowed to mention the name of the agency re-image its approach to CDM in line with their overall modernization plans our Tech talk will demonstrate how servicenow's integration of Legacy systems modern workflows enabled the agency to combine several layers of the CDM process to work better and faster as I mentioned earlier walking through this architecture will be Ben Prime Ben has spent over 15 years as a cyber security analyst Senior Solutions architect in cyber regulation contributor most of Ben's Focus has been supporting the federal government and the federal government agencies in their cyber Journey architecture and transformation across the mission and the Enterprise he's been involved in cem programs since the Inception over 12 years ago then you have the floor now thank you Scott and also welcome to everybody good evening good afternoon and good morning depending on where you are um so this is going to be a little higher level and for anybody who just getting on the CDM at this point in time we'll touch on some of those high level things in the beginning um predominantly we're going to open up to the why and what we're looking at we will touch on Basics um and how that's evolved or thought about um we will get into some technical there is you know the technical capabilities volume one and two uh that actually started this journey with servicenow on what servicenow does and how it aligns to that overarching architecture and then really getting into the meat of what we're talking about is that cost savings and actually being able to operationalize CDM the way it was intended and how that stack actually looks today um from what that agency's uh vision is and then like we said we'd have q a also just as another housekeeping thing uh Safe Harbor just in case there's questions come up and um there's anything road map we are not making any promises um and things can change there's contributing factors all that good stuff so anything that's not here now or future related uh forward-looking statements obviously you know will remain at our sole discretion servicenow Soul discretion so where are we starting with right um layer B consolidation year over year when we're talking about different agencies this is going to be a variable right um when we're this one small to medium agency um that reported up they predominantly could have saved 200k 400k year over year and potentially even more so we'll get to that at the end but it's not really what they saved because you know gauging different size agencies across the federal government or state local or now with critical infrastructure having to follow all these things um a lot of these different things in these architectures right what is it that layer B costs you and we'll go over layer B so if anybody doesn't know what layer B is we can definitely cover that um the what right what is CDM and what did we do in the CDM so that agency submitted a request for service that's how funding works in the CDM program it's discretionary funds from Congress to DHS as the facilitator of those funds the Departments and agencies so it's out it's in addition to budget right so the agency we're talking about actually submitted an RFS to DHS for funding uh DHS has been reviewing these in Sprints a lot of times the tools layer if you're going to use different tools for different pieces of CDM if you're going to switch your vulnerability scanner from one vendor to another approved vendor it's it's not really scrutinized but when we're talking about a major layer in layer B um there were multiple iterations of the DHS program office working with that agency per their deployment Sprints to see making sure that everything was still in line right uh they were failing phase one and we'll get deeper into some of that when we talk about the architecture and the technical capabilities volume one but within that six to eight months that they put this out as a concept to prove it out and everything else they were able to turn some of those uh boxes in their pmap for the things like the master device record uh the foundations of what's on the network they were able to turn those to Red because of the correlation of information was now actually the way it should be and then the big thing is uh the proving interoperability anybody who's on the software side submitting to cdm's approved products list um and some of the tools that have been removed in uh previous iterations of the CDM architecture for instance the dashboard layer passed was arcsite and that was uh or Archer sorry I'm in security I get the two A's mixed up uh that didn't scale so that interoperability plus scaling were some major things when that we had to prove out so and that's really what DHS was also reviewing in the Sprints is that we can actually share data with the dashboard because this wouldn't have even been a concept if that piece had failed right so that's why I put it in green it's one of the biggest things that we proved we can go directly up to the dashboard um and when we look at this we're going to look at their starting phase which is you know um pretty much the starting phases of CDM like if I have what's on the network in my master device records how do I get it up there and then we'll be looking at their future looking state which is all of the phases what's on the network who's on the network what's happening on the network and also that way you're protecting the network um and we're going to kind of bookcase those instead of going through each Sprint so that's the major of the why right that was quick that's why I didn't put any minutes on it the basics of CDM for those uh for what we've been doing years is it is the continuous Diagnostics and mitigation program like we said it's funding out of Congress to DHS program office that then facilitates the the prime incumbents down to the Departments and agencies to supplement them on their tools and deployment of security products to fortify their cyber security on their networks um and also with those tools and Integrations and dashboards their intent is that agencies improve their actual cyber security a lot of people looking at CDM still today are still just trying to get their their reporting green there might be failing in this section or not 100 accurate and another section on the reporting but really the intent is operations the daily operation so um and actually I was just grabbing the news today we've had uh just recent releases CNN is reporting on sizza and DHS that we have new Cyber threats that are coming out against globally um that are just starting to Bubble Up in the news and we had some other cyber threats um from Microsoft just a few weeks ago on our U.S critical infrastructure and Telecommunications through Vault typhoon right so how do we produce our surface area for those attackers to actually attack us increase the the cyber security posture and prove the response capabilities and we'll get into the Enterprise version of this uh kind of like the ZTA methodology and then still be able to wrap that around the fisma reporting right we have to report and we need to know where our boundaries are [Music] so when we look at all the things we could talk about in about 30 40 minutes we can not go over all of the CDM Basics right we could touched on the funding from Congress the RFS process um we'll go deeper into the architecture that's really where we're going to focus uh but we can't get into all of the tools all of the different ties because CDM actually is a part of the zero trust architecture the executive orders bringing out new binding operational directives that then restate CDM like in the 2301 and the 2302 that just came out two days ago or so and then when we're talking about the known exploitable vulnerabilities all of this is tied together they're not meant to be siled things but I think the architecture is the is the foundation that's going to enable all of the future ties to CDM and the phases right so what do I mean by architecture the architecture of CDM is not anything new that is just the the most basic multi-tiered risk management right we have tier three the information system so what are we doing to patch those uh put the correct settings in there with different types of benchmarks or CIS or Stig or whichever you follow and how do we keep those updated when the agency is always growing or adding new things right and having that complete feedback loop so we're continuously monitoring right continuous Diagnostics and mitigation things are happening in the environment operations is always doing stuff on computers and upgrading them and doing all those things but not having that operation siled from the mission and business process so we are always having oversight at the mission business process so that way we can facilitate what needs to be done and what the next areas Focus are to complete the mission and then the organization uh visibility and even organizations that have to report to Congress and go back for what they're doing having all of this stacked up is what we can report on for both strategic and tactical risks across the Enterprises CDM continuous Diagnostics and mitigation helps facilitate and support this you know methodology that we've had for years and uh nest and documentation right so let's look at how that is in uh more fluid and a faster changing paced environment like you know we're talking the old days and you know three to five year ATO cycles and long-term coding things right nowadays digital transformation is going everywhere if we cross the Enterprise across the mission everybody's trying to do things better and faster with what they have and what tools and that's one of the first things in ZTA tied to CDM is how much are you utilizing the things you have and what can you get out of better experiences and that may be for internal employees it may be for Citizens and how they use services on behalf of the federal government or state and local and you know are things always available right or there when we need them and then also what are we driving for uh developing or transitioning to people are looking at brand new tools that are coming out part of CDM is that new tools and new capabilities are always to be reassessed if they're better in the next iterations of CDM or your cyber security program always be looking at new tools don't get in a in a you know a stagnant state and don't be obsolete right because the attackers are going to start using the new tools uh so don't be obsolete but that puts a lot of pressure on the security office right more and more stuff coming onto the network new and newer stuff is coming onto the network and that's bigger surface area for and more things to Monitor and watch that you might not be aware of giving rise to attackers being able to get in and then end up in the news like I mentioned the whole CNN uh messaging today and other news articles or messaging it like you don't want to be there right um but then how do we deal with this like if the CIO is doing things and all the different teams are doing things in disconnected silos how are we going to fix that we've broken pipelines and we're or we're trying to get things done quickly you know like when covet hit we the lots of things had to get built for um you know if anybody was in close contact or who needs to take time off like if you're going to develop an application and deploy that really quickly in a crisis like covid are you going to skip some of the ATL processes or you know get interims and things like that are you going to have you know less governed I would say this is a little more commercialized completely ungovered we're governed in the federal and state local but again increasing perimeter vulnerabilities and threats more and more to manage not less and less so servicenow the reason one of these foundations and why we're coming into CDM is CDM still has these types of methodologies like how do we do this in our organizations right so a lot of this customer was actually coming back to the customer they're actually doing a lot of these things on the platform they're actually using different parts of service now to transform their operations so their services their ticketing systems which understanding where the assets are and how critical they are to the business uh scaling in the cloud uh things like that and then trying to do you know quicker sprints on custom applications or other things like that but security is going to be across the whole Enterprise so having it in one platform they're already trying to build design deploy uh and secure across their Enterprise on servicenow so all of that's there from the assets to the development right but when we come down to it security and risk having that all on one platform that overlay it's meeting the mission in the intent of CDM to actually do proactive risk and secure processor visibility we're trying to get us care posture we're trying to respond to threats and vulnerabilities and is close to near real time we don't want weeks or months because we have you know email and spreadsheet patch policies or things like that um and that's really what started driving this we have all of this stuff and it's really meant to meet the intent of CDM and this is where the data is living in this organization why can't we just pass that out right so that's the big CDM basics of where we think the cdm's overall vision is is to not only report but to operationalize right now we get into slightly technical uh what makes it different why would servicenow think they're a different solution or this customer think it's a different solution for layer B on its foundation well really the foundation of layer B there's two different types of databases right we have non-relational databases and we have relational databases servicenow is a relational database and currently layer B is a non-relational database uh across the boards non-relational was really brought up because we were expecting a lot of data all the Departments and agencies were going to put a lot of data in this layer B data aggregation layer they were going to pass it up but and they were able to put it in really quickly and you know get that uh unstructured data in there get started but really what we see is that these databases are great for certain things you can throw a whole bunch of data in there and then like around the walls you can organize certain pieces that you want to do but as we adapt into the late some of the latest uh iterations of CDM now we're adding more index type data we're going to start doing mobile and OT that are going to have to be reported as device records so now you've got to go back to that data schema and update that data schema for that new for those new data types right whereas servicenow is starts out as a structured database for data Integrity everything that comes into servicenow the first thing we do is say hey we're getting more data about an asset I want to map it to that authoritative asset and everything is indexed Right plus we kind of overlap the CDM to ZTA Journey because of transactional security and some of those new things coming out in the executive orders and really what we think that looks like is the same way that you would see libraries is there's an intent to have no matter which Library you go into you can go to the card catalog and you can find a book on the shelf and it doesn't matter what the neighboring Library looks like you can do that right whereas you're trying to find a hammer in your garage versus trying to find a hammer or a tool in your buddy's garage they might be stored in completely different places and it might be completely confusing and all that bringing that data in from the time it comes in having it organized having it where it needs to be that it can always go back and forth it can be checked out be logged all those things that's really where we started to see um that value in using a relational database from the concepts of CDM so for those concepts of CDM what do I mean by relational well CDM technical capabilities volume one has a lot of these different diagrams of how things are supposed to link together depending on which lens you're supposed to be seeing it as this customer that did this one of the things was is they were just trying to get master device records up to the dashboard and hardware and software asset management was in one tool and then vulnerabilities and configuration security were coming from two other tools and they were sticking that data up in the stack to report on it but they weren't always meeting up they might be slightly skewed like here's some vulnerabilities and I'm not really quite sure which asset they're on or here's some assets and I'm not quite sure what vulnerabilities they have right but with servicenow when those things come in we map them to the assets and we list out the ones that don't map so you can Rectify those and going forward keep that map so now you have this holistic approach of what the intent of Master device record is um same thing with Master users everything in servicenow people places and things are all configuration items or cmdb we want those relationships so customers getting their people in and having that inventory we've also been a soar since we've been building a security uh scary and vulnerability product since 2015 and gardeners put us into the soar documentation so we're in that same principle of the customer using us to manage events but even if you're not a lot of times customers or or uh different departments and agencies I say customers because we're coming from service now but a lot of different departments and agencies might have this type of methodology yes they're trying to meet CDM but in their operations in their organizations the sock might be siled from HR and that's where those things are so and you know binding operational director of 2302 which just came out like how do we make sure that bound and master security records there we don't have any Master devices that are being managed externally you might have some of these relationships because some of these tools talk to each other or some of these organizations are a little more tightly coupled where others are disparate but now you've got to tie all that to a completely separate GRC irm fisma boundary tools right whereas servicenow we're natively sitting over that so uh these organizations are already doing their security their devices their firewalls they've already have our Nest 837 accelerator they've got this whole concept and now inside the platform of service now they just have to build out how their organizational is structured what fisma boundaries do the finance department own and which fisma boundaries so that way we have multiple fisma boundaries users assets everything under those and then being able to continuously develop right design build secure always thinking of security and shifting left and operate Monitor and improve how do we watch people processes and things and improve them to keep up with the threats and the actors that are always going to be doing the same thing um and then just having that holistic picture that's probably the main reason why when I build up this architecture diagram what I think when we talk to customers where or you know in agencies and departments where they're feeling a struggle of trying to operationalize this is those siled gaps the lines when you look at technical capabilities volume one are very very thin you're focusing on do I have something that meets the master device technical capabilities volume two requirements do I have something that meets the fisma boundaries technical capabilities volume but in servicenow foundationally everything's relational the relational database is meant to do this structure and make sure the lines connect so we're we weren't there to solve their problem of being a vulnerability scanner we don't do that where we're not a Sim or you know an antivirus tool for security but we are that connection that bubbles it up across the Enterprise and that's really where they saw us being in their environment so why don't I just take that what I'm doing in operations and an environment and send that directly up that'll be the most current stuff the most uh tied together data to the CDM dashboard and that's you know foundationally what kind of drove this proof of concept so what do I mean by that having that executive visibility that executive visibility to figure out where you're not patched um the threats coming out now for you know industrial controls and other things they're they're attacking vulnerabilities they're attacking you know flaws uh and it could be compliance that we you know you're not following up on what you said you were going to do um against the regulatory guidance right but having that in one pane of glass um and the most current near real time right as soon as the dashboard refreshes that's the most current state of all the information the next one is directing the battlefield so when these things do happen we are talking about CDM continuous Diagnostics and mitigation being predominantly security but Security in a silo when these new news articles are going to hit about certain XYZ being breached it's not pardon me it's not the Cyber sock team that's going to the news outlets or the newspapers and doing the interviews we're getting people like public relations and legal and all these different other people involved in this when it escalates right so how do we see what's going on across the Enterprise uh from the governance people to HR if that's applicable to the security to I.T and the networking team and what parts are they working on so how do we get this holistic pane of glass when this happens and get everybody together in a war room uh with just a few clicks right not having to stand up all these things and you know do all the processes how do we automate that because that's going to be the point in time when you really need to operationalize the intent of CDM is when something goes bad goes wrong right and then also your due diligence on trying to meet the the maturity and the complexity of the executive orders tied to CDM and and your majority of CDM um how do you report on these things and get visual across the Enterprise on these things so just one example there's many examples for you know operational dashboards and where people are working and doing their daily but things like The Binding operational director of 2201 and the known exploitable vulnerabilities that's going to be the egress for the bad guys right um so how do we know across our teams if our application owners or our Linux servers uh have more vulnerabilities and then how do we fix that do we need more people do we need more resources like what do we need to do there uh and being able to you know not just report on it but get better you have to know where the root of the the bigger things lie so you can turn them over so really what we're coming down to is that whole big picture right just to recap a lot of what we went over in this one it's really about the entire Enterprise in one logical place where the relationships and the structures between sprawling Cloud assets developing new applications and devsecops the security and risk around those uh complete visibility into your it asset inventory including mobile medical devices things like that it's just going to keep expanding how do you service those things and then you know who's who's doing everything in the environment that's really what um we see as the foundation to actually utilizing and complying with CDM so we got through the second part I might have been a little bit longer than 15 minutes but now how did we do the stack right so um and feel free to drop questions in the chat and recoup monitoring but uh let's see where it was good so is that I am starting with the older version I know there's newer versions out there and this is the old version and it's no longer the summary level versus the object level but I'm just using it as a base it'll it'll more will do it and it's really that we are focusing on layer B so anybody who is saying layer a layer B reports on the dashboard layer B is bringing up all your tools and sensors so your vulnerability scanners your antivirus scanners your Hardware software inventory tools all those things rolling them up into a middle data aggregation layer that can normalize so like we said servicenow have The Different Twist on this now it used to be that um we had archery in here and there was a lot of policy management and orchestration so as we look at where those ended up right they kind of disappeared from the newer uh versions of disarchitecture because we switched over to elastic right elastic is you know the dashboard now and this summary type later um so they're not really governance risk and compliance tools so they're not really fisma boundary tools so we can't really push down policies against fisma boundaries because those go against pits 199 and the last thing isn't really I don't think Splunk or elastic quote themselves as you know a risk in policy compliance leader right so those kind of disappeared slightly from the the overarching document they're still in the intent of CDM like we looked at we looked at nist uh the pyramid 839 right they're still in the intent like the Strategic first hospital risk all of that has to be up and down the stack um but that's what the customer said is if I have all of this data here in servicenow and I've got it all mapped I've got my assets with the software and vulnerabilities mapped to my fisma boundaries and what security and who owns them and what location they're in and what the GSS tick out there behind and who's responsible for that I have all that on service now and then I push it up into the normal stack like a normal tools layer and I'm not complying so what is it that layer B is doing what is it that you do here layer B that's really the question that was asked to start this and they envisioned them as themselves to go to get the RFS so what we ended up coming up with is when they started that they started predominantly this is their end goal get all of it we started with phase one so with this isn't an option if you are an agency and you roll up the Departments servicenow can talk to service now right we can replicate whatever data you want from whatever's on the platform and pass it up and sync them together so they're they're in sync me a real time uh this agency happened to do it and the reason it's a dash line is it's optional this agency just happened to report directly themselves so they went straight up but they started with what what's on the network they had their Hardware asset inventory from servicenow and their configuration items and the cmdb they were bringing in their vulnerability scanner and their and their benchmarks they were already mapped to the assets so the first phase was just proving out interoperability how do we get this data how do we map it to the CDM structure and how do we get it up there they did start looking at uh and pushing up some of the phase 2 Data because they actually were accelerated in this journey and proved this out pretty quickly they started passing up some phase two data but overall uh and they did leave the original elastic layer B in place just so they could see if there were any deviations in the data or missing data and still push up phase three but overall the intent is to bring this data all of it up now the other piece that can possibly happen right uh and that's done with the uh Integrations and you know where just an open platform so no matter what you want to do this is what makes it possible to do interoperability with ease but we're a GRC we're Gardener magic quadrant for integrated risk management and a lot of Foresters wave and all these other ones were full-blown integrated risk management this RMF type application this is possible now if we were pushed down regulatory Authority documents with all of the different statements and citations we could map those to the current compliance of those controls as long as they're not interview and examine some of those you still have to do but we could have people you know timeline to go out once a week and do the interviews if you want um but a lot of those are technical controls like the Kev you know vulnerabilities so hey I'm going to pass down new vulnerabilities and I'm going to say you have to get to these in seven days not 14. well you could push that down and then we could look at the data and automatically send that right back up yeah these ones aren't done in 14 days I mean probably I'm on them we could actually bring these policies and management directly back into I've been an apartment and agency data connected to the tools servicenow is a soar we do well we're orchestration and automation for it and we're also orchestration and automation for HR like onboarding or orchestration and automation for security operations so we are a soar so there's a lot of push down to the tools layers where we could orchestrate an automate uh the remediation of those things and that's the whole intent is bringing down mean time to remediate right and this is future again this is why I said like agencies and and not necessarily a product feature future future agency maturity future the same way that we built out cin Yemen it was deployed past in the future now the next two slides are something that's coming up right there's a new uh RFI from the CDM program office and it revolves around an extra layer of the dashboard right now all the Departments and agencies have a slightly different connector and mapping uh kind of like Secret Sauce in between um DHS wants to be able to have the closest Neo real-time data and a common structure between the department dashboards and the federal dashboards so there's this RFI for uh having it as a man in service so that way pretty pretty much a copy of the federal dashboard into the agencies so how that would essentially look is and and this is an opt-in or opt out if you read the new CDM RFI in the bottom there is if agencies don't want to do this they can opt in or opt out but if you opted in it would be a clone of the federal dashboard and then you have a department level dashboard with all of the calculations and the calculators and all that other good stuff right but that's the same principle we have that open API we can we can integrate with elastic out of box we have we have Integrations in the store to integrate with elastic so you could have that opt-in and still be using the operational data in service now to do all of these things and still have that architecture if you opt out then this is what we're looking at for the intent of that agency to uh completely do so just you know service now in the stack and you're using the servicenow dashboards and you put the calculations into your instance and you have dashboards that align with the calculations in the dashboard and they're putting on the CDM dashboard and they're pretty much a clone so with all that being said I know I said a lot and um a lot of time I don't see any uh yeah Ben there was a couple questions there was there was one question that asked you we could give a copy of these slides out and the answer to that is yes I think they'll come out through Carousel isn't that right Heather yep we'll send out a follow-up email to all registrants and attendees that'll have the recording and slide deck included um there is one and there's a comment which is a great comment we've mostly been using servicenow as a layer a tools layer tool yes completely that's what we explained to the program office when we were talking about this concept is that a lot of people who use servicenow we were down here at the tools layer and that was good tools layer for master device record and things like that and but it was getting corrupted here so yes if you're seeing that same principle it's a great tools layer if you still want to use it as a tools layer push it up and that it'll just be a tools layer it wouldn't be a replacement for AMD that's always an option um for a lot of people but yes I agree that's that's the majority of people are using servicenow as a major tools layer and we are on the APL ledge so we can definitely new um uh talks in the future also so yeah I would I don't know if carosoft has a mailing list or anything like that um or getting plugged into these types of events in the future or being reminded um and then the bigger thing so which career Journeys would be suitable for CDM business process analysts actually it takes a town and a team um it's actually a major program right it's an Enterprise cyber security program so you do need budget resources tools program office um Gantt charts and mapping out progress and goals and Sprints and things like that so yeah there's business processes and cost-based Analysis people would be totally over this but then you also need the technical people you're still going to need to uh validate the tools in your environment or doing what they should be in the best tools to actually contain eradicate and mitigate the ongoing threats coming at you so um you're going to need sharp and tools aren't going to save everything people smart people in our cyber branches and divisions battling against these threats are also needed there so it's the cyber security people the cyber security tools the um the proper deployment and configuration of those tools so either um trained Workforce trained government contractors or uh knowledgeable and certified Federal systems integrators across whatever tools you're using um so it's yeah it's an Enterprise thing so you could you could pick any of those Avenues on where you would study up and uh Target where you'd support it in ongoing efforts um what is the highest level of this capability has been used thus far secret TS SEI so for CDM the only requirement of the current requirement is fedramp high so a lot of tools are not fed ramp high and uh departments and agencies would choose on-prem versions of those servicenow does have a Fed Ray up high ATL hosted environments with high failover in the US with supporting um continental U.S support people so we do that we also have il-4 and il-5 so these Concepts still exist in the dod in the dod they might not get CDM funds and they might not call it continuous Diagnostics and mitigation but this isn't like brand new concept we need to know what's on the network and who's on the network before we protect the network they're still going to be the same three major vulnerability scanners that you'll find in the civilian government or in the dod giving that data and mapping that data to master devices so we have DOD people and secret TS people using this we have uh air gap Network secret compartmental information Beyond il-4 il5 you can put servicenow on-prem and still make this this concept um in that in the dods OR Intel so you can use it in state local you can use it uh this concept or wherever you want to you just wouldn't have to report up to the federal dashboard you're looking more at you know um not uh not Einstein not stick out but um EMASS same methodology of EMASS like sending all of your assets with all your vulnerabilities and findings against your poems and your fisma boundaries up to EMASS that's kind of the same concept right um and we've seen people customers use it for that all the time hey Ben I'd like for you to comment this is an earlier uh from Robert one of the benefits of snow or servicenow integration with tool layer Asset Management tool layer a was servicenow has relationships with many third-party Asset Management vendors they collaborate with third-party vendors on creating integration modules that facilitate API integration titanium integration with servicenow works like a charm with available modules yeah that's a so that's a really good point um one of the foundation things in in doing this is you already have a lot of tools in your environment a lot of people in the original going way back a lot of different departments and agencies either were given a tool it was like some groups were like Hey Big Fix is going to be your hardware and software asset inventory tool or this other group in forescout is your hardware and software inventory tool um but then as things evolved like we're supposed to be looking at newer better products that do different things or maybe more applicable in certain environments servicenow is able to take those tools so we don't and we don't have to just use one tool bringing in something like tanium that's across the Enterprise already and you know as an agent on the systems monitoring their vulnerabilities monitoring them for who they are and keeping a consistent update of the assets on the network that can easily come into servicenow and add to the Big Fix or the forescout or the tenables or the qualices that are all finding Tools in your network so now instead of just picking a silo tool you can bring these tools in really quickly because they're already deployed in every nook and cranny of your network we just that was one thing that this customer did was they just integrated with titanium and it populated their horizontal cmdb quickly without having to go put new sensors to get different data out there it was really quick with our service graph connectors that's what gave them um a quick time to Value to get the complete Hardware software inventory and then tying the vulnerabilities from the vulnerability scanner directly to that right it was quick that's why it only took six to eight months to get this whole level of Architecture is using things that you already have in your network as that quicker time to value and like titanium is one of the ones where we have six or seven Integrations because of different places that are found in the environment the same way servicenow has different lenses for the different teams like security teams goes to the security part inventory teams going to see the inventory part and titanium and the other products uh we rely on to get us servicenow as a layer B that data from those tools and sunscripts so that's a that was a big one good point of I think that's all the questions that were out there right now do you have one or two more slides or yeah I do I have the um I have the wonderful so we we kind of left it with question marks in the top 200 400k so um and we did not do a full business case analysis but understanding in the ballpark of where that customer is um very educated guess so in that beginning what they really wanted to do was remove architecture complexity so we condensed those layers big time and stuff they're already using they were gaining a technical cost advantage and efficiency by reducing that complexity in the middle layer always trying to fight on the data not being correct going up to the dashboard was a lot of overhead and having to go correct it now it's operationalized correctly inside servicenow and going straight up correct so and de-duplicating Technologies right geez what are you doing here from that original one and uh that customer or that agency really sees this as an improved long-term sustainable option right so it wasn't 200k per year it wasn't 400k that small to medium agency is roughly 800k per year right so that's a huge savings and really going back to what does it cost your department and or agency some of them are Enterprise departments and they're supporting the agencies also what is your cost if you were to use what you have invested in servicenow now and not and be able to send that directly up and not have to use the elastic cmass layer as it is and then lastly the one thing I would do want to say is we do also have if you want to reach out there is a direct CDM at servicenow.com like we made it really really simple to reach out if nobody if you don't know which other way to do it but I would say those are the main things I think I hit everything did you have any thoughts Scott well we have a few more minutes if there was any more questions if not we can give some time back um I I think you covered what we wanted to get covered here today Ben yeah always playing for those extra questions right well they know how to get in touch with us CDMA servicenow.com perfect so Heather I think we're good I don't see any more questions so alrighty I'd like to go ahead and thank all of our participants as well as our speakers for being with us today we hope the information you've received during this webinar has been helpful

View original source

https://www.youtube.com/watch?v=eH7N7IdeURw