logo

NJP

Streamline Your Operational Technology assets

Import · Jul 18, 2023 · video

[Music] hello this is payal chakraborty from the product marketing team at servicenow the manufacturing sector is one of the most vulnerable to security breaches in operational technology as the number of endpoints and monitoring tool grows so does the volume of threats and vulnerabilities making prioritizing appropriate actions more challenging than ever but this challenge kept in mind let's see how servicenow service craft connective attainable helps various Industries with a vast expanse of OT assets to gain a secure handle on their remediation of critical vulnerabilities Robert is the head of security across all Sites accountable for ensuring all assets are protected from external and internal security risks trolls the security analyst and a control systems engineer responsible for setting organizational policies for remediating the Target date Troy has successfully set up the servicenow operational technology service craft connector for tenable and has many scheduled jobs one for vulnerability response assets and the plug-in import for VR Troy wants to take a look at all the data that comes in he groups assets to see what's coming in from the discovery sources the servicenow integration is bringing in these assets and now let's see how Troy finds the political abilities Associated let's go to the vulnerable items this false vulnerabilities into vulnerable response from the tenable OT products and the specific assets are mapped there is a custom map for any field that terrible has to map where there is no direct correlation Troy can add custom tenable acid attributes to these records and by doing this he's adding secure information directly added to this field Robert in Troy receive a notification of a critical parability Robert starts his day by viewing the vulnerabilities overview dashboard where he can view the Enterprise security posture of all the assets Robert can quickly understand how many vulnerabilities are there overall how many of them are critical and not assigned additionally he can view valuable items by risk ratings remediation State configuration items and risk score across the sites he can also filter the items Robert can access the vulnerable items list View for a deeper analysis which lists down each vulnerable items with availability and risk score calculated by launching the interactive enan properties that these are sites with different vulnerabilities that can be grouped to understand that Atlanta and London have critical vulnerabilities Robert wants to see the site's progress by changing the state risk Group by Dimension to understand that these are critical vulnerabilities in a different state but this one here is open Robert and Troy are notified via email whenever a new or critical exposure occurs let's see how Troy remedies this critical vulnerability by accessing the operational technology workspace he is presented with a list view to focus on Atlanta which has nine critical vulnerabilities the role of scope can be viewed here by different equipment modeling to be listed under the site the risk score indicates the manufacturing area he sees that assembly line 2 has the highest risk score and he further drills down to view the vulnerabilities reported he quickly accesses the vulnerable items Troy prioritizes this open critical vulnerability and notes that there are others awaiting implementation he starts an investigation onto this once the research is done and the necessary remediation is identified he changes the state of the workflow to awaiting implementation Troy creates a vulnerability remediation task by selecting the ones that are awaiting implementation he groups all the vulnerabilities reported on the assembly line too to develop one remediation task takes help of the scheduling assistant to choose the available slot for remediation he saves the task on the schedule downtime he resolves the job by assigning the is to himself this vulnerability risk is resolved now Troy can mark this close after testing that assembly line 2 is working fine and makes the necessary changes Robert and Troy have just seen how everything works together the key insights from here are tenable will find the assets by discover and asses once we've done that all of the information that tenable has synchronized goes into servicenow to leverage all of the information in the cmdb which could be any Source or custom rules to prioritize once prioritized it will coordinate to get the right information to the right team or the person to fix it once it's at the right team they will go ahead and remedy through their workflow test it and then deploy it you can validate the vulnerability response Integrations with the remediation scan that is targeted rapid lightweight and allows to check for vulnerabilities once the integration is set up for VR the security team and the ID team have access to this exact same information and can use it for prioritization and SLS this powerful integration obtainable OT with servicenow is a full featured risk-based prioritization and features scoring grouping coordinated remediation workflow and communication between servicenow and tenable this is just one example how companies can accelerate value and Innovation with servicenow the platform for digital business we make the Work World better with prepackaged and configurable solutions for customers employees and your entire ecosystem all built on a common Cloud platform to learn more visit servicenow.com

View original source

https://www.youtube.com/watch?v=Eqcd4yjFHSo