logo

NJP

What you need to know secure your instances

Import · Aug 16, 2023 · video

[Music] thank you all for coming to today's session uh we really appreciate all of you as customers so my name is Aaron Warner and with me is my colleague Rasheed harando so we're from service now's Office of the CSO team so we are a global team I'm from Washington State and Rasheed is from France so just to let you know that our team is available to you we really want to partner with you in your security Journey with servicenow so we have our Safe Harbor notice this is the don't make purchasing decisions based upon forward-looking statements slide but here's really what we want you all to walk away from from this particular presentation so you know more about well how do you secure your servicenow instances you understand where you are at in your security Journey with servicenow and then also you know where to go when you have questions so you have those resources that are available to you the first we want to make sure that we all are speaking the same language so when I say servicenow instance we all know exactly what that means so when you log in into your servicenow production environment over the Internet over TLS 1.2 you're logging into multiple application nodes and a database those application nodes that database it is specific to that production environment that you're logging into so say if you have a test and or a development environment each one of those environments they have their own application nodes and database as well in fact that's what we call an instance those instances are stored on physical Hardware inside a cage those cages are stored in a co-location Data Center and not only does that co-location Data Center provide environmental controls and redundant power it also provides the physical security for that co-location data center those data centers are paired for high availability and they're stored throughout the world now one of the best things about this is that when you own multiple applications from servicenow such as iton SEC Ops itsm and so forth it all resides within your instance so it's one platform with one data model with consistent controls oh we've developed this presentation into a crawl walk run type of approach because we understand that each customer is on their own path with their servicenow security Journey and what with that I'm going to pass it over to my colleague Rasheed who's going to talk about the crawl step in the security Journey hi thank you Aaron um and as Aaron just presented the instant security is an important responsibility that requires a careful attention so we know that Securities is not a one size fit all and one key factor in maintaining a secure instance is having access to Reliable and up-to-date information and that's why we have put in place resources at your disposal depending on where you are in your journey are you looking to evaluate service now are you becoming a customers um are you a partner and we have put at your disposal repositories here some of them require you to be authenticated which is uh we'll have to to you know sign an NDA we see the uh through the trust Center you see here in the middle once you are a customer you will have access to the trust Center and you will have to gain an additional access to get access to what we call the core portal where additional information on how we do um security uh internally at service now including our third party certification and audit reports so we committed for total transparency at service now that's why we put at your disposal like I said before a full repository of documentation regarding service now internal standard operating procedure um our like I said the third party audit reports um totally available for our customers our data center certification everyone presented how we work in terms of collocation we also make available for you was a third party certification and we understand that we have many questions about how we do security at service now that's why we have compiled more than 1 600 lists of questions and answers already filled up by our team at your disposal so and if you have to take back one slide out of this presentation that we will be the one this is the central repository and location to help you um navigate how to secure how what other service now best practices in terms of security what which species the central location for you where we're gonna gather and it is important to mention regularly and as you know security is evolving every day and we put a big effort to maintain this up to date for you and not only at the beginning of your implementation but at every we will recommend you to look at this best practice guide which include also hardening recommendation regularly this is very important as a security professional this is the best recommendation I will put here is to regularly review um your security settings so that's the location of a care of the best practices you will get linked and yes service now is a software uh as a service so like any software we need you to keep up with the patch and upgrade and um there is a monthly um security path program we want you to look at and make sure you don't skip um security patches so we will recommend you to follow our passing program and make sure you um uh instance is uh with the latest patch release in terms of security and allow me to uh take the opportunity here to remind you to make sure to update the security contacts in the now support portal this is a contact uh we will reach out if any suspicious activity is going on against your instance so it's important that you have people or organization or group or teams that can be contacted 24 7. yes we recommend you to put at least two uh contacts of course a million is recommended here so just reminding here uh two people to make sure you have the right Security contact here and please not do not put the same contact as the admin but really to put the contact of your security team that will be contacted if any uh suspicious or security breach or issue is happening against your instance I think it's up to you I don't know all right thanks Rasheed so in the crawl stab of the security Journey you now you're patching you're upgrading you're familiar with the resources that are available to you so we're going to build on that step by going a little deeper as we start walking down the security Journey path do you understand well who's responsible for what and then I'll also highlight some of the newer options that are available to you as well so the first item that we have here is the shared security responsibility model this chart was actually screen captured out of a PDF and we'll provide you a link to that PDF as well but that PDF will allow you to go into each one of these areas of responsibility to drill in deeper and get a more understanding of what those details are but what I want you to walk away from from this particular slide is that we have a partnership in keeping your instance secure we can see that partnership with all these dots and we can also see that not only does servicenow partner with you as the customer but we also partner with the co-location data center provider for these two areas we can also see where servicenow also partners with the customer in these particular areas then you as the customer have certain areas of responsibility and then also servicenow does as well and the reason why we're doing this is we want to help reduce common security risks we also want to understand roles in meeting compliance to Industry standards such as ISO 27001 legal regulations such as gdpr and then also privacy concerns also one of the best things about this is that good security hygiene also helps with keeping your instance available the incident security Center this was the Gen 1 version so generation one we now have a newer version so Gen 2 it's been built from the ground up to be more intuitive easier to use Vancouver and the releases after that it's going to come with the instance it's really comprised of these four areas so hardening the scanner metrics and learning so for Harding this is where the has platform security settings also gives you a score it allows you as a customer customer to make risk-based decision based upon that particular setting so for example there's an snc access control plugin that plug-in will block servicenow support Personnel from accessing your instance Without You authorizing them so there's a trade-off there right so see if um see if you have a problem you have the snc access control plug-in enabled but you know you're kind of not very timely in adding in the the email address of the support Personnel that's going to help you out there's obviously going to be some some delay there right so you have to make that decision on if you want to enable that or not so in the scanner piece the scanner is looking for a common application configuration items it also allows you to customize those checks as well so say you could be looking for certain ACL configurations so for metrics this is a monitor monitor for suspicious activities and then also it allows you to run reports so reports like hey show me some stale users I want to know what users haven't logged in in x amount of time 30 days 60 days whatever you want right and then learning this is links out to other security resources it's really a One-Stop shop for instance security it's included so it's no additional cost yeah when we transition over we start looking at logging and monitoring so this is a detective type of control when we looked at that that Matrix earlier on this is one of those areas where surfsnap partners with you as the customer so the customer you have access to the logs that are within your instance so you can look for suspicious activities you can also export those logs out to a log aggregator or a Sim so you can do that using the API you can also use the syslog probe via the mid server or you could use Kafka as well now on the servicenow managed side this is where servicenow we're going to gather all the infrastructure logs so logs such as firewall logs IDs logs file Integrity monitoring logs operating system logs we're going to store that into our own log aggregator Sim and we have a team that's dedicated to doing this we have a sock team here at servicenow that's looking for those suspicious activities at that infrastructure layer and we start looking at customer managed access controls this is probably where most of us customers are going to be the most familiar with these type of controls but it's really a segue to the next slide which is the one I really want to talk about so identification and Authentication well this is well how do your users log into your instance do they use single sign-on do they use an identity provider such as an IDP or say ldap do they use local database authentication do you enable multi-factor on authentication on any of those right so once your users log in goes to the authorization site well what do they have access to this is where we can talk about role-based access controls ACLs the piece that I really wanted to talk about is this adaptive authentication piece and the reason why I want to talk about this so much is because it helps to limit the attack surface to your instance and it's a newer piece of functionality as well so it does this by using both pre and post authentication policies so for example you could put a IP restriction in place that says hey only my corporate Network can access my instance well see if you have mobile mobile users so they're out in the field their IPs are changing all the time now they're being blocked right so with Utah we've added a new piece of functionality so whereas mobile device users can register those mobile device authorize those device devices as a known good so now they can use the mobile app on that mobile device since that device is authorized it's going to bypass those IP restriction policies so adaptive off authentication can help with multiple scenarios so if you have a scenario you think adaptive off can help you out with please contact your partner your account team if your partner account team can't uh answer those questions they'll reach out to our team and we'll help you out so email is one of the most common ways for attackers to compromise systems so we want to try to reduce the attack surface here as well so use the customer you have a couple options for your email infrastructure so you can use your own Corporate email infrastructure and all the security goodness that you've already built into that or you can use the servicenow email infrastructure and this slide is for those options for the servicenow email infrastructure so you can restrict file types you can restrict domains you can use email filters you can also set up SPF DCM and dmarc something that's somewhat newer as well as if you have a custom domain such as acme.com you can set up dcam for that custom domain as well and with that I'm going to pass this over to Rasheed who's going to cover the Run steps of the servicenow security Journey so yeah so so what we're in the work step we reviewed the basic location of information about where to get help and actually maybe I missed that you can always reach out to our team through your account manager as well on top of the information presented we um found where to find um what service now is doing behind the scene in terms of security in the work step um we of a security Journey you understand who is responsible for what like any cloud provider there is a sense of shared responsibility when we talk about security you get introduced to the instance equity center um you start to understand login and reducing the attack surface surface by utilizing utilizing adaptive authentication and service now email security option so now it is in the Run step let us review some of the capabilities you can leverage to meet more stringent or rigorous compliance requirements for your industry and gain more control over your data access privacy requirements are becoming focused for all of you here so and that's why I wanted to to start by introducing here uh out of the box free features to help in that regards you will hear a lot about security features uh but I like to emphasis on this new capabilities for data privacy which are um we where service now is actually bringing more and more features released after release which is an essential aspect of data security first days so it has become increasingly important as the amount of data we generate and share online continues to grow as organization collects more data about the customers employees operation they also take on more responsibility to protect that data and respect individual privacy rights in the context of service now privacy features play a critical role in answering but sensitive information is kept secure and used appropriately which these features enable organization to comply with privacy regulations protects against data breaches and build trust with your stakeholder one way to do that here is help you to a by is giving the features to help you classify that data once fat data is classified by based on your sensitivity level you can then apply different rules or even apply encryption context if necessary you can also track all the export of a sensitive data outside of your instance automatically through the security instant security Center one other aspect of enhancing your security and privacy of a platform is encryption and we understand not only you have the same requirements in terms of encryptions or uh that's why we have provided few options based on your risk level or risk sensitivity or risk appetite for you to encrypt the data on your instance of course each of them comes with more action on your side some of them come you know when you you get them by default all the database will be encrypted and you have nothing to do some of them options we have uh requires you to actually go and and decide of the different policies to encrypt and decrypt your specific field I invite you to look at our documentation on encryptions for more details but you have to know it's by default there are no encryption except in the backup and that's why if you require encryptions for your in your organization look at the different encryption options we have and choose the right one for your needs one key aspect to run encryption I like to present here is the options to give you absolute control of your data in the cloud that option yes allows you to as you control as you upload your own key we will use your own key to encrypt your data we will allow you as well to actually withdraw that key which will stop we access to all your data in the instance from anyone including you that's why we have included as well the resupply options to allow and you only allow to allow only you to bring back the data accessible to your users uh and um to your users and to everyone so that's options yes it needs to be used with a lot of a lot of caution because if you lose that key no one will be able to help you not even service now because the key will be lost with which you have encrypted your data in the servicenow instance so that option came with a latest release and can be um useful to fulfill your stringent security requirements in your organization allow me to um introduce our new servicenow vault which is our Marquee security announcement Suite intended to provide additional layer of security on the no platform volt the name is maybe confusing it's not evolved is is an is a bundle of consisting of a suite of security privacy and visibility tools so customer and you can not only secure their environments but also demonstrate that to an auditor servicenovo consists of five key security elements one of the key element is platform encryption which allows you to comply with mandates and protect sensitive data I've presented encryption just before one of our key elements is data anonymization to ensure that our privacy like by discovering classifying and anonymizing anonymizing specific data fields containing personal identifiable information secret management to secure store and control access to credentials that you may have in service now instance in some specific case cut signing with a cycle of trust to validate authenticity and integrity of mid server that you some of you may use with servicenow and finally our log export service which improve security threat monitoring with easy integration of service now system logs into larger Enterprise security analytics system I haven't mentioned it before you will be able to export all the logs outside the instance these comprehensive security solution has been packaged to make it easy for organization to order and contribute solution if you want if you need more information please look at our documentation but that's really a new bundle that we offering to our customer today after all of this one key aspect we're offering our customers is to allow them to do their own pension testing at the end of the day any control we have put in place you are put in place you are able to test it by doing running your own penetration testing and you can imagine if all our customers are doing it which help greatly improve security of our platform but we also if you if you don't do that we also have a third party pen test that we make available to you if necessary and yes I've been over there security is in your hands um we haven't of course reviewed all the different options here but available for you and we reviewed some of them like adaptive authentication you in VR VIP range based authentication based on your location you can allow or not allow access to your instance yeah because that review all of them here but you have to understand that you are at your disposal a suite of out of the box setup and configuration but also Advanced paid option like service novault so what we like you to do today and hopefully we have achieved the goal of our presentation but we need you to identify where you are in your security Journey right and where to find the information make sure you review the uh you or you bookmark the security best practice you know where to find more information about security Center and leverage our available resources [Music]

View original source

https://www.youtube.com/watch?v=aM-XRa-j5z4