logo

NJP

Automation of FedRAMP ATO assessments using ServiceNow

Import · Sep 15, 2023 · video

awesome as people join I'll just get through some of the housekeeping activities um because I know people are here to see Sarah and not talk to me about uh you know some of the uh Safe Harbor statements and things like that but if Sarah you want to get started we can go through that I do need to let you know that um we may have some forward-looking statements that are based on our beliefs and assumptions at this time um and that is all in an effort to be as open and transparent as possible um as we like to do with our customers at service now we really want to make sure that we're giving you up-to-date information and sometimes that stumbles into a little bit of a forward-looking statements um and we want to make sure that you're aware of that um and that you don't take anything um as written in stone um but I'm delighted to bring you to this uh service now webinar um and I wanted to let you know that we've got uh future webinars and meetups coming up um so Sarah if you want to flip we've got a a schedule of events that you can um join at any point um today's session is part of our live on service now sessions which are curated event series that connects you with service now experts and peers that can really help you deploy your products and Achieve value faster um we hope that you can join us again for another webinar or Meetup um and you can see the schedule there or you can look for it in the chat um so definitely access those because we've got a lot of content from a housekeeping perspective we will try and save some time for Q&A at the end so please use the Q&A button rather than the chat button because we'd like to capture all that information and be able to get uh back to you if we need to at the end of the session if we can't answer anything um and we'll have folks on the line that hopefully can answer things uh during the call the presentation is being recorded and it will be shared after the session in the service now community and after the event you're going to be prompted to fill out a short survey we really appreciate any feedback you can give because it helps us bring you more valuable content so for today's agenda we're going to start with an introduction I'll introduce you to Sarah um and then she'll start to talk a little bit about security bricks and their fed ramp accelerator that they br bought that they built they will bring you a demo and then as I said we'll have a little bit of time for Q&A at the end so definitely if you can answer ask your questions in the chat that's great um and if you need to follow up with us afterwards I'm Ros morville servicenow.com and I am a product marketing manager here but the key person you want to talk to today is uh Sarah Lang she's going to be uh addressing you all and giving you all this really insightful information Sarah is a Solutions driven security professional with about 25 years of experience analyzing planning and leading the implementation of Technology Solutions to enhance client productivity she's an expert in information assurance controls and best practices she has extensive experience in federal DOD PCI hippo regulations you name it she probably knows it as well as Disaster Recovery planning and implementation she's instrumental in her team's product research and new release evaluations she's done some deep um sorry she's got deep experience leading and supervising installations and maintenance activities and she's been involved in the planning scheduling and estimating time frames for implementation products in order to minimize downtime of and loss of Revenue while completing projects on time and under budget you'll see today that she's an extremely effective trainer and Mentor with strong communication skills and joining her today is Ahmed balal who it was a key developer in bringing this solution to light so if you do have questions um I think I'm will be instrumental in answering those in the Q&A so bring on your technical questions if there's something we can't answer we will follow up but otherwise I just want to pass this to Sarah and say welcome back it's really great to work with you again it's really G great to be back and work with you too thank you for the introduction so I want to talk a little bit about who we are as a company for security bricks so we are a um organization that is a Fed ramp authorized third- party assessment organization uh we also um have earned the accreditation of a cmmc credit a third party assessor organization as well as state ramp and we are service now uh Partners uh our company has a uh does transitioning for veterans to cyber security over the last couple of years we have a program with the dod to transition people that are coming coming out of that environment into commercial and we really have our primary focus is on cloud security and [Music] compliance and this is kind of covering a little bit about deeper into where our focus groups are um as a thirdparty assessment organization we are authorized and certified by the FED ramp pm to help assist organizations um with becoming ready to be successful um fed ramp um atos as well as um to assess and audit perform the certification necessary for an organization to get a fedra atto we also have a our own security software supply chain platform called appstone and um we specialize in automation of security and compliance so before we get started into the actual um discussion on the FED ramp accelerator I want to go ahead and cover a couple of glossery terms that you'll hear throughout the presentation and some of you may know the word fed ramp but not necessarily what it stands for so fed ramp is the Federal risk and authorization Management program so this is a federal government program that manages the certification and accreditation of all cloud service providers that want to do business with a federal agency and it establishes the security benchmarks and Frameworks of what needs to be in place to manage the risks of federal agency data an atto um is an author authorization to operate so what that means is that your company has implemented and documented all of the security controls and information necessary to reduce risk to an acceptable level to the federal government um and an ATL means that you have not only implemented the FED ramp requirements but that you've had a Fed ramp third-party assessment organization come in and certify your environment and then the fedramp pmo office has looked at that certification package and has agreed and decided to give you basically the green check box yes you you have done everything we needed you to do and you are um a company that all of our agencies can do business with and so that's what an atto stands for um the fedramp sponsorship so not just anybody can decide to become a fedramp atto organization so in order to get there right there's three paths and we'll kind of talk about that in detail a little bit later but sponsorship really means is how are you and why are you going to be added to the FED ramp list and what that means is you can get what's called a joint authorization board or jab um authorization which means your product or platform is in such need throughout so many different agencies that they're going to go ahead and sponsor your atto that means on their end they're going to handle doing all of your monthly reporting and reviews and be the ones to look at your third 3pao uh certification packages the other option is having an agency sponsorship meaning there's a federal agency that wants to go out and use your product and because of that they're willing to sponsor through the FED ramp atto process and last but not least there is a program called fed ramp ready so those companies that have solutions that want to be able to sell to the federal government but let's say they're not U approved by the jab and they don't have a agency sponsor yet they they want to show that they're ready that they're going to be able to pass that certification and that they're there to do business so what that means is it's called a fedan ready designation a Fed ready designation is going to mean that you've gone through with the 3pao the third party assessment organization um and they've certified that you have implemented and documented your environment to the level required by the FED ramp pmo um and you get listed online um in the marketplace as have being fed ramp ready meaning if an agency decides to use your product they can rest assur you'll be able do an easy transition to an atto um next we're going to talk about is poem what is a poem a poem is a plan of action and Milestones um this is basically it's like a running risk register um so a poem identifies any weaknesses findings vulnerabilities um within your environment and it assesses the inherent and residual risk tracks any Milestones um leading up to the remediation of that risk and also what uh defense and depth that you put in place to reduce the risk next you're going to hear things like CIS and CRM work Burks and um this really is a a document template that the pmo office puts out and it is around your control implementation so what controls do you have implemented how are they implemented and the customer responsibility metrics so all of us I'm sure have heard the terms you know shared responsibility um no matter what cloud provider you're using for your Solutions um you know that there's some responsibility that the cloud um provider actually assumes and then there's some that only your company does and others that might be shared so it's really important as part of this program is that you understand that and know where that responsibility lies within your environment right so we kind of talked a little bit about this so I'll go into a little bit of detail here so this is the process to achieve a Fed ramp authority to operate right so the authorization path agency jab and Readiness designation these really are your three paths that you have to get into the fedramp marketplace um the marketplace is an online location at the fedramp pmo Dogo and um that is where it's going to list your company your platform what designation you have um it's almost like a marketing tool for all federal agencies so any that wants to go out and purchase a product or a solution can go right to that page and look for Solutions within that area and see which ones already have an atto or ready uh next we've got the preparation so what goes in getting ready to get that famous atto right so there's you know Readiness assessments which is the pre-authorization so you've gone through and you've done all of your own assessment control re um you've identified a 3PO that you've engaged um that's going to be doing your assessment and at that point you get listed in the marketplace and you go in it's called in process meaning you are in the process of getting your atto um and that Al notifies all the agencies where you're at um next is getting authorized so what happens after all that work is done right and basically you're going to have the 3 Pao going to put together a package to deliver to your agency sponsor if you have one to the jab and to the pmo office for fed ramp and that that package is going to include all of your documented program that you've provided such as your system security plan your policies and procedures your control implementation summaries and shared responsibilities um also it's going to include the risk assessment report from that 3PO and their recommendations and that's going to go in and that is actually going to get reviewed and at that point it will either get authorized and you'll receive your ATO or your ready designation or it will not um if during that process there feel that there is going to be too much risk um you do have there is the option for them to deny that um once you get that designation that you were looking for you'll go into continuous monitoring and the continuous monitoring basically is going to give you it's a series of um controls requirements and processes that you have to have in place that you report on on a a regular basis um this slide here we're going to talk about is fed ramp rev five compliance so what is that mean um fed ramp recently um released their updated version of rev five to align with the nist 853 rev 5 framework that is available um on here uh this is all of the different control families within the FED ramp rev five that would need to be implemented um and we have cross those mapped those to the nist c um CSF the cyber security framework of identify protect detect respond and recover and what that means is these are the higher arching control families um that you must have implemented to secure Your solution a little bit of feedback I'm not sure is this any better that is actually better yes thank you so that includes the pii processing and transparency program management and the supply chain risk management which is a really key feature that's been added as we hear every day in the news between the breaches and the Cyber incidents that are happening um it can take nothing more than a weakness in someone in your supply chain to affect the security of your platform and the data that resides in it excuse me um next we'll talk a little bit about these fed ramp baselines so fed ramp uses what's called fips 199 and it's the federal information processing standard to evaluate the the level of risk and impact to um the federal agencies and where your product solution would reside so the general three basic categories is low moderate and high so this is based on you know what your platform does the types of data it's going to have right so low Baseline is going to have 156 controls that you have to implement that fall into that previous slides control families um moderate Baseline which is really where you're going to get the bulk of most people falling has got 323 and then as you can see you jump significantly higher into the higher risk and higher impact areas of 410 controls now we talk about this fed ramp process but why is not more people and more platforms up there um fed ramp isn't easy to implement it's got a lot of moving Parts it's a very do well documented program um and it does require an organization to be very thoughtful in their implementations and all of their standard operating procedures and to be able to communicate and document how they've secured their environment and with that said there's always going to be pain points when you're implementing any type of new security program um some of those um most common ones are things like the authorization boundary diagram so this is something especially in today with Agile development um microservices that that your authorization boundar is very dynamic in nature you know it needs to include all systems apps third party vendors processes that touch the FED ramp system so anything that processes stores transmit or has access to one of those systems would fall within your boundary so understanding your data flow can sometimes mean meeting with a lot of different departments and people to truly map that back um it's really based on your computering environment and it can be very complicated to design um so thep Sarah I'm getting the feedback again okay oh moved how's that good if you just start back to talking about the SSP sure so the SSP is really going to be your core document and in that document you're looking at about a anywhere from 5 to 600 pages and onwards of documenting your environment this includes everything from the types of roles that are used within your environment or solution um your data flow your boundary Des description and diagrams um how you've implemented each one of the controls that you need to implement your procedures your policies a description of your solution so it's um it's very long it's a big process it's a big document to actually produce and then it must be maintained as well um the SSP is used as the core document for a 3pao to build their test plans and um to do your audit the poem which is the plan of action and Milestone right this is a that running risk register I mentioned earlier and this is where all of your assessments and continuous monitoring and any findings and gaps that you have is going to be documented so if you can't fix something if it's still in place um if you've identified it it's going to go into that poem that poem is submitted to your agency sponsor every month and there's tracking of what's opened what's new what's closed movement or changes to any Milestones or missed Milestones as well um all critical and high vulnerabilities um that are listed in your poem will be need to be resolved within 30 days um medium moderate would be 90 days and low vulnerabilities within 180 days um next is that inherited shares responsibility controls so this is something something that um has caused causes a lot of pain for a lot of people because you have to really kind of dig really deep into um your relationship and what's provided by your CSP um this is where um you have to identify what's fully going to be covered by your CSP let's say for an example physical security controls for the data center right those are something that's fully inherited but how have they implemented those controls you'll need to be able to understand that because it's important for you to understand all of the layers of security on your environment um partially inherited uh let's say that they are responsible for um the overall arching environment um for the network and the routing uh but you're responsible for your own rules and of course that's the CIS and CRM workbook that we talked about previously um and that will be reviewed with um all parties before the federan package is submitted next is the continuous monitoring so there's all this work people talk about about geted for any type do need go ahead and sit down with your three paos but what happens next next is continuous monitoring so continuous monitoring is a part of fed ramp where the audit isn't just a oneandone it's you're monitoring your environment for any changes any new vulnerabilities you're making sure the things you say that you do are being done are you looking and revalidating all your privileged accounts are you making sure that there's not enabled active accounts that haven't been logged into by people that maybe have left if the people's permissions that are associated with their account the correct permissions for their current role are you identifying any potential events and investigating them to find out if you've had an incident right all these different kind of categories and things that we do dayto day and then that needs to be documented is how do I run my security program moving forward in a continuous monitoring State and then that gets reported on so these are kind of the main uh pain points that we're going to address here within the FED ramp um application here in service now so the FED ramp accelerator that we've built um is built to integrate with the existing reporting capabilities of the service now GRC module it's going to provide you with real- time visibility um it's going to allow you to get status and progress on all your CNA activities uh so your Kris and kpis that you've already built are already going to be um usable within the FED ramp accelerator um the tool is really set to enable all collabor a as you know anytime you're rolling out a new program it's not just one Department that's responsible for it you're having to have communications and feedback and receive information from all various teams within the organization um it's been developed to provide a centralized repository so I'm sure everyone here knows what it's like to go out to various file sharing sites and services and have to look for the most current version of a document or having to take multiple versions that people provided input on and marry them together um making sure that all the information in that document is up to date um it just takes time so the fenm accelerator does that for you within the accelerator um it allows you to keep track of all of your related artifacts and evidence from within service now modules and extending to your Cloud environment as well as streamlining the entire atto life cycle by automating assessments and evidence Gathering next we'll dive a little bit deeper into some of those features like how do we address those pain points um so uh we were able to within the accelerator provide evidence for 44 inherited and 114 shared fed ramp controls from Azure and AWS today and will be continuing to expand out to other csps we can automate 65% of evidence collection of the 323 moderate controls so what does this mean to you this means that let's say you're using itsm or devops or SEC OBS within service now is there are um indicators that are built to automatically go into your service now modules and pull out the information and say hey here's your evidence and by the way this is compliant or I I noticed that you're doing something different over here in itsm that isn't aligned with fed Ram so it's not compliant um there's set of comprehensive questioners with guidance and types of evidence you're going to need to provide um on how you should be implementing those controls um there's been templates um that you can produce right out of service now out of our app um that's going to be able to be part of your package that you're going to present to your 3pao such as your SSP and your poam so because you're using a tool you're using the application to gather this information and automatically pull this information we're able to take all of that and everything the application and build CH and paste and everything out of the platform you're using will automatically pull that in and build it out for you so you don't have to sit there spending all those hours um next is the poem the plan of action of Milestones right this is a document that has to be submitted every single month it's a running live document um because you're managing your risk and your remediation projects within the service now we can track all of that Milestone changed new Milestone added when you generate that poem it's going to automatically update all of that information and you can pull it out your importing your uh vulnerabilities into service now and managing your vulnerability remediation through service now we'll be able to add all of those new vulnerabilities that meet the criteria to go into your poem and track those for you as well so no more trying to copy and paste from a vulnerability scanner uh report into uh your poem we'll do that for you and the evidence of course that's going to be collected next what are we doing for the continuous monitoring reporting side right so there are connectors built for the AWS security Hub and aure security to allow for easy importing of your security configurations to service now integrating Cloud security into compliance management um you can also as uh mentioned earlier fully integrated with your now dashboards so out of the box there's several reports kri and K dashboards that you can use to help communicate the status of your fed ramp program internally um there's automation of those monthly reports uh such as the poem and the deviation request forms that must be submitted so now we're going to go ahead and I'm going to turn this over to ahed and he's going to show you a demo of the FED ramp accelerator thank you Sarah um so basically our fedramp exor has fundamentally two parts the first one as Sarah explained is the authorization boundaries here we um Define the table name and the filtering condition to get the evidence for the authorization officers in this authorization package so if I go into to one of this authorization boundary we see it's having an authorization filter and in the authorization filter we give it a table name and a filtering condition on on the on this basis uh we get 26 records matching from this table depending upon the filtering condition once we are done with the boundary filter The Next Step would be to create a authorization package so once the boundary is defined we get the system elements we can see 26 system elements then we are going to create an authorization package we have one for account management over here if you go in this record so authorization package will have seven steps that are namely prepared categorize select Implement assess and upright and one trate so first step would be prepare where it will ask you the name of the authorization package and and also the authorization authorizing official so this one uh stakeholder will be giving approvals on different states so we need approval on categorize select and authorize state so authorization authorizing off official will be approving these approvals so once we're done through the uh prepare State we can move forward to the next step that is categorize in this P we are basically um overriding an impact statement and we can give it whatever we want for example I just gave it moderate and we can just forward to the next St in the select state we will have all of the Baseline controls that are moderate for this barel and in select state we what we are uh able to do we can do control Tailoring on all those controls that we have in our fed ramp accelerator so for example we can select the ones we need or for example if we need if we are doing a yearly assessment so we can just have all of those uh controls in there and just the step as it is and we'll have all the Baseline controls for the authorization uh and the SSP so once we are done with the tailoring of the controls we can just select uh move to next step that's Implement once we're in the Implement State um the controls are going to be generated on the basis of the selected um Baseline controls over here so for example we have five of the Bas on controls selected so it's going to create five controls also what else we can do in this uh State we can um go in there in these controls and we can send in the assessment assessment would be the set of questions that are mapped to the control objective or the control for example for example for this control a61 the assessment questions will look like something like this so once uh the uh control is sent to a test state that we can just do like this select the ones that we need to send to the stakeholder for example we need to send these two we can just go and select action on all of the selected items and do it in a test once they're done the assessment is sent to the control owner so in this case I'm the control owner for all of these control controls so as we can see the state change to a test State once the state changes to a test State um the owner is going to get an assessment that he's going to take for example in this control I already have taken the assessment and it says compliant it says compliant because we have selected um the right answers in the assessment questions for example fully implemented and we give them an evidence for that and a brief uh description and also a control origination we can also uh look into the responses of the controls that will be right here in a testation and inside the control so as we can see the percentage of answered question is 100% And we can review the responses on this side we can see the testment the description and the controller orig origination once we done with the Implement um uh State we can move to the next state that's assess in the assess State we get the poems created if we have any controls that are not not implemented or not the right answers and also we create the control tests the next step of this uh authorization package would be authorize and this t we need uh approval so we can select request approval once we do the request approval the authorizing official will get this approval and he needs to approve it to create the SSP SSP would contain all of the Baseline controls that we had selected and the questions that the stakeholders answered to those assessments and we can have them into this document in this state so for example it will look something like so this will be the SSP document with all the information of this authorization package and all the stepss that we went through and by the end of this document we will have the responses of those assessments and all um map to this document that will be the second last step of this and then we can uh once the all the assessments or the controls are attested and they're answered we'll have compliant not compliant over here once we're done we can just send it to the next state that's the final State that's monitoring and we can monitor all the controls from deer and that's it Sarah hi let me go back all right thank you very much so next we're going to talk about extending the accelerator so we have a solution that extends on top of the accelerator um right now which includes the um Cloud connections to your AWS and Azure so that we can automatically go in and U Pull in your evidence and any artifacts and do your continuous monitoring for you automatically um as well as additional inherited controls content and the indicator templates so those indicator templates um will be able to um validate and check within all of your service now modules um whether or not something's compliant um be able to aler alarm you and give you alerts if you fall out of compliance quickly as well as um being able to pull the evidence necessary from those modules and from your CSP um for all of the various controls within um fed ramp then there's additional enhanced dashboards that are fed ramp specific um that um are available as well and then the solution also includes some validation so being able to have um team of um fed ramp assessors to validate um your um Readiness and your package before you um engage with your 3 paao um as well as actually doing what's called a mock audit so the security bricks fed Ram team will do validation um of your um control implementations and the self assessment and preparedness that you've done um as well as being able to work with you to do an actual mock audit to make sure your team's ready for to engage with your 3 Pao to help um ensure that you have a successful outcome from that audit I've gotten a couple of email addresses um if you didn't get a chance to uh send your email address or you're following up on this recording after it's been posted in community by all means you can email me at rosen. morville at servicenow.com I'm happy to share um this over with the uh the folks uh at security bricks um or your uh rep internally at service now would definitely be able to help so thanks so much for the time I appreciate you coming on and listening to us I appreciate the demos and the uh wealth of information that you always share Sarah so thank you for for joining us today and everybody a fantastic Thursday afternoon

View original source

https://www.youtube.com/watch?v=AV-11iQq9us