logo

NJP

ServiceNow Federal Tech Talk: Cloud Transformation Powering DoD Missions

Import · Oct 13, 2023 · video

good afternoon and thank you for joining us today koft technology would like to welcome you to our service now Federal Tech talk Cloud transformation powering dood Missions at this time I'd like to hand the floor over to our speakers team the floor is all yours thank you everybody um we're the service now team I'll go around and do quick introductions and then jump into some um content we have today and then take questions um at the end I'm Shamira I'm at service now I am a product manager for our us clouds uh the GCC the government Community cloud and NSC our national security Cloud Pete all right right good afternoon everyone thanks for joining my name is Pete loango I lead our Solutions Consulting Group within Federal here at service now um so I've got priew over Intel DOD as well as our civilian business so I can talk a little about kind of what our customers are using service now for and hopefully can share a little about those use cases with all of you today and with that Dave thanks Pete my name is David Paran I'm with the office of the ciso field security Team U my role is to basically enable customers to understand our Cloud security posture but also um you know manage uh help them manage through their ATL processes and understand what the nuances in terms of onboarding their actual service now instances so thanks for having me thank you all for being here um we'll start off by going over a service now overview and um some of the key DOD Focus areas all right Pete over to you great thank you this is great we're actually in the same location so it makes it a little bit easier for us to do the handoff instead of multiple Zoom pictures so I know it's a rarity on these live telecoms but uh it's nice to see so one thing we did want to start off with is really what is service now I know a lot of folks are familiar with service now as an IT Help desker ticketing system um that's sort of where we got our Roots we started in itm and making sure that you could get to those ticketing at this point though after 15 years in business we have done a lot more so really the core of service now is the entire platform you hear you see this slide here where the intelligent platform for endtoend digital transformation what that does is really gives that platform Foundation it tiing is one solution area and not all of it right we do more than that so if you look kind of across this that middle layer where it says the now platform that's the fundamental piece of service now that every customer gets regardless of which solution you're using that piece allows for automation data management Ai and ml really kind of the fundamentals that build that and then everything on top of that is built on top of it our creator workflows is our use low code use case where we can build anything that c customer Mission oriented and we'll talk about some of those that DOD has implemented shortly but that allows you to really build something that's fundamental to your mission your use case because no out-of-the-box vendor provider will give you those use cases um but then we do provide some kind of prepackage solutions that are similar to every company industry or federal agency um that's our customer workflows or industry workflows or employee workflows if you think about employee workflows that's things like onboarding a new hire offboarding uh a departing employee doing a change of state St doing something like that for government where you're doing uh TDY all those functions can fit in our employee workflow system and then be kind of expanded out with our creator workflows because each of these building blocks does tie together and really fundamental to all this is the ability to tie into any of your existing platforms so we've got access to third party data whether it's Oracle workday uh people soft you know any of the underlying tools that you have in your environment today can be plugged into service now so you get that data you get value from the Investments you've already made and then you can really transform that using our digital transformation platform to kind of move that into other areas so this is where that's a very very quick overview of what service now does as a platform but I want to sort of level set because what DOD is doing with cloud and service now is much more than just an IT ticketing and help Des system so that's what we really want to start with that um because while some of you may be familiar with that I know that is not one of the more common things that you hear a lot about so all right this is the next slide and so for this audience here I mean how is DoD seeking to transform they really want to do some of what we talked about they've got to modernize their legacy processes they've got to protect their environment ecosystem infrastructure there is and has been a move to the cloud across DOD for quite some time and now it's not just moving to the cloud but now it's extracting more value from the cloud and making sure it's secure to then kind of you know handle those threats from different nation state actors or different threat vectors that are coming in so really what you've got to do is make the most out of your investments in it give a efficiencies to your people and drive that Talent so you can recruit new Talent retain the talent you have and give them a solid consumer grade working experience so they can do what they need to do to get that mission Done Right the mission of the dod is to protect our borders secure our Assets in the world protect our war Fighters it is not to just run it systems for the sake of running it systems and service now really believes that we can meet those Mission goals by really cleaning up the back end without rip and replace big Legacy 20y year you know new systems built it's something that sits in that workflow layer to really transform it but give you the assets give you the value of your data help you set up for things like Ai and generative Ai and what you're doing really make sure you can meet your mission needs with the data and the assets you have with a platform that rides on top of that one thing to call out here and I know Dave is going to talk about it shortly is that we have invested heavily in the federal government and we are making sure that we can really meet the needs from a security and compliance perspective we operate at every compliance level within the Federal government we meet that for DOD and we also do it for the intelligence community so with that I'll turn over to David let him talk a little B about kind of our compliance posture for you thanks sweet so before I start before I start uh in terms of describing our uh respective cloud services there's a misconception that is pretty common uh I've have conversation with customers describing the service now platform and a lot of times they think um that we're a essentially you know an infrastructure as a service and so where does service now um essentially fit in this you know Cloud Model um if I go to the next animation you'll see that um we functionally um operate as a SAS so we're authorized fed ramp high or dood4 or DOD I5 or NSC and GC respectively um you know we actually have the you know the official authorization to function um as a as a sess but sometimes customers can also associate us as a pass but I wanted to really just you know address the misconceptions that customers can you know actually control their environment but that's not the case you know so if you can take a look at this image just we rest assured that we actually operate as a SAS officially but you can also you know bundle this in as an actual pass now the the reasoning or the reasons for protecting um data um in our Cloud customers or you know government agencies they have requirements to to make sure that they have the appropriate controls in place and there's various levels when it comes to protecting you know specific types of data for I4 um we have um you know cui data that needs to be protected but also you know with io5 that's the same you know situation but what's more specific or unique about I5 you know protection um you in this case is the fact that you know we're really talking about um you know protecting National Security Systems data you know so that's the main difference between the two clouds in this context there's about nine different controls uh between the two environments uh but they're they both have their you know specific function now when we're talking about eligibility criteria and you know things of that you know that sort you you're really talking about um who is um basically eligible to uh to be hosted in these respective environments for the Department of Defense they you will most likely see uh customers mainly in aisle four and Isle five but for non-federal agencies or non- dood entities they will be hosted in fed rep High instances in this case and a lot of times um how do we access or how do customers access these various environments so for I4 you know and as well as for I5 you must originate from the Nipper net um otherwise there will be a a series of whitelisting you know processes and steps that you have to take as a mission order to make sure that your users are able to access those instances now here's a a really I like this slide very much in in in regards to the differences between GCC and NSE I won't go through every one of them but the main thing I wanted to point out is the Target customers so for GCC um it does allow for um non dood entities to operate in that environment for nsse it's strictly for for the Department of Defense and there's um you know lots of regulations as well as mandates that obligate service now to enforce those respective um controls in this place or in this context um if you were wondering how is what's the differences in terms of the architecture between GCC and NC um the the third bullet there so service now GCC is hosted in service Nows Cloud however for nsse this is uh basically a full stack implementation inside of Microsoft Azure um but by and large we're still using the NIS based um you know control framework more specifically NIS 853 rev 4 we're looking to go to rev five um next year uh but essentially the main differences here in terms of um the actual architecture is where is you know the the respective components are hosted GCC is in service now natively NSE is being hosted inside of Microsoft aure and with that I will hand this over to Shamir thank you David hi everybody um so that was a really great overview from David about the different types of clouds that we have at service now for the US government um and in trying to you know meet the needs um for the data and and the right compliance levels that you have and and like Pete said you know having you not need to worry about the infrastru structure the operations and starting to do more of the workflows and enabling solutions for your you know end users your employees your customers Etc um without having the operational overhead of a self-hosted um on premises instances so GCC has been around for about five years um in you know in a couple different iterations and it's familiar to most of y'all um so it is it is authorized at fed ramp high and Isle 4 uh for the dod we have it's a separate carved out section of GCC that like David said is only connected to the Nipper net um and you know this this was this was this has been available uh to our D customers for a while but I wanted to draw your attention and focus a little bit of today's talk on our most recently launched offering um for for our DOD customers and this is the National Security cloud and it is truly a SAS offering with the same level of kind of access and um user experience that our commercial customers of service now have so we're we've built a purposeful cloud and authorized at Isle 5 um and ready for you to do all of the you know the wonders of the service now Eco system the workflows the applications uh whether it's building your own or leveraging the ones that we have out of the box um In This Cloud that was again purpose buil for the dods um it was it recently launched as of March 1 first so wanting to kind of get some awareness about of this out there and then you answer any questions you'll have as well so I guess the first thing um to understand is you know with with the with the move to to the National Security Cloud it is providing um it's providing you really a completely isolated um and separated Cloud that is has the entire service now software and Hardware stack replicated in there so you know as we launch new innovation and new capabilities for the service now platform and products we will you know continually be adding to uh the National Security Cloud enabling you to have the latest and greatest um including our family releases as well as you know new capabilities like like generative AI to come now this entire cloud is like I said you know has a has its boundary um and and we do have all the services that are that are in there exclusive to the customers um in the National Security Cloud now what what is this enable it enables you to be more agile right to have more um sort of budget and time that would typically be focused on operational maintenance of self-hosted instances and now we could sort of pivot to really using the power of you know ass sass platform um and having you know the latest upgrades and the latest patching to mitigate risk RK you know and then have the confidence in service now's maintenance of this Cloud at the levels that are you know uh mandated by the dissa cloud security requirements so there's a lot of value to be got uh By You Know by using NSC and we're really excited to bring this to our customer base and then uh see see the different use cases sort of get built on top of the National Security Cloud a really quick peek into the architecture we're not going to go into this in a lot of detail uh but like Dave said we built it on on top of the US government um cloud from from Microsoft Azure um also authorized at i5 and so we're sitting kind of um on top of that so we're using their infrastructur as a service customers will not see the Azure components except for maybe in some cases of like migration of data at the start um besides that you should only be seeing the service now portal um and uh you're you know interacting through those IP um address and URLs that were provided to you so um again you know controlled access via the Nipper net no other customers except for DOD in there and um and again you know there's there's really a big team at service now that has worked to launch this and continues to maintain it over um over time so that's kind of what I wanted to um kind of focus on a little bit in my section and then I was going to um yeah Dave Dave is really excited about the actually yeah I wanted to kind of enter or basically inj the fact that uh this is actually you know unprecedented um in terms of being able to uh have a a rather longstanding um atto so we were able to secure uh our PTO until um uh June of 2026 which is pretty pretty cool in my opinion because um I cannot tell you how many times myself or or Shamira or Pete hey when is um when is uh I see that the authorization is about to expire what's the update what's the update well now we can actually not have those those sort of like inquiries bombarding our compliance for our Cloud Assurance team so just wanted to kind of throw a plug in there so thank you yeah thanks for calling that out always nice to have a longer timeline so that that's all we had in the content so please keep the questions coming but I did have um kind of some questions to ask I'll ask David and uh Pete to come up here and then I will be the question asker okay all right I'm GNA move off of this slide if we can so that we can just sort of yep there we go okay um and shir's got a few questions for us that obviously so we can have a dialogue about share that we thought might be interesting to most of the audience but as as you do please uh use the Q&A function and and ask others yeah please all right so first question is um as you you all have both worked with the dod for a while um what has been the typical like barrier to Cloud up you know in in your years p I can go first I sure this for this is a layup for this I mean for this topic but um essentially from my perspective um you know uh adoption into the cloud means a lot of things to folks right so you know essentially uh you know understanding do they have approval to go into the cloud is that's really a barrier that's overlooked and it becomes quite apparent that if you don't have those appropriate authorizations or approvals in place um before you know it you're back to square one and there frustration sets in um another thing is just basically aligning uh internal Technologies what sort of applications you have Integrations that might be in scope so those sort of like you know um those buckets if you will they have to be accounted for so um proper planning and making sure that there's due diligence um you know take being had in this case is always a good first step in terms of getting over those barriers as quickly and as efficiently as possible but I agree I mean I think that makes sense from a you know especially when we're thinking about compliance I'd say the other piece that we see is also process changes um whether you're moving to an IAS Cloud you know an Azure AWS gcp or you're moving to a SAS offering like this there are definitely process changes whether that is on the back end and how you manage things whether that is how you manage your alerting and your incident response processes kind of all those changes need to go into and be planned for uh you get greater time back in terms of focusing on your mission because you don't have to manage everything below the stack but then you've got to adjust like all right great I don't have to manage that but I need to get alerted by that cloud provider I need to understand that so I think those are some of the big things that really Drive some of the the movement to cloud and how you can get there I think the value you see in cloud is really after you've made the shift and then you start to realize that operational value because it is an IT project to get there in the beginning and so as long as you understand that there is not a return on day one but a return on you know day 90 or day 180 that's really where you start to look at it thank you for sharing yep um all right so my next question is regarding success stories you've seen over the years right um service now has quite a significant dood customer base and you've seen customer sort of Y different flavors what are some takeaways from those successes first I'll take this one sure um I will start by saying I mean every every branch of the military uh in dood as well as the fourth estate is all using service now today so that is where you've seen some of the capability and many of you might have it behind the scenes and not even know about it but it is something that's out there today one of our kind of more popular use cases that I'm particularly proud of is our Arma arm it's called Arma it's the Army maintenance application it is built on service now and if you remember I talked earlier about customer workflows what this is used for is really used for the maintenance of housing on base so when a soldier deploys they might deploy and their you know significant other family members spouse loved one whatever you want to call it um it's home and so rather than having that service member worrying about hey the toilet's broken hey there's mold in the garage because of a flood the roof is leaking in base provided housing that process used to take weeks to get those things fixed multiple phone calls no real clear sort of approach to get that done um theyan a pilot about two years ago one of the bases and they were able to roll this application out so that a spouse of a service member can take a picture of a problem a leaking toilet you know a leaking roof whatever it might be take a picture submit it through a portal and rather than taking weeks to get responses back it now takes you know a day two days to not only get a response back but then get a plan of action to correct it and they're expanding that to more bases now across the US they've rolled this out further because of the success the amount of money saved as well as the satisfaction on the maintenance of army housing has been tremendous and that has obviously a direct impact on people as well as our wari whether they're home or not having to not worry about it so that's an area where I mean it is what you think of a very simple use case maybe not Focus but it allows that service member to focus on their mission when they're deployed because they're not worrying about you know being able to fix something at home that they would normally take care of and so that really helps Drive the mission we have numerous others Around Mission workloads and capabilities and whatnot um obviously not all of them are for public dissemination but that's sort of where where I do think of if you think of what is any problem process paino workflow that can really be automated and simplified um you know I think of things when you're when you're departing the military and you've got to turn all of your assets that's a huge process very heavy and paper dependent that's something that can be automated there's a lot out there that you can do so I want to share that one just because of the the value to our our service members but also because it it kind of demonstrates the capabilities of service now I think you nailed it all right all right David a question for you um there is a lot of you know I guess worry about the paperwork involved especially moving to SAS um you know from more traditional models so what would be your advice to our our dod you know um customer base of kind of navigating that and any any tips yeah um first of all try to identify um who your your authorizing official is and who is your ISM or your isso right those are the security officers of your agency or your organization um having a conversation early in the process really helps um you know decouple a lot of like um delays right because if if you do things a little bit slightly out of order without the proper um authorization or approvals or just get getting to communicate what you intend to how to use the platform um you're just delaying the the inevitable in terms of all right well this it going to take you know maybe eight months instead of two months right so my suggestion is to get Buy in from the stakeholders um you know contacting your security officers respectively but then also get the talk with your account team and help allow them to help you to compile as much uh documentation as possible in preparation you know towards onboarding your entire um Community to the service out platform so preparation preparation preparation and and just being a lot you know be being more communicative to with with your security um agency or your security um officers respectively so just be prepared that there will be some you know things that you have to go ahead and and get um you authorized or or or approved and there will be some peerreview right you so architecture will come up a lot um security requirements what's your data governance model and so make sure that you bring all that to the table before you move forward with any sort of implementation thanks Sten it's great um great advice and I think we've seen this play out in a number of our customers so um my last question I think we'll we'll wrap this up a little bit early if there's no other questions um is nse's launch we're really excited about that um obviously unlocks a lot more uh use cases for us and from the is 5 standpoint um in the SAS model that we're want want to get to all our customers um what are you excited about like the next year or so and and seeing customers in the dod adopt n well I just like the fact that well I'm enthused about you know the this just the broad broad adoption to begin with I mean we've had customers in our Cloud for quite some time and so now we have the opportunity to grow with the customer right so you know Pete just mentioned in terms of leveraging the platform for digital transformation and being able to stream on a lot the processes but from a security perspective you know my team as well as you know other you know folks on the compliance side you know we're basically locked hands or you know we're locking arms in terms of making sure that we're protecting the customer as best as possible but also enabling our customers to leverage the platform securely showing them best practices what are the data governance model that I mentioned earlier right and just just being over communic overc communicating in terms of all right these patches are coming out or here's a new capability within the platform like say for instance adaptive authentication not sure if anyone knows this but like this is out of the box in terms of being able to um you know uh do what's called Step Up or step down authentication to be able to comply with your agencies or your organ ganization sort of policies so I I'm I'm enthused in the fact that we're able to you know um Kickstart our security campaign with customers in terms of enabling them giving them best practices that I mentioned before so that way they're more equipped and more empowered to secure their instances so um I mean for me what I'm I'm really excited about is really the the level of use cases and the the benefits that we can provide to the dod um to our service members deployed at home wherever it may to really meet the mission of DOD I talked about the Arma example there are many others but what really excites me is that if we can simplify people's lives if we can bring data that they've already got stored somewhere and kind of bring that forward and automate it really to make kind of their life easier we hear all about budget threats we hear all or budget concerns within the D we hear all about you know the escalating threats from other nation states we look at things like Ukraine and and the other areas around the world and kind of the unrest DOD is in all those areas right whether they're just you know doing analysis or or they're doing actual boots on the ground they're doing everything for um our country and being able to kind of help support that in a way that really removes some of the the burden on that right if you can make your job easier to put boots on the grounds if you can make your job easier to do humanitarian rescue missions if we can do any of that whether it's through asset maintenance deployment management Logistics if it's through Supply Chain management all of those pieces can be run through service now and you've got systems to do that but really kind of take advantage of those systems Elevate the data up expose it to the right users and then automate it through the system it makes your jobs a lot easier and that is something where you know I think these siloed systems on Prem today are are able to be tied together because we can tie into an on-prem system we can tie into another Cloud vendor bring that together for a user and for a workflow in a mission based scenario and that to me is what's exciting about kind of you know what servers Now can do or commitment to the federal government or commitment to DOD across every impact level including the classified environment is really something that I think we've got a lot of ability to help with and I'm excited about that opportunity oh well set Pete all right that's a wrap from us um Heather thank you for hosting us you appreciate it are there any other questions out there questions folks can come off mute we're happy to take them live as well and if not reach out after we're your resource and we're here um to answer any questions or have follow-up conversations as needed

View original source

https://www.youtube.com/watch?v=Q5AvDAAH8lM