logo

NJP

Snyk Peek Part 2 New Snyk Integration Releases for ServiceNow

Import · Dec 15, 2023 · video

okay well thank you everyone for joining today um it's my great pleasure to welcome back to live on service now um our technology partner uh sneak um sneak security we have a repre of the presenters from uh previously because there's new and exciting integration material for for us to share with you today my name is Aaron Bennett at leite Partnerships here at service count for Tech workflows and um if we can advance one slide I'd like to welcome Mark Nichols and Aila manoli from um service now Mark Mark is from sneak um to uh co-present today on the topic that we have for you the new Integrations just uh very quickly to um flash our Safe Harbor notice maybe some forward looking statements today um so take that as you will also um for any who go also for any who'd like to join uh future live on service now sessions we have this QR code um you can scan from your phone or um you can visit the service now Community community. Serv now.com and uh click on our events tab um go ahead so finally um we will save time at the end for Q&A we may or may not answer questions in the flow of the presentation so please do um add your questions to the chat um or to the Q&A section in the webinar we'll take them uh in either format and um we'll make sure to read off those questions for purpose of the recording so that if there is any um if there's any need that um you know we can make sure that that content's available for afterwards the session today will also be recorded um and stored on our community YouTube channel and will be attached to the the blog around this content today and uh we'd like to um ask if you'd like to be contacted for further uh further assistance afterwards um on the new Integrations so we'll we'll get to that probably halfway through with that I'll step I'll step aside and um welcome Mark and Aila uh to take it away today thank you very much thank you Erin and U and Aila and thanks for the team for uh the folks for joining us today we're really excited to share with you some updates to our sneak integration with service now there's there's a lot that's been going on here and we'll cover a few things like the business challenge that that we see our or our customers facing in terms of managing risk in their organization we'll chat briefly about the background of the partnership between sneak and service now uh we'll cover uh a little bit of our app vul response refresher and updates we've released a new version of our app vulnerability response uh integration that that I think you'll find very interesting um we'll also talk about the sneak vulnerability intelligence for our esom app uh we'll take a look at a quick case study and then we'll go into a demo uh we have some information about timelines for Milestones coming up if that's something that you're interested in so the real challenge today for organizations is is being able to identify what their application risk is in their uh in their software supply chain not only do we have our internally developed apps but we have um the apps that we've purchased and we need to know when there's something that happens in the organization from a vulnerability a vulnerability standpoint uh how that's impacting our organization and also how do we respond quickly to the newly discovered high-risk vulnerabilities uh that are needed to protect the organization that I'm a part of at sneak we take a look at that from uh stepping back at a higher level in terms of where those vulnerab abilities are coming from you know for a couple of years we've already known that the the challenge for developers and the def SEC Ops Community is that it just doesn't work to stop your development process in order to check security it's something that has to be integrated into the process from beginning to end uh and the more that we can provide developers the tools in order to address their security uh challenges the more effective and efficient they will be in producing great applications they'll be able to move quicker another challenge that that's happening right now in the in the world of application and um vulnerabilities is the fact that we've expanded the scope of our code and now we're including what's happening in the cloud and the fact that um uh that even what's going into the cloud now is being controlled by code it's a whole new level of exposure in terms of risk for the organization and so it's very important for us to understand uh the role uh and how do we address the risk associated with that and then finally uh one of our um sea level officers today said you know this was the year of AI everybody knows about Ai and the impact that it's having and um we're very familiar with the fact that AI is going to change the world for everything especially for developers but the challenge is is what what if AI is producing insecure code and how is that going to add risk to your organization and so the solution that we're going to talk about today address all all those challenges in bringing together uh the story of sneak and service now and H how you manage that risk for your company sneaks approach for the the first part of this is making it easier for security teams and developers to work together to find and fix prevent Monitor and manage those vulnerabilities as early in the process as possible uh now the manage part is the part that's going to really uh come in handy as we talk about our integration for service now and in in terms of the framework of why this is important or um the partnership between sneak and service now uh first of all sneak service now is a sneak customer we're very proud to have service now using our products uh that they they've integrated into their processes uh so much so that they became an investor in sneak uh they're part of sneaks Advisory Board we have been a member of their Technology Program since February of 22 um and all of the Integrations that we've done or all the work we've done in our Integrations uh has been in coordination between sneak service now and the clients for both organizations we've gotten a lot of feedback based and a lot of the work that we've done is based on what uh customers have asked for uh so much so that I'd say that the the sca or the source code analysis data model uh that's being used in the the app V module within service now has been influenced by sneak and also the esom data model uh in fact we were launch partners for the sea offering and the sbom offering by service now and we're very thankful and proud to be a part of those two launches and some of the key outcomes of this partnership uh is something is something very interesting we have two certified apps now in the service now store that customers can be begin to use the the 1.0 version of the vulnerability response module was uh introduced initially in January of 23 and we had an updated release of that in October 26 of this year and we also released the sneak vulnerability intelligence for service now esom on November the 7th and so with that in order to put the Integrations in the context of solving this problem of addressing risk for the organization as far as applications are concerned I'm going to turn it over to Aila manoli and she's going to talk about what application vulnerability response represents in service now and then we'll talk about how the sneak integration Works in that world thank you Mark uh to those of you who don't know the application vulnerability response module of service now it's it's part of the broader vulnerability response and it provides a central location to manage and respond to vulnerabilities across applications so one of the common problems security teams have today is lack of visibility into application vulnerability information so basically no landscape awareness so by defining the business applications using uh service application portfolio management security organizations can have landscape awareness like what are my crown duel applications how many of them are external facing how many of them have PCI Data so on and so forth right and the application portfolio management combined with application well response the goal is to provide a single pan of glass for security organizations to understand the security posture of all the application in my environment and which you know you can use the application context and the criticality and severity of the vulnerabilities coming in from different scanners and not only that we can use this information to share with development teams for remediation or the senior Executives and the Risk Managers based on the need of the hour and and you might be familiar that most organization use testing tools like dast sast software composition analysis which is known as sea and all of these tools provide different ways to find weaknesses during runtime or by examining source code or vulnerabilities exposed and open source components using these multiple tools testing tools also creates a new layer of complexity for security teams to collect data points to identify relevant development teams and to determine the next steps on how to remate them so application vulnerability response supports importing all of these type of scanning like Das s sea and also manual pen testing and not only that you can integrate with many of the uh parters out there and and in just as findings to the AVR and the service now sneak integration that Mark was talking about the version but which was released last year it it supports bringing in the open source vulnerabilities uh basically the sca findings into the AVR module and what this integration supported was the ability to bring project from sneak into service now as application releases and scann application and we could bring in issues from sneak as service now vulnerabilities and application vulnerable items and packages and ability to link the application release and scan application using the C lookup rules that's part of the application VR and provide a userfriendly dashboard for data visualization and you might be like you might have already given it a try and I want to give it to mark back to hear the exciting news of what the updated version looks like today Mark well thank you Aila you know before I I go forward with that I want to take a step back here and I like to make webinars like this more conversational and don't worry I'm not going to ask any questions that uh that you're not already prepared to answer but isn't the application vulnerability response module within uh service now part of the SE Ops environment you're you're right yes it's part of the security operations yes yeah so so so within cir security operations I know that there's a vulnerability response capability within service now and uh from a market standpoint in terms of the where especially large Enterprises are going uh is is it is this one of the the most important or fastest growing parts of service now right now is this a big emphasis for for organizations absolutely absolutely you said it right Mark because you know um with we'll go in the youth case studies we'll Deep dive into you know the lock for and the solar winds and how that has impacted Ed organizations and how many hours have gone into just to even find out where where the risk is still existing right like to even know what should I fix so things like that you know using application vulnerability response uh we we can actually and sneak together the the power power companies together how they can actually reduce that time to resolve when they when you thrown into issues so yeah it's one of the fastest growing today for sure you know I remember the days when we didn't talk very much about open source code and how it impacted the organization and the risk that's associated with that and uh everybody was just concerned about you know whether or not I was writing a buffer overflow you know vulnerability in my code but but now as much as 80 or 90% of the package that uh I mean 80 or 80 to 90% of the code that's Incorporated in in releases now I understand is using open source libraries open source packages so so yeah here here's the part to what's new I mean it's great that sneak has been able to have this integration now for a while uh but but there's some really exciting things here and what this new integration to do of course I'm start on the right side of this screen here we added support for Tokyo Utah and Vancouver I think we already had Tokyo so it gives customers to be the ability to be on the latest version U is one of the great pieces of feedback we had from our customers is that they wanted additional filtering options in determining what flowed from sneak into service now and so we added a whole list of things like you know One customer used different repositories uh for software uh source code management they had some bit bucket some GitHub and they wanted to be able to filter on which one of those were brought into uh the service now environment we added some cwe information from sneak in the service now we we added the ability to close uh avit now that's the application vulnerable items that get created when an issue comes into sneak I'm sorry into service now when a project gets deleted from sneak but the biggest one the thing that seems to be the most exciting to the customers we've talked to is what we call bidirectional capabilities and from what I've heard I think we're one of the first integration partners with service now to have a bidirectional capability uh and what that means uh and we'll demo this here in just a little bit but but uh if if there's a developer or an appsc manager working in the appv module within service now they can uh they can define an exception process or they can say ignore this issue and that flows back in sneak so that deel velers that are working in the sneak UI uh know that they can ignore an issue uh and we'll take a look at that a little bit more but it's it's pretty interesting now that this level of integration that we've Incorporated so the other big issue today go ahead yeah I just wanted to add here is I know that's part of it was part of the first release too but the sneak score the sneak score also comes in uh you know to service now and it really helps to prioritize and you can make use to to drive the remediation and which one is my priority right you you can make that fit into the risk core already well that's great you just took us back to what the core problem is what we're trying to solve today is understanding risk in the organization that's been introduced by applications I'm glad you brought that up now the next thing in terms of the challenge of of Open Source packaging and how you manage that is what's happened with the world of es bombs I remember years ago that uh es bomb was not even an acronym that anybody knew anything about and so tell us Aila about the es bom offering within service now and what this represents yeah this is really an exciting time for service now right now uh I'll tell you why Mark U because you know the with the Vancouver platform release um you know and we a few months into it already see uh service law platform has released a new um application called as bomb which is nothing but software bill of materials so what is it right so you might be familiar with open source you already know that open source software has become the common place for application development today and but it also introduced it not only can we know that it introduces security risks and service now right in time has introduced software bill of materials which is called as sbom module to easily process and ingest software components inventory gain comprehensive insights into its presence within the business application assess security risk and drive the response workflows using our own platform and by extending the centralized visibility for third party and Homer application as bomb gives customers the ability to more easily manage fiber risk that a company um that accompany with the open source software and you know what is as bomb you know many of us are used to going and grabbing um energy bar from a store and when you when you pick a I'm just giv example of energy bar here when you pick energy bar you tend to turn the bar around and look for the ingredients right it has what all it has and what does it help me do is it helped me to understand what it contains and what I'm I am I can I consume it for example if I'm allergic to nut if it says it has nuts I can make a risk based decision on that so similarly having s bombs which is an inventory for your applications and the risk exposed with that it allows you to make risk- based decision you cannot protect what you don't know it all start with inventorying things and not only that today a lot of federal agencies like us and European Union they're mandating to provide s bomb if your software is ending up in their environment and and we talked about a little bit on the solar winds and preaches like lock 4J theyve definitely increase the need for ES bomb so that's that really tells us the story of why es bomb is required now Aila I got to get a little bit more clarification here did did you say that that we only that service now is only only supporting esoms for my internally developed applications no actually I'm going to Deep dive into it in the next slide good I like it when I ask a leading a leading question that takes us to the next yes so what do we do what do we how do we support right so today uh if you have your inventory already with you so uh you can ingest that to servical platform that two two ways you can ingest you can use the rest apis that we have already exposed rest API that you can call and or it can upload manually and if you're familiar with as bomb there are multiple uh format it comes with and the current version that's out there supports Cyclone GX format and we are working on supporting the um spdx format in the near future right in fact next year so um this actually as you see there you know it supports the commercial softwares Legacy applications OD or medical devices firware whatever is in your inventory all of that is supported today most of it is supported today and once you upload we help you the next step is to assess we help you assess the risk of the open source components coming through the sbom to make the uh and to do that you know along along with investing the data you can also make use of the integration that uh provides the uh security intelligence like sneak right so there are other Integrations also available on the service store but I'm going to be focused on service now and sneak integration how that enriches and helps you to assess better that's going to be my um I'll complete the the workflow here and then I'll jump into that and once you basically our goal is to provide a single source of Truth for your security posture and that that's part of the assessment and once you assess we help you respond so what you can do is you can create findings for the components that are abandoned or stale or for the vulnerabilities where the exploit access so you can have the rules created within the sbom application for which you can create the AIDS which Mark talked about the application vulnerability items back in your application while response module and then you can action them and you can use the full um all the features that comes with the application World response like you know uh assignment rules and all of the prioriti and prioritization all of that put into the AV that's got created and drive the uh response workflow from there so basically as bom give customers the ability to more easily manage cyber risk that can accompany open source software with the latest solution that the sneak vulnerability intelligence for as bomb app sneak brings in more timely and comprehensive and actionable package vulnerability intelligence to S bombs stored in service now so the seops and absc teams can be confident that the s bomb stored in service now offer a highly accurate understanding of the risk within the enterprise software Supply change so together with sneak and service now uh we we help seops and APC teams to better guide the developers so they can efficiently prioritize and remediate vulnerabilities in the components identified in in the swamps does it help Mike yes that's that's very clear thank you okay all righty so let's take a look we're gonna there's a sneak vulnerability intelligence for sbom and I think the best way to to show this is to to demonstrate it but I I'll kind of give you the the overview real quickly here number one it gives you the ability to identify and track new high risk vulnerability so when you import those es bombs into service now uh you know there's of course uh in some cases you can fairly easily identify if there's a vulnerability associated with a particular package from the nvd database but that doesn't really tell you everything that you need to know if you're going to address the risk in your organization the second step is to understand how and where to apply remediation and that's where sneak comes in and we'll show you what that means for example whether or not there's a a package that you're using that has a simple upgrade whether or not it's fixable or you're going to have to rearchitecturing uh so especially if you're a financial institution now there's a lot of rules around tracking your s bombs and knowing what the risk is associated with your s bombs and where the risk is within your organization and sneak provides the foundation for that and then the the last element here is that um not only are we doing the projects that you already have in sneak but you have the ability to import s bombs from anywhere if it's defining an open source package that's in a platform that we were that we support then you'll automatically get this information that I was referring to uh and so it it spans you know it it works for sneak and non sneak customers so that's a great thing about this this integration so let's take a a case study and a demo that we're all familiar with and that's the log forj example if you remember a couple years ago all of a sudden this vulnerability was announced in this package that a lot of us were using uh called log forj it was all over the place uh so if you were an organization that was developing your your own applications well well of course you were using log forj and that's the first thing that you wanted to know is how many of the applications that I developed uh are using lock for J and then the second thing is oops what about the purchased applications if you remember the story as that was unfolding ing that that story and the previous one for people who were using uh a product from solar winds is that that they had implemented solar winds and then within that if they had looked at the sbom with solar winds they would have known that that the vulnerability was in a package that they were using from open source repository and so what you need to know right right away is what needs to be fixed which applications need to be addressed how to fix those vulnerabilities and which system is at the highest risk and that's what the integration between sneak and service now is all about sneak identified the what and the how piece of this and service now provided the context on which to fix first and I didn't add this bullet I should I need to go back and edit this slide and add this in and that is that U service now provides the framework for tracking the the workflows and the reporting of you know who's been assigned the the uh the fix that that needs to occur and how many are still open and are we making progress on reduc those those are all done with the dashboards and so and along with that you know you can do um exception management as well in the vulner response Mark so oh yeah that's right like we won't fix this this is we we've abandoned this application let's go on to the next one yeah that's a great point so recently sneak did a customer value study we asked our customers look we want to make sure that doing what you need come back and tell us the uh you know what are we doing for you does does it really make sense and here's some of the statistics on the right side of this screen uh that that that our customers gave us when you get into a vulnerability Management program like you could have with sneak and service now 16 hours per vulnerability improved efficiency in resolving things a savings of about one and a half one a little more than one and a half million dollars per organization due to Time Savings that means that developers didn't have to SP spend as much time trying to figure out how to fix a vulnerability because they had that information available they didn't they had they knew you know with sneak you can know which version you need to go to and what changes will be required to your applications to fix the vulnerabilities uh they said that it was a almost $ three and half million do due to R risk avoidance uh and the pace at which they were able to fix critical vulnerabilities was almost five times as great in 2023 as it was in 2022 those are measurable results that our customers have reported in using sneak and so um and the sneak and service now integration gives you the ability to manage that entire process so now we're into the fun stuff let's do a demo here and I um let me make sure that oh I knew it I got expired Kila I'm gonna have to come back and log into this but before I do that let me let me come back here and just talk about real quickly uh the sneak overview of uh in this case we you know um for my particular demo user that we have established here I've connected to a bunch of software control soft repositories uh we have this traditional one that we use for demo called the sneak the the Goof the Java goof application that has a lot of vulnerabilities and so those come in uh with different projects and within a project you can uh drill down into this and within this particular uh uh manifest for this Java project you know here's here it is there's the log for J vulnerability uh and this is the information that that you would get if you're using the um the uh the sneak user interface and of course this information is available through apis but what we're here to talk about today is how we bring that into service now and so let me get logged back in here real quickly um with my two Factor authentication all right it came up first to my sbom dashboard but I'm GNA we we talked first about application vulnerability response and so the first screen that I want to show you is this is what it looks like like when you've imported your vulnerabilities from service now sorry from sneak into service now uh it we automatically create avit and by the way that integration is a configurable in terms of how frequently it does it by default it comes out of the box that we uh update these vulnerabilities on a nightly basis um and then we also update projects and organizations from sneak in the service now uh on a weekly basis uh but that's configurable by you uh and we also import if a if a a a vulnerability was fixed in your code and it shows up in sneak that it's fixed we update that and and close the avit for you automatically in this process so you see that these are some of the AVS that have been imported uh from sneak and the first you know the first thing I'll call out here is that we've also imported the sneak priority score that's sneaks uh process of an analyzing the level of of how you know how much you should pay attention to this particular vulnerability and as you can see the Java the the log for J are all pretty high from our perspective from a priority score standpoint but the next column here risk score is something that you define as a service now user where you go in and say okay if it's over this priority score from sneak then we need to say that this is a high-risk item for us it can be critical or high and I'm just going to flip over real quickly to this vulnerability calculators we ship with a default sneak calculator that you can go in and and and modify yourself on this risk rule where we're calculating we're saying that a sneak score between 900,000 is a number one critical 7 to 80 700 to 899 is a 75 and 400 to 699 is a 50 so let's go back to those vulnerabilities here and take a look at some more interesting I said it's totally configurable right if there are any other you know uh scores or any other factors they want to take into consideration before find defining risk they could they can do so they can customize it and add other features but we have faith I mean we this is totally wetted the sneak priority score is already wetted and it already has taken a lot of factors into consideration it makes the the life easy for the security teams and the UPC teams all right well that's good now here's a here's a topic that I don't get into very much Aila and that's the workflow capability and I see here that I've got uh I can probably can I create a workflow to assign it automatically to a group or to an individual correct so the the recommendation is I mean typically you know uh it's to assign to a group that way you know there are many people in a development team there in generally organization has many people within a given group that way they can pick up or they can assign reassign to who can take what load right and all this assignment group can be driven there a uh they're all customizable so uh it's part of the configuration for the AVR so you can Define based on the um the Discord application you know who is the owner of that application you know you can look into different factors like that and create rules and that way the moment the aid is created it goes to that group and get gets assigned to them to work that well I can tell you that it's a good thing that this is a demo instance because this one's assigned to me and if it's up to me to fix vulnerabilities we're going to be in trouble here but let me drill down a little bit further into one of these aits here and let's let's see uh some more information now this is where the the it gets really really helpful here you know we've got a summary of the vulnerability uh the risk score uh but look at this we've got a link that takes us back to that project within sneak so uh if you don't have enough information here you can go get additional information from sneak about this learn more about this type of vulnerability show more detail about this and then we also have uh sneak has this marvelous uh database uh about security regarding vulnerabilities and so there's a link here that gives you a lot more detail about this and really our heart as sneak is is that we want developers to get better at development so that they're not you know so that they understand vulnerabilities and how they got created uh so that when they're writing code U that's why we have the sneak learn capability but this link right here within the avit takes you to that and then then here's that key information this is what you need to upgrade to to resolve this issue all right it's a single pain of glass view for a developer like when they got get into the AIT they know what's the problem they get additional context they also know the Commendation that how to fix that and that brings up an interesting point Aila because I I'll tell you that I think that a lot of organizations think about this in the context of okay it's going to be just my absc managers that are working from service now but there's a real opportunity here for developers if they choose to work from this environment too so that they they can track their information and let's go back to to to one of these avats here because this gives us an opportunity to talk about the B directional capability so as a developer I can go in here and request an exception or or even an appsc manager and I can say let's defer this for a particular period of time or uh I I have a reason for my deferral um one of them is a mitigating control in place and you know if if this particular avit is uh I may want to set this aside for right now it's not a higher higher priority item because until this date till we get some other things that are more critical fix this may be on an internal VPC in your Amazon Cloud and you know this but we may not have that that information available um when we're we're you know before before at the sneak level and so anyway there there's a lot of uh capabilities and functionality here uh let's go take a look at um what's the vulnerability filtering capability and I mentioned this a little bit in my earlier presentation but here's where we Define the information that's going to be pulled in from the integration um and quite honestly a lot of organizations are overwhelmed with so many vulnerabilities they may choose to only um bring in items that are uh have a minimum priority score or they may say that we only want to bring in critical or high in critical vulnerabilities so that they're they're H having a a manageable world to work with uh in this environment and they don't feel quite so overwhelmed and so this will take me out to uh this page right here and so we know that uh every ceso loves a good dashboard and probably a lot of EPC managers do but this is a dashboard that gives you the ability to see how things are are progressing in your organization with vulnerabilities and so I think these are uh and then here's a summary I've got 106 critical I've got 912 high and 242 low so that's very helpful information and figuring out what's going on with your organization yeah and just to call this is demo data so don't go by the Numbers here but but you know that's right this is a demo environment yeah so alrighty let's let's go ahead and poke in here to the sbom world yes so I will start with the sbom workplace and so what I've done here is I've I've imported some sbom and two of these are from projects that are what I'd call internal projects that that we play with a lot here at sneak this is our to-do list web struts struts sbom and then our one of our Java goof projects that I've imported but I've also imported a third-party um application it's one it's kind of a fair a fairly well-known one called keycloak I've never used it before but uh look at this here's the interesting analysis uh in in the keycloak application there's 93 components uh in goof there's 545 and here's a summary of the vulner ities that associated with it and look here some aits have already been created automatically based on the information that's been imported here um let's go here and take a look at step back here um Mark I I think what I want to highlight here is when you the moment you come to this dashboard you can see how many bombs have been ingested the first step you see all bomb entities there three that shows how many bombs you've already inest or imported to tho platform or to sbom application uh and not only that if some bomb entities don't have vulnerabilities you don't have to worry which ones has the second tab which says bomb entities with vulnerabilities that shows how many of them have vulnerability right and uh you brought up the good point about AIDS here so when when you uh ingest a bomb entity you have the aid creation rule so you can create your own rules hey do you want to make it actionable to your development teams and abs teams so you can create those rules and create AIT back in the application uh well response module for these entities which have vulnerabilities exposed and exploit exist in them all righty let's see I'm going to go over here to the es bomb Library so this is actually a list of of um the vulnerabilities that have been identified uh in in all the es bombs and so check this out you know sneak has said this is the uh our version of that vulnerability it's an improper input validation um we're saying that for us the severity is a level four and there you go is this fixable or not fixable and here's the instructions the REM the remediation notes upgrade the package to this version in order to fix this vulnerability that's incredibly helpful information as you're going to decide this this stuff and so let me go down here to this particular screen you I've got all these set as my favorites here's another way of looking that information actually I think the last one was a little bit better and let me go down here to the component vulnerability fix information so this gives you more details about what the component was where the vulnerability was identified the sneak score and which version it's fixed in and this is of course the source that this information came from sneak yeah so lot of good helpful information there now I haven't gone through and looked at any of the avit that were created by my esom work workflow because I don't understand my workflow very well but that's something for another day for uh that you can work out with your service now team to to get that worked out alrighty I see Daniel's made a very nice comment that this is helpful I'm glad to hear that Aila do you have anything else to add for today yeah if I was um if you go back to the sbom the previous slide you were on workspace es bomb workspace correct that's the one okay yeah the workspace click on the second yeah that's the aid creation rule ah there we go correct so that that helps you I think we just we haven't created anything here for the demo purposes but this is where you create you know if you just click on you we can just give a quick understanding of how you can create a new evit um so you can pick you can name it what rule it is and you can pick the conditions as to uh on what component and what vulnerability you want to create the uh aits for so using once that this rule is created based on the sbom information we already have it correlates this Rule and creates the evids that's down workflow right here yeah there you go that looks pretty easy I think I I can probably even figure out how to create one of these aent rules so have to give that a try y y and as you said this is the first version and uh both uh I mean there are a lot more features already in Pipeline and plan to release in the coming year I think and also for the I think sneak as bomb um integration as well like both of both yeah yeah we have many more features coming in the early early next year to mid next year yeah that's that's one of the things that we're not going to get into today but I can tell you that sneak and service now together have road maps for both of these things for both of our Integrations and both of these capabilities within service now and things are only going to get better here so and we'd love feedback from customers on all of this uh we we that's what drives our our our our growth and our Direction in this is making life better for customers so solving their problems absolutely all righty I think uh I've got a little wrap-up slide here and let me pop this back out to the slideshow capability uh the goal here is that you as the customer have complete visibility um and that you have the ability to manage the process making good decisions uh by analyzing the risk to your organization and overall lowering your risk exposure uh and that's what the sneak and the service now Integrations do is it provides the capability to do these things uh and Sol and let's go back to the the first problem michaa the question is and actually let me uh I'm going to go up here on the slides and see if we answered the question for today and the question yeah the question of the day was how do I manage application risk exposure in my software supply chain that's not just the things that I've developed internally it's the things that I purchased and we we've shown how we can do that today with the espon capability and looking at application risk for the applications that we developed internally and how do I respond quickly to newly discovered high-risk vulnerabilities we talked about log for J uh and the fact that this capability gave you the uh gave you what you needed to answer the questions of which um which pieces of software or applications were vulnerable and what do I need to do about it and so yeah I think we I think we've covered that today yeah I think my ending thought will be like as I said together service now it they really help the seop synaptic teams to better guide developers they can effectively prioritize and remediate vulnerabilities in the component identified in in in the response so that kind of summarizes um both applications here Al righty great well with that folks I'm going to uh go ahead and take a look let's see there's been a question here about whether or not the slides will be available yes absolutely the slides will be available um and and uh we look forward to helping you be sure and contact your service now rep or your sneak rep uh if you have any questions these things are available from the service now store if you go to store. servicenow.com and uh you search for sneak SNY YK you'll be able to find these Integrations uh you can start today with the sca integration and U and if you you can initiate the process for sbom from the service now store and we look forward to helping you with those things thank you everyone for attending and thank you Mark I thly enjoyed the presentation co-presenting it with you me too Aila it was great talk to you later yeah bye

View original source

https://www.youtube.com/watch?v=FOHbY2CbYns