Simplifying Compliance with NERC CIP 7 and 10
hello everyone my name is Amanda Justice and I'm a field Chief technology officer for energy and utilities practice today we're going to do a demo of nerp s and 10 uh today our speakers today are going to be Brendan and Kona who is our Solutions uh consultant uh Michael Goden who is our senior advisory solution architect in our cyber security practice and Megan Laughlin who is our irm Solutions consultant thank you for your participation today we help you get a lot of value out of this demo Michael do you want to kick us off yeah so let's get started guys so this is Mike Goen I'm the uh advisory solution consultant focus on the secops portfolio here at service now um so what I'd really like to focus on today is really kind of an end to-end demonstration that combines the use cases and and management responsibilities for a lot of different personas um you're going to be hearing from from three participants on on this demonstration today myself who will be playing the role of a of a vulnerability manager Megan Laughlin will be playing the role of our compliance manager and Brandon anona who be playing the role of our it and change manager um when we think about nerp 7 and 10 and the workflow in most organizations everything really begins with integrated risk management um we want to wrap those nerk policies and controls around a framework that allows you to perform uh patch assessments produce mitigation action plans and track the life cycle of vulnerabilities that are detected in your environment both within the it and estate now in order to achieve this it takes a lot of different components um to really facilitate this overall Administration uh from detection right down to remediation and that's really what our goal is today we'll be focusing on some a some some facets within the service now platform that are going to touch on different modules right from service management to change management Asset Management security operations and even our GRC process um so to kind of kick us off I'm gonna have Megan really you know you know take us down the path of how we integrate um nerp 7 and 10 controls into our irm framework in order to provide a governance layer into the administration of vulnerabilities from the detection to the remediation of those so Megan can I kick the ball to you to to share your screen and get us going Yes sounds good Mike thank you let me go ahead and grab the screen all right is my screen loaded you've got it okay awesome so my name is Megan llin and I'm the solution consultant for the integrated risk management Suite of products um which include our compliance management product which can help you uh establish and maintain your compliance Frameworks for all different types of regulations including nerk zip so to start I'm logged in to our compliance management workspace as Jacob Williams and he's going to be our compliance manager so from here he's going to be able to see the uh unified interface where he's able to look at all of the compliance task across his organization and then see how his organizations is is compliant with different regulations that they're required to be compliant with so he can look at the compliance posture look at all the different Authority documents in his organization he needs to be compliant with as well as all the internal policies and then all the different entities or assets within his organization that are required to be compliant so jumping into our Authority document list from axip um Authority documents you're going to be able to pull in all the different Authority documents that are related to nerp into service now irm so this is where you're going to have all your foundational data set up to make sure that you're compliant as an organization so I'm going to actually jump into our ner 7-6 standard with the purpose of this demo jumping into this Authority document you're going to be able to see an overview of the description as well as how compliant your organization is with this specific standard and breaking down the different compliance from a control level as well as all the different non-compliant entities in your organization as well you can jump in and see more details around it um in this case can be actually either manually imported but you could also um work with a content provider such as unified compliance framework to pull in all the different Authority documents including nsip that you need to be compliant with jumping into the citations so this is where you're going to start breaking down your Authority document into the citations to start managing your compliance at the citation level um to make sure that those requirements are being met within your organization ation so I'm going to jump into the requirement 2.2 for nerp 7-6 and just like in the authority document um you're going to have an overview of that specific requirement or citation uh description as well as the tracking of the overall status and compliance of this specific citation so what service now irm allows you to do is start breaking down your compliance um you know the different compliance regulations that you need to comply with and have them you know into a more manageable manageable and operational level jumping into the details tab you can also get more details around it but what I want to jump into next is the control objective so from a control objective level this is where you're going to start mapping all of those citations that you're required to comply with to control objectives within your internal compliance framework so you might have a control objective that matches to many different requirements in your organization so when I jump into this control objective you're going to be able to see the overview but you're also going to be able to look at from a control objective level what does this comply what does this U map to and how does this map to different citations so you can see that maps to different Authority documents including narip so that you can start measuring you know your compliance um holistically and mapping you know requirements that say the same thing within different Authority documents jumping back to the overview um within the control objectives tab you're going to be able to see you know the different details as well as the overall compliance of this control objective and then you also going to be able to see within my organization what is being mapped to these control objectives and what controls are compliant need to be compliant with what this um control objective is mandating so just jumping into a control really quick for this specific entity you can jump into the control and this is where you're going to really start having that workflow around each control tied to assets within your organization so you can start assigning it out to a specific entity or asset and then that owner of that specific entity is going to be your control owner so they're going to be responsible for making sure that the control is compliant that it's working as expected and they can either do that via manual attestations or they can also from a organizational level you can set up indicators they'll actually go out and you can do um continuous control U monitoring off of that specific control and actually go out and collect evidence that can be provided to your Auditors in you know in the case of for example this install um your critical security updates an important security uh updates in a timely manager you can actually send out tasks to those control owners so that they'll have to go in and provide evidence that they are doing and meeting this specific control objective and requirement for nerp so that was a highle overview of irm and how it can fits fit into start monitoring your controls that are related to ner zip and all the different standards and Authority documents um I think I'll pass it over to Mike next if that sounds good to you yeah that works thanks Megan that's a great overview and I'm following along pretty well so as we start to walk through you know everything that's required to really meet um you know these regulations and and improve compliance and adherence to those as well as really you know secure your entire landscape whether it be in the OT environment or it environment again we we want to think about how this is really a team sport so as we start to think about Asset Management you know which is really 95% of security at the end of the day um as a security professional I want to get out of that business I really want my it organization to manage all my assets for me so I can become a consumer of that data and really work towards identifying vulnerabilities that can be remediated in short order as well as finding exploit activity but that's another conversation for another day so we'll focus on really the asset management and the and the vulnerability detection side of the fence and the way we achieved that is with is is really by enabling our it organization to manage assets both from a hardware and a software perspective and some of that asset management is is a is is achieved by leveraging things like service graph connectors um our iton visibility solution which will allow us to pull in asset information to create configuration items and really manage that that cmdb that configuration management database and some of the ways that that's achieved is with the cmbb workspace so our asset managers and really any subscriber to the service now platform is going to be able to get in and see what new CIS are out there what new applications what new hardware exists within the environment and it really enables any different business unit that needs to leverage this data to get quick insights into both the assets that are being managed as well as some of the governance controls that might be associated with them and really some of the details around each one of those assets themselves now where we draw the Line in the Sand and where this is kind of a a core problem for most organizations is figuring out where OT assets exist versus it assets and again by leveraging different Discovery solutions to populate the cmdb um we're able to detect both those it assets that might contain a Windows Mac or Linux kernel um but also the it the OT estate where other systems are going to exist in the environment that aren't managed by traditional it tools so think of things like Rockwell um you know Honeywell Schneider Seamans these types of devices the plc's the hmis these can all be managed within um the OT technology workspace where you'll be able to see all of your OT um assets and the manufacturing processes and and have things broken down both by equipment model but also by site code right so we're able to see what manufacturing plants are going to contain what assets and what schedules they might have included um to manage downtime associated with those assets because any remediation eort is going to be associated with um you know specific steps and processes that might take a specific system offline for a certain period of time while we perform maintenance now as we get into some of the Integrations um and things of that nature you know we obviously have access to the store where you can search for any integration that will detect Assets in your environment and pull that information in so from the OT estate we're able to leverage tools like Nomi or Clarity um and dragos as a way to pull in vulnerability data with within the OT environment but we could also leverage those tools to populate the cmdb with OT information um likewise on the it side we're able to integrate with tools like tenable or qualis enable to to enable us to to identify detections of vulnerabilities and pull that information into the database now as we start to work through items you know we're really talking about the life cycle of of vulnerabilities that are detected right and that's where we have a vulnerability management workspace that enables a vulnerability manager to track all vulnerabilities detected on all the specific CIS within your environment and all these individual vulnerabilities that are detected right within um a particular scan or integration run as we like to call them those vulnerabilities will all have a unique risk score and a risk rating associated with them that will be tied to a remediation Target rule that really is the clear indicator of what's been prioritized and what needs to be remediated by when and by each user so in order to track the life cycle of these vulnerabilities we've developed developed a workflow that allows us to track individual states right so the vulnerability life cycle is really a Clos Loop process upon data ingestion all vulnerabilities would be moved into an open State and really that first step of automation is to assign that vulnerability to a specific user for remediation and this is that hand and glove approach or that team sport where your vulnerability manager is going to prioritize and assign their vulnerabilities um to specific users and then the remediation owners will will will pick up that workflow and and move them through a a couple streams you know one piece is they might know that they need to remediate a vulnerability by a specific time frame um and if they can't do that for a number of reasons they're going to move that vulnerability either into a review or a deferral state where they can automatically request an extension to that remediation timeline um that's an approval workflow that is native to the platform or native to the VR module that enables the communication and collaboration between the remediation owner and the vulnerability manager the other stream of process is really to take that vulnerability and either move it through Change Control if it's necessary and then resolve that vulnerability as the as the flag to tell that vulnerability manager hey I've remediated this particular um issue and then dependent upon a success of scan will automatically close out that vulnerability if it's no longer detected but if it is we can move it back into the open State and force you back through that state flow now this entire workflow is is is is pretty is pretty simple to follow um you know in practice but there are other ways to go about this um with ner and with SIP 7 specifically we're really talking about not just identifying vulnerabilities but really marrying um the lack of software updates on specific Assets in order to produce a a patch audit report that allows us to know what systems have missing updates so in the absence of a detection technology you can secure your assets just by by making sure you get the the latest um software deployed to those systems that doesn't take so much of a risk based approach uh into vulnerability management but it does provide value at the end of the day and typically what we'll see is um within organizations with our within our conversations with a lot of customers is we're seeing people wanting to produce some type of an audit report that just simply States these are the missing patches on systems and not necessarily detected vulnerabilities it doesn't take into account things like control violations um that might that might exist to offset the lack of a of a patch on a system but the bottom line is when you get into patch management and orchestration we are natively integrated with the national vulnerability database right so we have that ability to kind of pull in all known vulnerabilities that are registered with the MVD and track them and from this perspective we're going to marry those cve to the detection technology to give you the ability to identify you know what a particular risk score may be on an asset with other business context Associated and on top of that we're also able to leverage our solution management component which allows us to identify what vulnerabilities have the highest supersedence right so we can see if we wanted to take this from the from the perspective of what software distribution tasks will produce the most remediation outcomes um with the fewest software distribution events um we can take the you know we can take the hell that way right and that's kind of a little bit of a of a patch management or istration piece where right from within um a a a solution record um you know a remediation owner or even a vulnerability manager could actually go in and and update or patch a system directly from the P platform by scheduling um the software deployment through tools like big fix um seccm or or even tanium and and others you know coming down the path um but as we get into vulnerability management we really want to focus in on our vulnerability man workspace where we've identified all those you know different grouping Logics that different grouping logic associated with um generating what we'll call a remediation effort so if I want to focus on one OT asset specifically um I've already kind of pre-staged this in a way just to kind of make this demonstration move a little bit more quickly but when I have a specific OT asset um I can see the configuration items that might be associated with it you know what class that might be what vulnerabilities maybe may exist on that particular device um and see specifically those vulnerabilities um you know in a list view that will show me each one individually scored um based on our risk calculators that we have what's open what's in flight and really you know who it might be assigned to from here the remediation owner task is pretty simple they're just going to want to create what's called a remediation effort and that remediation effort is really that that that that ticket that allows us to track the work that's being performed by that remediation owner whether they be on the it side or on the OT side and given the type of vulnerability that might be detected it might get routed to a different user um to perform that remediation if it's an infrastructure patch that could be one thing that could be easily deployed if it's a code change that might need to go to a different group to develop an a a remediation and close that out but that remediation effort is really broken down into a number of different tasks and as it relates to nerk or sub seven from a from a vulnerability manager's point of view when I open a specific remediation task I really want to track the overview of that that issue and if there's any policy violations that might be you know um that might be impacted by this remediation effort we'll want to see those those exceptions or those um or those controls that might be listed within that particular assets context and if we can give this a minute to open up let's see if we have a good example one that's open open is a change request so in this case I've already opened a a a change request that's going to be submitted to my change Advisory Board um full review of the the priority of this vulnerability what it is what the implementation plan may look like um and upon approval we can get this into that remediation code So within this change record and this one's actually closed let me pull one that's actually open and if I wanted to create that change request I'll just walk through this process and what you'll see is by leveraging the solution management database if a patch is applicable to this particular issue we'll be able to pull that information automatically in from the national vulnerability database and from the records that are applied so I can actually you know determine if I want to do a standard or a normal or emergency change I can provide a description and a justification and I can even include that implementation plan in that patch deployment by creating that change request um and once a change has been submitted you know it'll really you know go into that um that change Advisory board for review so I will pause here and see if I can kick the ball over to Brandon um to kind of take a look at this um a change request from a change Advisory Board uh perspective and and let's see how the approval process can work from there thanks Mike let me share screen here yes so my name is Brandon Kona I'm a solution consultant here at service now I have the pleasure of playing the change manager role here so approve that coming in here log in as a change manager one of my favorite capabilities of service now is the reporting and dashboard Bo so here we're logged in we're able to view uh some of those reports that are most important to me as a change manager so I'm seeing what changes are open I'm seeing some of the success of the changes and then all this on the right I can change and um quickly filter those reports uh based off those certain fields or metrics that I'm choosing on the right so another just way of drilling in being able to see um what's important to me as a change manager so we're really seeing that um process marrying into the IT service management or the change management perspective if we want to drill into another component here we can really focus in on some of the performance analytics behind what is the success that we're having of these changes so we can look through a a period of time understand those changes so I won't go too far off topic we'll go back to exactly where Mike left off will drill into a change request so this change request has come in um from Mike from that uh remediation that needed to be completed we've created a change and now as a change manager I can come in here and access that we're seeing the configuration item here as we talked about this OT asset if we want to drill into uh a dependency View and understand what could be impacted Downstream um from doing this change request of course we have this view um but really the key value here from the change manager perspective is uh drawing the information using our one data model one architecture one platform to see and make informed decisions uh with when we when we uh carry out these change requests so right away we're seeing that the justification has been brought in that mitigation plan or the implementation plan has been pulled in we have all the details um here so that the change manager can make a decision based off how they want to continue down at the bottom in our related list we have the affected CIS of course that um CI we talked about throughout this demonstration we also have impacted services in CIS but then most importantly we can drill in and look at those controls that may be impacted if I were to continue and uh implement this change request so again uh insights information right here in order to make a an informed decision on this change request let's continue through let's schedule this change we'll schedule it for Wednesday we'll make this one hour long and we'll just take you through briefly the process of what it would look like for a change manager to implement this change so we're seeing a great example here we've put in uh a time this scheduled time is actually uh we're noticing a conflict with this time so we can look at the conflicts we can understand that it is in uh Blackout Window and now we can use our scheduling assistant a great feature here that pretty much offers up times hey select these times this is a better time to to make this change and to be able to uh do this without affecting users uh Downstream so when we say that we're going to see that conflict status goes to no conflict and here is where we can kick off the approval process so up here we're going to move along to the assess stage that top part is a life stage of the change request so now we're moving on to the stage this is where the technical team down here below is going to uh be receiving approvals so this is where Sarah green and Carla Jackson they're going to get approval request to see if they prove from a technical perspective this change being put through since I've got the the power of a change manager I'm going to come in and actually approve that for them to speed things along so now we're approving this change request and the the way we have it set up is if one change is if if one technical person approves it the other one is no longer required and now as you've seen we've moved on to the authorized state so this is where the change Advisory Board is going to review this and go through another set of approvals again we will just approve this for demonstration purposes but we're seeing how we've got from one one place we're orchestrating getting the whole team together and ensuring this change is successful so we moved now past the change Advisory Board now we're in that scheduled phase we're saying hey everything is approved we're ready to implement this change are we set to go I'm going to say of course let's implement this and when we implement this this is where those change tasks are kicked off so this is of course configurable up to your discretion as far as what change tasks need to be kicked off it can be different depending on the type of change request it can be different depending on the CI um however you want to set that up but for this demonstration we've got two change tasks that have been set off and these can be assigned to a specific group to a specific person all automatically we want to make this as hands off as possible um but in order to get this to a closed phase we have have to come in here and close out these change tasks so we're coming in here we're going to open up these change tasks and we're going to assume that they've done their due diligence they've come in through in here and they um complete these change tasks that need to be completed to ensure that this change request uh gets closed out so we'll do that on that one and we'll do this on this one as well and this is where we're able to track um those details as far as what is getting completed to ensure that those controls um and the the regulated um pieces of of this change request is done efficiently and completely so we'll close this out now and this is where it's going to have the final closure notes of the change requests and we'll we'll choose successful and we can put as many notes in here as as we wanted completed successfully and this is where we change out we close out our change requests and we saw the the full life cycle of this change request being able to make informed decisions again because of the information that's right in front of us as a change manager seeing those controls come in um and then of course tying back to the metrics and the reports we saw in the beginning now this is going to be seen there and we can uh make actionable uh steps going forward so I'm going to pass it back to Mike if you're ready and and we'll close out this demonstration yeah I will take the ball back and just to kind of wrap this up you know really from a you know a scanning and a confirmation perspective once that change has been implemented whether it be through manual efforts automated efforts um things that go through Change Control you know really it ties back to a number of different views from EX itive level reporting to manager and even audit reporting right if you have an auditor that comes in and wants to identify what work has been done by who and when and what steps were Tak and this is really how we're going to kind of wrap this up um from a reporting perspective there's a lot of purpose buil dashboards that will roll the vulnerability data from an average time to closure perspective um from a from a ceso perspective down to your vulnerability manager point of view which we showed kind of in the workspaces but you'll understand what some of the system hardening is and and this goes Beyond uh just uh you know Common vulnerabilities and exposures you know again we're we're we're tied natively to the National vulnerability database so we're able to pull in common weaknesses and exposures to highlight some of our configuration compliance adherence right um we're able to pull in uh common platform ination so cpes cwes and cves are really all kind of accounted for in a in a holistic vulnerability Management program and then taking it down both not just within the it Estates but also giving you a perview into your OT assets right so knowing how things are are performing from a discovery perspective to a risk perspective to a remediation perspective and breaking this down by site IDs right so everything gets managed um and and reported up in in purpose belt reports and then you know lastly you know if you wanted to get insights into that you know who did what when and what was it you know there's lots of descriptors around OT versus it Estates and wherever you find that implementation plan you can really see the details of what was done when and by hoop um at the end of the day and this will really give you a One-Stop shop to Output you know all of your audit reports you know to an auditor to to let them know um that that you're you're you're performing your your risk to remediation you know value stream with adherence to um sip seven um compliance requirements um and again it's it's not done with any TurnKey solution it takes a little bit of of all of all participants to to play along in the game and and that's where we touch on within the platform and kind of an end workflow where we leverage things like our software Asset Management ham Hardware asset management change control risk to remediation and vulnerability detection at the end of the day um so hopefully this is a a good teaser into what we can achieve in the platform I'll I'll kick the ball off to Amanda to to maybe wrap us up thank you so much guys really appreciate it um I'm excited to be doing these demos for our utility sector this part particularly seven and 10 is a very complex very difficult process for us to manage in this industry hopefully you got some value from it we have some more demos we're working on specific to ner siip but if you'd like to learn a little bit more um engage with me would love to partner with you and team thank you for a great job on this demo today we really appreciate it y'all have a great day
https://www.youtube.com/watch?v=hiXuPJZDJPQ