logo

NJP

Get Started With Security Operations Applications

Import · Mar 04, 2024 · video

all right welcome everyone thank you so much for taking the time out of your day to join us for this webinar today on getting started with security operations applications I hope you're all doing well and thank you for being a security operations customer so I'm Sarah wood I work in the outbound product management team within security operations at service now and I'm located in New York and I'm excited to be joined by Jamie jacks today who will introduce herself now hey good morning everyone my name is Jamie Jackson and I am a product success manager in the security operations space here and I'll be assisting uh service I mean Sarah once we get to the piece of uh around the implementation best practices so it's great to be here and nice meeting everyone thanks Jamie and we're also happy to be joined by a team of subject matter experts uh here to answer any questions you might have throughout the session as well as during our dedicated Q&A at the end so we're really all here to support you in your implementation journey and please ask away in terms of any questions that you might have now we aren't planning to cover any forward-looking statements but in case that does come up our standard Safe Harbor notice does apply to this presentation and today's webinar is part of the live on service now events program so we do encourage enage you to keep an eye out for future events and register for instance we have a security operations office hour session coming up in March it's an open forum for you to get your questions answered by the product management team and other subject matter experts so please do register if you're interested in that and we also have a series of best practices and roadmap webinars that are posted in the community regularly so we'll share the link to those in the chat as well and before we get into the agenda for today I just want to remind everyone that we are here to answer any of your questions so please do use the Q&A button in Zoom at the bottom of the screen there to submit questions and they'll either be answered there or live at the end of the session and it is a recorded webinar so we will share the recording afterwards in the community and uh lastly you'll receive a quick survey once we close out the webinar and we would really appreciate it if you could take a few minutes to complete that just so that we can get your feedback and improve for next time all right this is our planned agenda uh most importantly we want you to come away from this with a clear idea of your next steps towards your implementation and resources to help you get there so really our goal is to support you and provide you with relevant resources to help ensure a successful start to 2-year security operations implementation and in this first part we'll do a quick overview of security operations and highlight some Key Resources if you or your team members want to dive in deeper but before we do let's launch the first poll uh we'd love to hear from you you should see it uh pop up on your screen we want to know what are you planning to implement in your organization so let us know by answering the poll so it might be security instant response vulnerability response both maybe something else we'd love to hear all right so looks like a lot of people planning to implement both which is great excellent all right we'll close that out okay so getting into a quick overview here um as many of you will already know the security operations portfolio includes a suite of products that fit into these two broad areas so on the one side we have the ability to respond to vulnerabilities across Cyber attack surfaces and this is largely achieved through our vulnerability Management Solutions including vulnerability response as well as application container VR and as you can see this covers a range of areas which are all addressed through different product offerings and on the other side we have the ability to respond to incidents across Enterprise security functions and this is largely achieved through our Enterprise security case management solution which is security incident response and within that we also have our threat intelligence solution uh data loss prevention incident response major security incident response and more and within our security incident response products we really unlock Automation and workflows that enable you to respond to incidents faster and this is a high Lev view of what that process sort of looks like so by integrating your various you know security and Sim tools you have one Central system of action to view and prioritize alerts along with that native connection to your cmdb within service now allowing you to understand service business context and prioritize security incidents and next the ability to integrate with threat intelligence tools helps to enrich those incidents and better organize and orchestrate response actions and direct those responses right from within sir followed by posst incident workflows like completing configurable reports and on the attack surface management side side we have vulnerability response which gives you that visibility prioritization and automation of vulnerabilities across the Enterprise and this starts with integrating scanners setting up your vulnerability calculators and assignment rules to enable automatic risk scoring and grouping of vulnerabilities as well as assignment to the right teams across security and it and in addition we have solution recommendations and Patch orchestration as well as workflows for reassignments and requesting exceptions and deferrals which can connect with our own service now integrated risk management solution as well and lastly rescans can confirm whether vulnerabilities have been remediated and Clos them out so we really feel that understanding security operations is an important early step in implementation so that the right outcomes and functionality can be prioritized so these are the resources we think will help your team get up to speed and remain informed about cops applications so we'll have many more resources throughout and we will share them uh the links are in the chat so that you can browse them at your own uh at your own Leisure so first off we have product documentation which is where you'll find all the latest product information and release notes as well as other helpful content like setup guides and instructions on learning about entitlements and then we have our community YouTube channel so there are a ton of videos across YouTube and these particular channels are a go-to resource if you want the latest and greatest uh demo videos for products uh and any other live on service now content uh next we have our now learning platform so this is where your team can use learning credits towards virtual ond demand or instructor-led courses and also obtain certifications so we have regularly updated SE Ops fundamentals course and sir and VR implementor courses as well as relevant different learning paths so I have also created a community post that you'll see here which includes links to a whole bunch of recommended training for SE Ops and we'll share that in the chat as well and then we have our security operations community and this is really a central hub for SE Ops users around the world where you can share resources and best practices and post questions to get solutions from service now experts we also regularly post articles and blogs there about the product and upcoming webinars like this one so we do recommend that you and your team subscribe and get those updates regularly and our quick start guides shown here as well uh for VR and S are a really good reference at this early stage there's lots of helpful links within there in terms of getting started with these applications and lastly in this section is our developer sites so this is our developer ecosystem which is a great resource for any of your more technical team members but really it's open to all levels of individuals and it has more detailed technical documentation uh it's also where your team can sign up for the free developer program where they can collaborate with other service now developers and gain access to a personal developers uh sandbox instance where they can download service now applications and experiment with the now platform so another great resource to check out all right so next up we do want to spend a bit of time on why you should begin your implementation if you haven't already and what kind of value you can expect to see by getting started so we're going to open it up by launching another poll we do want to hear from you again we want to know what are the top desired business outcomes that you would love to achieve with your security operations implementation so might be more related to the security incident side vulnerabilities um maybe some other ones that you can feel free to um add in the chat I think I might have seen someone's hand go up but feel free to post your question uh in the chat or in the Q&A all right couple responses still coming in so I'll just give it another few seconds there before closing that out okay so lots of interest across the board and uh that's not a surprise to us now the good news is that you can certainly achieve all of these things depending on your priorities and our customers certainly have been able to achieve these types of results within just six months of going live with security operations products so we want to highlight a few of these here um for instance analysts closing almost two times the number of security incidents on average at just six months of use usage uh really amazing results and cutting meantime to vulner to remediate a vulnerability in half in just six months and our best-in-class customers are achieving uh even greater results so these are the types of things we really want to help you achieve and we're here to help you achieve and we've been through it ourselves so we at service now are a customer zero so we moved from using manual labor intensive processes to respond to vulnerabilities uh to using vulnerability response leading to over 99% accuracy in assigning vulnerabilities High SLA attainment and 85% gain in productivity so really really great results on the VR side and when it comes to SI or security incident response our internal security has gained a lot of value uh in moving from manual processes to being able to prioritize alerts and automate processes leading to over $800,000 in Staffing cost savings and thousands of hours saved so again we at service now are active users of our product and we are continuing to implement new functionality and Achieve even better results every day now to get to those types of results uh setting your vision and outcomes is a really critical first step in your implementation so these are just some examples of the types of outcomes that you can choose to prioritize in your security operations implementation and many customers will choose one or two outcomes that relate to their particular key challenges in order to prioritize those for their implementation and be able to select appropriate metrics to measure their success um and really get to Value quickly and so there are a number of resources on now create that will share that Jamie will be speaking to shortly which include information on these outcomes and metrics that you can also reference and so as you continue to explore the value that you can get out of security operations applications and create a vision for your organization these are some of the resources that we do want to highlight for you so first and foremost the customer success Center is really really your One-Stop shop where you can search across all service now resources uh find leading practices resources different tools and calculators uh events Services all sorts of things learn about the now value methodology at service now which is a framework to Envision create and validate value from your service now products and Champion your success so that's a great hub for customers to go to the value calculator is a resource that you'll find there in the customer success Center that's worth calling out because it is a quick and easy way to see the annual business value that you can achieve using service now so it allows you to calculate the value of using multiple different solutions or just focusing on security operations uh like is shown here so just asks you a few questions where you can um fill out the answers or move the sliding scale along to to see uh what the estimated annual value is next up what if you have service now impact so this is an acceleration Tool uh to accelerate value really maximize the value that you get out of your investment with service now there are a range of packages that have different offerings and so this slide shows a little bit more detail around the possible offerings that you might have or you might be interested in and so this is essentially the total package with the full range so you'll see things like having a designated Squad having um different value recommendations added technical support and special discounts on things like training and expert Services if you are interested in more information about service now impact you can reach out to your account executive or your customer success manager now getting into the next section I will be handing it off to Jamie shortly to provide more context on the security operations implementation Journey but before that we are going to launch our final Poll for today's session and in this poll we would like to hear about your implementation Journey so in terms of where you're at in that Journey um are you implementing implementing now or in this quarter we're planning to implement later in the year or maybe nothing planned yet let us know see some responses still coming in all right so most people planning to implement now and some people planning to implement this year a few not not planning to implement that's that's fine we hope that after this webinar you will have some more resources and uh get started with your implementation all right I will hand it over to Jamie Jackson now all right so we're going to go through this qu kind of quickly so we can get to the Q&A but it look like we have about a 5050 implementing soon and implementing now for those that have not started the implementation you have a couple of different ways as you see on the screen to go about doing that um preferably with an implementation partner or even the service now expert services that we provide uh which will help you through that implementation and we'll show you how to get to a partner that has security operations experience and then obviously through our expert Services as well self- implementation if you don't have the budget to hire a partner and you want to do it yourself it can be done there's a lot of risk involved with that um your people need to be trained and so on and so forth all those all these artifacts that we provideed you are just going to be that much more important um but just know that it's it's success is usually defined by having some sort of implementation assistance all right next slide all right so depending on how you guys are going to you go about implementing security operations and it looked like most of you are implementing both of them so what's the priority there you implementing vulnerability response First Security instent response first or perhaps both of them in parallel if they're separate teams it doesn't really matter um it just depends on what the organization's priorities are and how you guys want to go about doing that um within vulnerability response there's two primary sister applications to that which are included with application vulnerab response as well as configuration compliance which gives you the ability to not only import your vulnerability scans but those compliance scans that come in so depending on which one you go to um you can start with one or the other or both at the same time and then move up to application VR configuration compliance and then security incident response has a plethora of other enhancement tools to leverage as well like threat intelligence major security incident and so on all right next slide all right so this is a very very highlevel uh road map of a maturity model however this is really subject to your current state of how you guys are running vulnerability response in particular what we're talking about here so if I was to go into an implementation the very first thing I would ask is what are you guys doing right now are you guys just sending out spreadsheets to your folks to do uh vulnerability um tracking or whatever it may be or maybe you have some other tool that you're leveraging how are you assigning out vulnerabilities at this time how are you tracking risk acceptance and then based on what your current state is um as Sarah mentioned before let's define five key performance measurements or metrics that we can say okay in six months I want to be able to do this and be able to provide leadership a better Enterprise view of risk and provide some Roi on the tool itself whatever it may be so again this is totally subjective to where you are at right now high level and this is not only vulnerability response in particular is not only a maturity of vulnerability response and vulnerability management as well it can also affect the cmdb so we know that they go hand inand together so vulnerability response is going to force the hand of the cmdb to get it up to kind of speed and where you want to be in the cmdb in in parallel to the vulnerable response can be one of those goals all right next slide security instant response same kind of concept however with security inant response if I was to walk into an implementation the first thing I would ask is where are security incidents being generated from we know that there's a whole plethora of sources that a security incident can be created from everybody thinks about the Sim and alerts and events coming from there but they can come from multitude of other places they can come from a normal incident being escalated to a security incident they can come from a catalog item they can come from an email they can come from multiple different ways so what are the sources of my security incident that I'm going to start with in particular and maybe it is just your sim or maybe it's just an escalation or maybe I'm going to put some catalog items on my portal to report security incidents or whatever it may be so based on where where a security incident can be created again current state will then essentially adopt the maturity model based on your based on that and this is just an example very very high level um typically on the first step we we integrate with a Sim to start out with we're not doing for orchestration or anything of that nature um and then we Define a handful of playbooks what are the majority especially because response time is one of the key metrics that everybody wants to improve on and playbooks are going to get you there what are the what are my steps or what are the incidents that my security analysts are you doing every single day what's the volume of them and let's get a Playbook and automate this as much as possible so it's very minimal manual input to it all right next slide and this is a very very busy slide but these are all those details again those first couple of uh slides itself are very very high level here are some details on what you can actually look at from a step one step two so for instance with vulnerability response you can say okay I'm going to import what am I going to start with here am I going to start with what am I going to import from the scanner am I going to import my business critical systems my infrastructure um my my highest risk stuff internet facing what am I going to actually start with to import into this into service now and the very next question you should ask is is that data in service now right currently is the is it in the cmdb is has it and it's not why isn't it is Discovery not running or is tenable or rapid 7 or whatever it may be going to be the source of record and populate the cmdb with it so those are some items that you need to think about on as far as where you're going to start and then move forward from there what does my risk acceptance process look like can I Implement that in the in the tool to get started with or do I need to skip that to the crawl and walk stage and so on and so forth again all of these um will be available to you and uh we have tons of links around this as far as artifacts go to get you guys started but the key thing here is to define those metrics as Sarah said once you get started so you can point to Something in six months and then move to the next step all right next slide Sarah same thing with security instant response so what are those initial um initial playbooks I'm going to implement what are those initial sources that I'm going to implement for security instant am I going to have escalations from an Inc to an sir I'm going to have just alerts coming from my sim am I going to have catalog items where people can request or report security incidents or whatever it may be the source is there and then the playbooks associated with those types of security incidents how many am I going to have playbooks are going to drive the resolution time or in half essentially so you want to make sure you get those going and then you can provide metric tricks on the actual implementation time all right next slide so next thing we're going to go over and I'll have Sarah do a mini um demo on how as far as how to get to a partner and service now or expert services and now create for that matter um if you already are working with the partner totally fine if you don't have a partner or even if you do have a partner and you haven't started implementing one of the big things to identify is if that partner obviously has the security operations lines or if they have experience with that and they have certifications around that so we know that they have implemented this stuff before so Sarah can you go ahead and go through that and show them how to identify a partner yes I will do that now I'm just going to pull up the Partner Finder so this is the landing page here and um as you can see you can search directly for a partner if you choose or you you can follow the guided steps here with the get started button so once you do that you could choose from a range of different options in terms of the type of partner that you want and in this case we'll take a look at our implementation options and then you can narrow it down to specific regions as well and then you can select different product areas so we can choose vulnerability response and security incident response here and then we get our results so a range of we can see over 200 Partners here for specializing in vulnerability response and security incident response which is great and then the nice thing is you can actually view a detailed partner profile for any of these partners that come up and this is where you know Jamie was mentioning you can get into the actual certifications of the partner you can see the customer satisfaction on other implementations contact them and as you kind of go through the details you'll see different you know achievements in terms of number of deployments um again different certifications that are relevant so really great tool um I don't know if you wanted to add anything Jamie no no no just this is perfect just wanted to hone in on that to make sure that when we are selecting a partner we're selecting the partner that has the qualifications for doing it um and then obviously if you move to service now expert Services that's another option as well so I'll pull that back up so we've got expert Services here and then in addition to to implementation so before we go further right there implementation obviously we're going there we get it done we get the implementation going we go live or on our crawl stage or whatever it may be we all know that that's not the last step in the process it just doesn't turn on and work till the end of time there's post go live support for some extent that's where impact would come into play to help you guys continue to mature the product continue to mature your processes or some sort of go live or posto live advisory support whether that's from a partner service now or whatever it may be those are available to you as well and then lastly on the now create so if you're wondering if you've worked with a partner before if you worked with service now during implementations this is essentially the methodology that we leverage to do the implementations you'll essentially see how it gets started with the build process documentation or workshops creating the stories every single step in the methodology is in this now create so if you're wondering what your partner's doing at what step they likely follow something of this nature you can go in here and we have artifacts available to you guys and to them to leverage for process documentation like starter stories everything and anything you can think of is in these now creat so this is a really really great um powerful repository of a lot of artifacts all right next next slide and here's a summary again more more resources as far as uh what we can leverage this I want to call out real quick the SE Ops Community um the community site is fantastic there's a lot of folks in there I when I was learning service now especially security operations if I didn't know a question or I had a problem I went in there and searched and somebody had already done it or already asked that question it's almost inevitable and if not everybody's really um responsive so you will get a response in there so take advantage of that community site as it's very active yeah great point and then before we get to our dedicated Q&A portion we did want to mention our knowledge event coming up May 7th to 9th in Las Vegas so if you're not already aware this is an exciting annual event for our customers to come together and share knowledge best practices Network and attend training and other sessions so I believe the early bird deadline uh to register is tomorrow so please do feel free to scan the QR code um to learn more and to register if you're interested thank you all so so much once again for joining us today uh please do take a minute to complete the survey that will pop up after the webinar is closed out and we look forward to seeing you at future events have a great rest of the day

View original source

https://www.youtube.com/watch?v=c6jOJoLpqQo