Introducing Security Posture Control
greetings and welcome to security posture control security posture control or SPC is a new offering from service now security operations to help your vulnerability remediation managers and information security analysts gain better visibility into their organization's critical asset hygiene with security posture control you can accelerate your responses to reduce risk and remediate your most critical vulnerabilities and misconfiguration security posture control will work with your existing security Integrations in vulnerability response to help you attack the big rocks that plague vulnerability analysts and Remediation managers do we have endpoint protection on all our devices that need it are all our devices managed are those devices covered by vulnerability scans are we aware what the critical vulnerabilities are on our highest risk devices and what are the top three security gaps on these devices deves the key insights widgets shown here are powered by outof thebox policies and help you address these questions and give you visibility into how your organization is doing let's drill down into one of our out-of-the-box key insights in this case which devices have endpoint protection coverage here we can see the list of devices that failed configuration compliance tests resulting in these devices being reported as non-compliant we can view one of these test results to see why it failed here we can see that this test failed because it was reported by Dino Trace but not seen by crowd strike from the workspace you can also drill into your key use case coverage to improve your visibility into your organization security posture like detecting assets with missing endpoint agents here is where we can see our organization's connectors and policies for this use case and easily filter for those that are active or inactive these are outof thebox policies that must be enabled for this use case but custom policies can also be created to meet the specific needs of your organization let's take a closer look at policies there are several outof the-box policies included in security poster control such as assets missing endpoint protection and assets not scanned for vulnerabilities policies can be activated for a range of use cases allowing your organization to better understand and priori I misconfigurations and vulnerability remediation for instance focusing on assets with critical vulnerabilities missing endpoint protection internet facing or combinations of these issues the conditions of this policy look for assets that are not reported by the service graph connector of the category endpoint protection and are reported by service graph connectors in any of the categor shown Below in addition conditions can be created for combination policies for instance assets with critical vulnerabilities and missing endpoint protection findings are published as test results in configuration compliance allowing organizations to leverage configuration compliance to automate remediation of findings efficiently by assigning them to the right teams prioritizing and tracking remediation let's now dive into an easy way to create policies for your organization asset search asset search allows you to create policies by first searching for your devices we're going to fill out this asset search with a few parameters in this case we want to know via devices connected by rapid 7 all assets that are running Windows as an operating system and have critical vulnerabilities that are not reported by crowd strike and point protection this returns several devices that we can see meet this query criteria earlier we saw that we have a series of out-of-the-box policies if we want to create a custom policy around this asset search that is possible with security posture control by returning to our asset search we can convert this search into a policy let's do that now and give it a fitting name description and save it as a policy policies are not turned on by default and they must be activated before security poster control can monitor the assets that match the policy once you activate a policy and data is collected on it with security poster control you can display the data on the custom insights dashboard custom insights and security poster control enables you to configure customizable insights for greater visibility into your organization's envirment here you can choose from a range of insight types for instance we can see how a policy match percentage chart widget can be configured to view a comparison of the assets matching the selected policy we can also use other widget types such as policy match count comparison chart and policy match Trend chart to configure the insight as per our organization's requirements by creating this policy match percentage chart looking at assets with critical vulnerabilities missing endpoint protection we can gain quick visibility into our risk posture these graphs can be easily configured for the policies your organization enables for security posture control security posture control also works together on the now platform with your vulnerability response application let's look at vulnerability risk calculators for an example vulnerability response uses risk calculators to calculate risk scores on vulnerable items in your environment with security posture control you can use your SPC policies to create risk calculators in this case we've created a calculator that takes the result from the SPC policy asset missing endpoint protection and automatically attributes a risk score if the asset does not have endpoint protection as an organization we decided to make sure these are considered a critical priority so this calculator returns a score of 95 for those vulnerable items Rising them to the top of our organizational awareness you can even map SPC policies to governance risk and compliance control objectives so compliance managers can gain quick insights into their risk posture we hope you found this tour of security poster control valuable with security posture control helping you improve your visibility into your Enterprise asset inventory and address your most critical security gaps you will be able to better Harden your digital attack surface and protect your overall organization security thanks for watching
https://www.youtube.com/watch?v=5pZE1IBCXWE