SecByte - CISO Dashboard
welcome to the security operations cso dashboard for security incident response vulnerability response using our performance analytics offering for today's discussion we're going to be quickly going through some of the security initiatives on how we can establish better visibility value and vindication on how we actually go through identifying the most critical areas concerns and areas of our attack surface that require immediate attention from the cso persona first and foremost we'll go ahead and start with our overview now in this custom view we have our policy compliance and configuration compliance here we can see the assistive controls that are relevant to this particular compliance initiative that will pertain to the specific assets observables and vulnerabilities across these particular compliance initiatives as it pertains to our configuration here we can see our past our errors as well as failed configuration compliance areas that require immediate attention from machisa's perspective on the right hand side we have our vulnerability response average time to close now in this case we're looking at the mean time to remediation around a seven day running average and by leveraging predictive intelligence we can start to forecast where we are trending in terms of that average time to close vulnerable items within the organization now what's relevant here is having that first field of scope view across the entire landscape of your it infrastructure but also understanding how these assets are being handled in a timely fashion on the right hand side we have our approval requests this could pertain to specific approvals that require executive leadership to approve these requests to kick off executive workflows sub-workflows or specific actions within a controlled state in this particular instance this could be a security incident that requires someone in this case to see so to approve the actual closure of a ticket before final sign off and post analysis recommendations down here at the bottom we have our risk overviews and security incident response average time to respond both of these users are completely customizable and these widgets can be used at any time to be configured for specific metrics and performance analytics reports that can also be pulled natively within this dashboard below we can also go ahead and toggle specific areas for our metrics so as the cso we're able to see the exact information we need at a glance in real time without having to mess around with specific spreadsheets or pulling from multiple data sources rather we have this dashboard to help facilitate and curate the story of successful security posture within the business and finally our security automation labor values and hours saved the proof is in the platform and we're able to calculate the automation as well as operational overhead costs and now we can start to decrease costs around our socket teams and also improve overall team collaboration on our saved which then allows the cso to focus on more higher priority objectives and business positive outcomes now of course this is a high level overview as a cso executive but if we want to get a little bit more details we can also navigate to our incident handling now in this particular view this can also facilitate conversations around security incident backlog growth and prioritizations prioritizing security incidents in terms of specific record values this icon indicating real time that we have 167 p2 incidents versus our 619 priority one incidents immediately we can see the scope and the volume of how well our security teams are performing and start to excavate more information on why our priority one incidents have spiked moving down below we can see our basic security indicators indicating a number of different tables and values across new closed and our backlog growth in terms of those security incident records and those navigating trends now this is one of my favorite views the security incident tree map for two main reasons one we can break this down by business criticality and different categories across your victim stats your assignment groups and also business categories but also the indicators being able to break this down from critical high criticality or non-critical business criticalities immediately i'm able to say we have 41 security incidents tied to i.t specific services this could entail that there is a issue on a specific server an appliance or specifically with a user and this allows me to activate more information and that security incident record and list of all of the records tied to this particular security incident business criticality that has been set to critical from here i can go down into the categorization stats as a cso i want to know if we've had a couple of phishing scam attempts and i want to know how many we've had in the past let's say 30 days well by simply navigating to our categorization stats maybe i want to have the full scope of all the categories that we've supplied within the security incident response form and our service catalog by simply selecting the categorization stats i can see we have a total of 135 phishing security incident records 21 unauthorized access and 12 that pertain to the malicious code activity category instantly i have the results that i need and now i can start to make data-driven decisions moving down the line here we have our assignment stats by groups so now i can be abreast of what my teams are involved with and how many incident records are applied to those specific assignment groups and lastly my victim stats or my repeater founders not only can i see what resources have been affected for the security incidents but i can also look at the specific affected user in question this will help me tailor better performance handling when it comes to further educating and creating a much more manageable and enjoyable experience when promoting security posture within the organization now moving over to our systems hardening as i mentioned before we work in conjunction with the security incident response and vulnerability response product capabilities on the vulnerability response side you also have performance analytics which allow you to look at the same metrics and also excavate some more information around vulnerable items compliance and your vulnerability ids as well as the most vulnerable ci's by class again all of this information is right at the fingertips of your cso and you're able to go and through all the different in all of the different metrics which will give you valuable insights into critical vulnerable items overdue criticalities that might require immediate attention as well as understanding the threat landscape moving back over to our overview slide one of the questions i also hear is how do we actually get here now out of the box there are some functionalities and certainly a number of widgets that pre-populate this information but what if i want to understand where these tables exist so i can create some of these more dynamic reports simply by clicking on the three layered hamburger icon we can go to the launch dependency assessment in this particular dependency view this will break down all of the different categories in terms of all of the different areas that we've covered and focused on today as part of the dashboard discussion as you can see here our top level is the cso dashboard on the right hand side we also have a legend to help navigate us through this particular breakdown here we've selected incident handling and i want to break this down to show the specific table used for the number of closed security incidents and by breaking this down i can actually see that the dependency is based on our security incident table and in addition we can show the schema map we can edit or show who it's being used by so as i see so i'm also able to create reports on the fly and this simply gives me a breakdown of those capabilities and how to assess this moving forward to create my own dynamic reports as well as dashboards moving over to the cso dashboard for vulnerability response is another key area where we can start to focus on vulnerabilities at a glance but also excavate more information as it pertains to the vulnerabilities per asset our mean time to remediate as well as the average age of open vulnerabilities on this particular dashboard we've gone ahead and categorized this by risk rating we also have the option for age range and internet facing and also selecting elements from highest criticality to no criticality here we can also view the services with most vulnerabilities and most importantly countries with the most vulnerabilities based on location so for organizations that have multiple locations or instances you're able to curate all this information in a collaborative effort to understand that particular threat landscape and where the highest risk exists from a location based perspective we can also calculate the monthly remediation efficiency how well is the sock team doing on the vulnerability side for your analysts the proof is in the platform and we provide these particular formulas out of the box we can also see our scan coverage the monthly scan coverage percentages and then our top 10 assignment groups for deferred vulnerabilities versus lowest remediation target adherence now one of the most performant performance driven analytics areas is going to be our recommended actions and as a cso and a variable analyst we'll want to make sure we have the top 10 vulnerabilities right on the surface of what we're looking for so here we can understand the threat landscape by leveraging these recommended actions here within this breakdown table not only can i see the vulnerability and the summary but i can also see the vulnerable items attached to the specific cve when it was published the risk or and of course my exploitation source here we can see the highest impact solutions that are tied to these specific vulnerability solutions and as i scroll down we can see our top 10 oldest vulnerable items and our top 10 vulnerabilities that are most prevalent on our assets within our instance again beneficial information to make data-driven decisions last but not least i've gone ahead and created my own custom tab here on my cso dashboard and you'll notice i have some relevant information that pertains to my specific persona now as to see so i'm also involved with the network and security teams so i'd like to know not only the closed security incidents around the analysis of my assignment groups but i also want to break this down particularly by category so perhaps i'd like to know how many lost or stolen laptops have reported back in october and how many spam sources we've also curated over the last quarter in addition when i'm going through my specific audits i'd also like to know how many users have the itil role or better yet how many super administrators exist within this particular instance common security practices suggest that we should have no more than five to seven super administrators across specific instances so there might be an area of concern here that we might need to look into and adjust some of those access controls based on users groups and roles last but not least i've created a quick widget here that is out of the box showcasing the appliances that i have within my it landscape 26 appliances three switches and four routers that are currently in this instance so immediately i can drill into these and understand more relevant information around those dependencies the observables and how those affected assets tie back to the user that might have some type of votability change management or patch that is pending and this was just a general overview of the cso dashboard for more information feel free to visit our website at www.servicenow.com and we're also happy to provide a full deep dive demonstration with our security operations team thank you
https://www.youtube.com/watch?v=f0dILs1JUsU