


Just like Michael Jackson's last hit, This Is It. After months of preparation for our ServiceNow vulnerability response (VR) implementation, it is cutover weekend. I woke up at 4 a.m. with a dream that vulnerabilities were being manufactured on an assembly line, and I could not find enough Clorox wipes to keep the facility clean. This reflected my fear of causing disruption on our ServiceNow platform, and I quickly reassured myself our trial cutover went very well. As our last rule works its magic in PROD, here is what I’ve learned about implementing ServiceNow vulnerability response.
Understanding your current vulnerability management (VM) capabilities and the maturity level you aspire to achieve is a great first step, and the CMMI and SANS institute vulnerability management frameworks are excellent guides. The VM Module makes leaps in maturity with its ability to automatically open, triage, and close vulnerability tasks, built-in notifications, and its deferral management, false positive, and change management processes. Solutions from scanner tools and third-party sources are incorporated into vulnerability tickets. There are also multiple out-of-the-box dashboards through performance analytics. Organizations manually managing VM processes are great candidates for VR.
The biggest barrier to entry is an unreliable CMDB. Assets must be in the CMDB for VR to work. If this does not yet exist, a strong leadership champion should be in place to increase CMDB's health. Asset metadata should contain an assignment group, support group, and approval group and ideally be mapped to applications to maximize routing effectiveness.
ABC
‘A’ stands for application project. Especially if workflow customization is needed, you will need to think through how to manage scope, funding, requirements, testing, environment promotions, change, release, training, communications, and platform governance requirements.
"A strong VM program is all about stopping cybercriminals."
‘B’ stands for business workflow. Document the process you want to achieve and work with your implementation partner to assess methods for achieving your goals. The product documentation and ServiceNow demo environment are excellent resources to get started.
‘C’ stands for customization. While VR is highly customizable, customizations can be time-consuming to develop and test. If you are fully implementing out-of-the-box, VR can deploy in three months, but this timeline can greatly increase with customized functionality.
ServiceNow is here for you. There is a helpful two-day ServiceNow VR implementation class, and there are many best practice sessions for VR practitioners that deep-dive into various features each month. Best of all, their customer support team is amazing and has always made themselves available when requested.
Picking proven and lovable implementation partners will have a significant effect on the success of your program. The IBM XForce team has deep expertise not just in the configuration of VR but also in incorporating the XForce Red threat intelligence tool to fine-tune a company’s risk profile. Most configuration work affects the integration setup, connecting to scanners, and ensuring tickets are generated correctly.
Workflow development supports processes like change, unassign, reassign, deferrals, exceptions, and false positives once the configuration work to create tickets and vulnerable items is complete. We leveraged the ServiceNow implementation team, which refined our workflow and provided options for custom processes. They quickly translated our business process and requirements into actionable and elegant solutions to enable our organization.
The best part, our two partners worked beautifully together in parallel during our implementation, shaving months off our timeline since there is little overlap between configuration and workflow development work.
A strong VM program is all about stopping cyber criminals. Proper role and access management to sensitive vulnerability is a must, and a clear strategy must be established with platform governance for the handling of vulnerability information between environments. Lower environments are often more permissible than production, and this consideration should be factored in for your program team members, leadership, VM team, and remediators.
Don't Stop 'Till You Get Enough
Keep planning until you have high confidence in your implementation. It prevents nightmare scenarios (and nightmares), so it’s important to manage testing, training, and deployment strategy well. A test case should exist for every requirement, all critical test cases should pass, a detailed implementation steps plan should be created, and a trial cutover to a mirror production environment is strongly recommended. A cross-functional pilot team and targeted training will enable adoption. These steps will give you the confidence to go into your cutover.
I Want You Back
This is the first step in our ServiceNow SecOps journey. SecOps contains many powerful integrations to explore, which weaves solutions together seamlessly. It allows for the simplification of the remediators' work, and there is no platform more powerful for simplified visibility and management of remediation tasks. I have only fangirled three things in my life- Michael Jackson, ServiceNow, and Star Trek. We will have to save Star Trek for another article.