Transcript
solution. I'm Aziz Kapadia, Field CISO at Zscaler for the Risk Management Solutions. As Andy and Adam highlighted in the keynote, companies have too many vulnerabilities to ever fix them all. The prioritization step is a crucial component of Continuous Threat Exposure Management or CTEM program, so you know where to focus your precious resources. Our UVM solution provides three key advantages, and I'll show you all three of them in action. Customizable risk prioritization, UVM provides an out-of-the-box risk calculation that combines your risk factors and mitigating controls to prioritize which exposures you should fix first. You can also adjust these calculations to fit your company's metrics and needs. Automated workflows for remediation, UVM integrates with Jira, ServiceNow, or whatever ticketing solution you need to get these fixes over to the right team with an automated two-way synchronization. And dynamic reports and dashboards, so UVM provides out-of-the-box and easy-to-build custom dashboards and reports, always running off the aggregated up-to-date data to track your vulnerability management program, including metrics like SLA reporting and other board-level metrics. Let's take a look. Let's start at the top. The journey begins with the data coming in. Unified Discovery is actually step two of CTEM, so let's take a look at how we bring in that data. First and foremost, we've got 150 connectors out-of-the-box. We've got threat intelligence feeds, cloud data, application security data, vulnerability data from infrastructure sources, user data. Whatever data you want, we're going to be able to support it. If we don't have a connector out-of-the-box, no problem. We always have the AnySource connector that can bring in data from virtually any source, as it says in its name, AnySource. Now that's not the key here. The key here is how we model that data. So let's take a look at a sample connector and see how we can bring in your vulnerability data, your asset data, and any other contextual data that's relevant to your program. So very cool screen over here. You've got all your data sources on the left-hand side, and then you have your model right here on the right-hand side. Very simple, easy to use. Everything's in the UI, so if you needed to add an entity, no problem. You simply click on the button, put in the entity name, and off we go. If you needed to add a custom field, no problem. You simply click on that button, and you can add any field you want to your data model. Now once the data is in the platform, it's a matter of having the right policies for scoring, for grouping, for SLAs, whatever you want to configure as part of your workflow. So let's take a look at how we manage your scoring. So here's the scoring configuration. You've got your base score, which has got CVSS, EPSS. You can even bring in your original severity score. Even if you have your own custom score, you can bring that in to define that inherent risk for a vulnerability. You could also bring in all kinds of contextual data, whether it's a risk factor or a mitigating control. Risk factors can include asset data. It can include compliance data, any kind of business data, user data, whatever's relevant, right? So if you wanted to identify a user that's clicking on phishing links as part of your simulation exercise and bring that in as context, you can do that. We also have integrations to all kinds of mitigating controls, EDR, ZIA, WAF, whatever you need. Very simple, easy to configure, but we have several out of the box. And if you wanted to adjust the levers, you can absolutely do that over here. Now once you have this configured in the UI, you simply go to the findings to see the results. So here's a list of all my findings. I can search for whatever I want. In this case, I'm going to do a search for Apache, a very common vendor that we use in many organizations. So here's a finding for Apache Tomcat. Let's take a look. You could see all of that contextual information right there in front of you. This asset's got EDR. It's got critical sensitive data, PII data. It's associated with a critical application, so the business criticality is high. We could even understand what specific vulnerabilities are blocked by ZIA and show you that risk reduction right here in the UI. So this is done dynamically across all of your findings to give you an accurate risk rating. Now the next step is to help you operationalize it. So first, let me show you what it looks like from an asset's perspective. All of the findings are going to roll up to the appropriate asset. In this view, you can search for any asset you want. I'm just going to show you quickly what that view looks like. You have all of your details about this specific asset right here, ownership information, association with any applications, any findings that are related to it, any tickets that are created for any kind of remediation. But here's something really cool I want to show you. Let's look at this visual explorer. So for this specific asset, I can cleanly visualize everything that's associated with it, findings, assets, applications. You can see all the different entities that are associated with it. So check out all this metadata that's available for all of your assets. Nogood's going to touch on that as part of the exposure management piece. Now let's go into operationalization. Over here, you can see all of your findings grouped together in the remediation hub as tickets. What we do is actually take in all of your data, and then we group things together logically based on their best fix, based on similar patches, based on similar findings. So the outcome is very effective and efficient for your remediation teams. You could simply see all of the metadata that's associated with this remediation action. You can see all the findings that need to be resolved. And if you drill down into the findings, you can see all the contextual information that we looked at earlier. critical business, protection by things like ZIA, all of that is relevant here and is available to your remediation teams and for the stakeholders. You also have all the asset metadata available here, so you know exactly which assets to apply these fixes on. And then you can simply integrate with whatever ticketing system you have. In this case, I've got a ticket created with ServiceNow. You can actually map all the processes as to how you have it configured in your business process. You can also manage things like exceptions, false positives, so on and so forth. All of this is possible because of our out-of-regulation capabilities. I'll show you an example of what that configuration looks like. Here is a JIRA instance. You can see that you have all the fields that are relevant to you and your ticketing system on the right-hand side. And then everything is simply mapped over here based on your workflow and processes. Now the next thing I'm going to jump into is reporting metrics and analytics. As you know, that's step five in CTEM, mobilization. Let's look at some of the out-of-the-box dashboards. This is a very cool dashboard that shows you key metrics over time. You have a ton of active tickets organized by the criticality, different statuses of tickets. Maybe some tickets are open, but no one's really taking action on them. You can quickly identify that, and you can see how your different teams are performing. You can leverage this for gamification throughout your organization. You also have this really cool risk dashboard, a nice visualization of key metrics such as your risk over time. Now every organization identifies the way they calculate risk differently. You can report on average risk, max risk, even risk mass over time. I personally like max because you're only as good as your weakest link. Now you can see all of your findings across your sources, across your asset types, based on severity levels. And again, you can see the performance of your different teams, but you're not limited to that. You can pivot in any direction you want. If you wanted to look at your most critical applications, no problem. Simply type in application name, click on it, and off we go. Now you can see your top applications in your organization, the number of resources they have. And then if you really wanted to click into it, you could also see what kind of progress they're making over time. You could also build your own custom dashboards as you need to do so. Let's take a look at some examples. This is a very cool dashboard that took me about 15 minutes to build. It shows you your risk mass over time. It shows you your risk mass broken down by different applications, number of active tickets, critical open tickets. It even has cool metrics like mean time to remediate. You've got to understand every organization calculates MTTR differently. Some like it to start when the vulnerability is identified. Some like it to start once the ticket is dispatched to the remediation team. No problem. We can support you with whatever needs you have. Everything is customizable. We have tons of measurements that are out of the box, but you can also build your own measurement as needed. And then you can leverage that measurement to build any dashboard or widget you want. You can choose pies, bars, trends. You can choose any kind of dimensions you want, whether it's time or assets or applications and tickets. You can have it all in one widget to give you the exact outcome you're looking for and build pretty dashboards. So contextual prioritization, automated workflows, and customizable reports. These are the ways that UVM provides a great foundation for your C10 program. Our asset exposure management solution that Noga showed you can be a great feed into UVM and both of these solutions could be a great feed into RISC-360 to make your risk quantification more accurate. We are so excited about our growing exposure management platform here at C-Scaler. We would love a chance to see how our family of capabilities can help you build an effective C10 program. Thank you again for tuning in.