Hello, this is Nick Holland for Information Security Media Group and I'm joined today by Bryce Schroeder who is the Global Security and Risk Practice Lead at Service now. Bryce, thanks for joining me. Oh, thank you Nick. Appreciate being on the call.
It's a pleasure to be here. So we had a fascinating roundtable discussion in Toronto a few weeks ago. The subject was moving from vulnerability management to effective vulnerability response. I want to ask you first of all though, but what do you see as the essential capabilities for effective vulnerability response?
Sure Nick. So first off, I mean I want to contrast vulnerability management from vulnerability response. So if we look at vulnerability management, certainly scanning devices, knowing what their exposure is, how prevalent that exposure is across the environment and how severe that exposure is, and categorizing that as vulnerability, critically important. That next step is where we move that response component in.
Knowing the importance of the business level of the particular asset or device that that vulnerability or exposure is on, being able to aggregate that across a business service model where I know devices talk to each other, these all are connected in this service element. If any one of these goes out, I lose that service piece. That's where that step from management, that advice layer to that response piece of knowing how it impacts my business, and then taking that prioritization step of understanding at a risk level, all of those exposures to each service, and then applying that visibility to responding quicker, prioritizing which things I respond to, reducing the things that I don't respond to. That's where we get into that key response model.
Being able to not just track and prioritize what I remediate, but actually prioritizing that in a way that affects my business for one way, and I hope that helps clarify the two. It does, thank you very much. What we got into talking about was the importance of linking risk, configuration items, and vulnerability. Could you provide some clarification on that as well?
Sure. If you look at what happens to you, a lot of security professionals get very confused about the term configuration item. It's fundamentally a device or asset, and some configure item that's on it, but not a certain discussion. But really, is that a particular application package or a platform operating system, what is that element that I can actually touch, feel, change, or modify?
It's really a way to define modifiable elements of an asset, whether that's at a software or hardware level. That's really kind of the connection. If I move that more into vulnerability, I now have the ability to classify configuration items according to their level of priority to the business. Again, back to that conversation we had about vulnerability management versus vulnerability response.
I want to say, hey, if I make these changes, whether that's a CI for vulnerability with a patch or configuration item where I change a config, how does that change my environment? How does that make it better or regress it negatively? That's that common understanding really between how security and IT view change. That's really the core of that configuration item, especially when I attach vulnerability or exposure to that CI.
And then, I think, just finally, we had a good conversation over dinner. What were your key takeaways from the attendees? What did you learn from the discussion, Bruce? Well, first off, it was fascinating because, just to acquaint the folks who were listening with who attended, we had a wide variety of attendees between financial teams in the Toronto area, along with manufacturers, a mining company, governance agencies, so a wide panorama of different use cases.
Yet, the discussion was fascinating to me in that it all focused really around risk and risk at a business impact level. Again, each one of those businesses, whether financial or governance or manufacturing, had a different categorization. Again, manufacturing was really focused more on safety or keeping their line up. Financials was data integrity from their risk standpoint, but the core of how they quantified risk, how they wanted to see visibility of that risk, and how to set alerts so they could respond in a real-time proactive fashion to risk thresholds.
That was the core of the discussion that I picked up, and it was fascinating to me because it broke down the barriers between each of these industry-type of segmentations, and really came to the core of the middle of the meeting for the session we had. I agree with a lot of commonalities there, despite being from very diverse silos. That was key takeaway from me as well. Well, Bruce, I enjoyed the event, I think you did as well, and look forward to continued conversations on effective vulnerability response.
It was a fascinating topic. That's Bryce Schroeder, who is the Global Security and Risk Practice Leader at ServiceNow, and for Information Screen Media Group, I'm Nick Conant.