<h2>How to Engage the ServiceNow Security Office (SSO)</h2><br/><div style="overflow-x:auto"><div style="font-family: Arial, Helvetica, sans-serif; display: flex; align-items: stretch; flex-wrap: nowrap; width: 89%; background-position-x: initial; background-position-y: initial; background-size: initial; background-repeat-x: initial; background-repeat-y: initial; background-origin: initial; background-clip: initial; background-color: #032d42; height: auto; min-height: 90px; padding: 10px 0px 10px 0px;"> <div style="font-family: Arial, Helvetica, sans-serif; color: #ffffff; margin-left: 10px; min-height: auto; flex-grow: 1; flex-basis: 100%; position: relative; left: 10%; max-width: 85%; padding: 10px 10px 10px 0; background-repeat: no-repeat; background-attachment: scroll; background-size: auto; background-image: linear-gradient( 0%, 100%);"><img style="margin-left: 10px;" title="Customer Security and Trust" src="/sys_attachment.do?sys_id=bf70169693114250101833527cba1019" alt="CST Logo" width="148" height="65" /> <h2 style="font-family: Arial, Helvetica, sans-serif; color: white; font-size: 2.2em; line-height: 1em; max-width: auto;">How to Engage with the ServiceNow Security Office (SSO)</h2> <h4 style="font-family: Arial, Helvetica, sans-serif; color: white; font-size: 1.4em; font-weight: normal; line-height: 1.2em; max-width: auto;">ServiceNow has a dedicated "follow-the-sun" global security team protecting customer data 24 hours a day, 365 days a year. All security concerns and incidents should be reported via the <a style="color: #62d84e;" href="https://support.servicenow.com/now">Now Support Portal</a>.</h4> </div> </div> <div style="min-height: auto; flex-grow: 1; flex-basis: 100%; position: relative; width: 86%; padding: 10px 10px 10px 20px;"> <h3 style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.6em; line-height: 1.2em;">Security Contacts in the Now Support Portal</h3> <p style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;">All security communications including <em>incident response notifications </em>are sent to the Security Contact named in the Now Support Portal.</p> <p style="font-family: Arial, Helvetica, sans-serif; color: #000; font-size: 1.2em; font-weight: normal; line-height: 1.3em; padding: 0px 20px 0px 20px;">It is critical that a <strong>suitably qualified person</strong> is entered into the <strong>Security Contact field</strong> and that this <strong>field </strong>is<strong> kept current</strong> at<strong> all times</strong>.</p> <ul style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.2em;"><li style="margin: 10px 0px 20px 20px;">A named Security Contact is essential for the communication of security alerts and security events (e.g. a breach notification) and will also be informed of security updates/patches, new security features in the platform, and threat intelligence information that could impact customer data.</li><li style="margin: 10px 0px 20px 20px;">We also strongly recommend that a Security Incident Response or SOC email distribution list is added for 24/7 coverage.</li><li style="margin: 10px 0px 20px 20px;">Please reach out to your organization’s ServiceNow Administrator to ensure that the correct Security Contact is added to the Now Support Portal.<br /><br /></li></ul> <h3 style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.6em; line-height: 1.2em;">Reporting a security or privacy incident to ServiceNow</h3> <p style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;">There are two methods available for customers to raise a security or privacy issue or concern:</p> <ol style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;"><li style="margin: 10px 0px 20px 20px;"><a href="https://support.servicenow.com/now">Create a case in Now Support Portal</a> – preferred method <em>(requires a Now Support account)</em></li><li style="margin: 10px 0px 20px 20px;"><a href="https://www.servicenow.com/support/contact-support.html">Contact Global Technical Support by phone</a> <em>– </em>who will create a case in Now Support on your behalf<br /><br /></li></ol> <h3 style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.6em; line-height: 1.2em;">ServiceNow incident response workflow</h3> <p style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;">The diagram below provides an overview of the <a href="https://community.servicenow.com/community?id=community_article&sys_id=a75c6aa1dbd0dbc01dcaf3231f961958" target="_blank" rel="noopener noreferrer">Security Incident Response SOP</a> (requires access to CORE, find out how to access <a href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0564067" target="_blank" rel="noopener noreferrer">here</a>).</p> <div style="content: ''; float: left; width: 30%; border-radius: 15px; background: #eee; margin-right: 10px; padding-right: 15px; min-height: 460px;"> <h3 style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.4em; line-height: 1em; margin: 10px 10px 0px 10px;">Activation →</h3> <ul style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;"><li style="margin: 10px 0px 10px 20px;">A security event, incident, or vulnerability is detected and reported</li><li style="margin: 10px 0px 10px 20px;">An internal bridge may be set up between relevant internal teams <em>(as needed)</em></li><li style="margin: 10px 0px 10px 20px;">Triage is conducted to validate the incident and assign the appropriate priority level</li><li style="margin: 10px 0px 10px 20px;">A Security Incident Response Team (SIRT) is created, bringing internal resources together</li><li style="margin: 10px 0px 10px 20px;">A customer bridge may also be set up <em>(as needed)</em></li></ul> </div> <div style="content: ''; float: left; width: 30%; border-radius: 15px; background: #eee; margin-right: 10px; padding-right: 15px; min-height: 460px;"> <h3 style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.4em; line-height: 1em; margin: 10px 10px 0px 10px;">Response →</h3> <ul style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;"><li style="margin: 10px 0px 10px 20px;">Incident briefing is conducted by the Security Incident Response Team (SIRT)</li><li style="margin: 10px 0px 10px 20px;">Mitigation plan is created</li><li style="margin: 10px 0px 10px 20px;">Remediation plan is created</li><li style="margin: 10px 0px 10px 20px;">Communications plan for both internal and external stakeholders is created</li><li style="margin: 10px 0px 10px 20px;">The SIRT sends communications to relevant stakeholders</li></ul> </div> <div style="content: ''; float: left; width: 30%; border-radius: 15px; background: #eee; margin-right: 10px; padding-right: 15px; min-height: 460px;"> <h3 style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.4em; line-height: 1em; margin: 10px 10px 0px 10px;">Resolution</h3> <ul style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;"><li style="margin: 10px 0px 10px 20px;">The mitigation and remediation plans are carried out and overseen by the Security Incident Response Team (SIRT)</li><li style="margin: 10px 0px 10px 20px;">A post-mortem report is created including: <ul style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1em; font-weight: normal; line-height: 1.1em;"><li style="margin: 10px 0px 10px 20px;">A summary of the incident</li><li style="margin: 10px 0px 10px 20px;">Mitigation and remediation activities</li><li style="margin: 10px 0px 10px 20px;">Effects of the incident</li><li style="margin: 10px 0px 10px 20px;">Lessons learned</li><li style="margin: 10px 0px 10px 20px;">Next steps</li></ul> </li><li style="margin: 10px 0px 20px 20px;">The case is updated and closed</li></ul> </div> <div style="content: ''; display: table; clear: both;"> <p style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;">All customer communications are sent at a cadence appropriate to the urgency of the incident via the case in the Now Support Portal (and via a customer bridge as appropriate) until the case is closed by the customer.</p> </div> <h3 style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.6em; line-height: 1.2em;">Useful links to security resources</h3> <p style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;">Publicly available resources:</p> <ul style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;"><li style="margin: 10px 0px 20px 20px;"><a href="https://docs.servicenow.com/csh?topicname=sec-center.html" target="_blank" rel="noopener noreferrer"><strong>ServiceNow Security Center</strong></a><strong> </strong>– a set of tools designed to help companies maintain the security of ServiceNow deployments, improve their security posture, and strengthen compliance levels with a seamless user experience</li><li style="margin: 10px 0px 20px 20px;"><a href="https://docs.servicenow.com/csh?topicname=administer/security/reference/instance-security-hardening-settings.html" target="_blank" rel="noopener noreferrer"><strong>Instance Security Hardening Settings</strong></a><strong> </strong>– contains detailed descriptions and the recommended compliance values for the security-related system properties and plugins in the Now Platform</li><li style="margin: 10px 0px 20px 20px;"><a href="https://www.servicenow.com/company/trust.html" target="_blank" rel="noopener noreferrer"><strong>ServiceNow Trust Website</strong></a><strong> </strong>– website containing security documentation and information regarding compliance, security, and privacy on the Now Platform</li></ul> <br /> <p style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;">Resources requiring Now Support Portal Account (provisioned by your ServiceNow Admin):</p> <ul style="font-family: Arial, Helvetica, sans-serif; color: #333; font-size: 1.2em; font-weight: normal; line-height: 1.3em;"><li style="margin: 10px 0px 20px 20px;"><a href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0621516" target="_blank" rel="noopener noreferrer"><strong>Security Contact KB</strong></a><strong> </strong>– How to update and maintain the security contact field. The Security Contact receives communications from the ServiceNow Security Office (SSO) on security-related issues.</li><li style="margin: 10px 0px 20px 20px;"><a href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0689066" target="_blank" rel="noopener noreferrer"><strong>ServiceNow Security Best Practice Guide</strong></a><strong> </strong>– An easy-to-follow guide to the main security features provided by the Now Platform and how to best use them to secure an instance.</li></ul> </div></div>