What is our primary use case?
The customer implementing ServiceNow Security Operations uses it for gate lock reactivations, Wi-Fi network router management, IP address whitelisting, website blacklisting, and vulnerability assessments.
When phishing incidents or other security issues need to be resolved in the ServiceNow Security Operations Incident Response module, it directly fetches data about users receiving phishing emails, enabling research and appropriate resolution. Through integration, data from third-party tools is also accessible.
In ServiceNow Security Operations, vulnerability assessments are conducted based on IT band and other factors. If there are open ports or other vulnerabilities in the system, incidents are raised, resolved, and monitored until completion to ensure the vulnerability no longer exists after resolution.
What is most valuable?
Integration is crucial in ServiceNow Security Operations because everything must be integrated to obtain data. Without integration, the solution is not as beneficial as expected. In SecOps, real-time data is essential to avoid discrepancies between real-time events and ServiceNow data.
Multiple tools integrate with ServiceNow Security Operations, with Qualys being one of them.
ServiceNow Security Operations collects data from various sources and presents it in a single, respectable format for assessment and action. The main benefit is not having to access separate tools for different data. It provides a unified user experience where all work and fixes can be managed from one location.
What needs improvement?
ServiceNow Security Operations is not specifically a vulnerability management or incident tool, but rather a data aggregator. It would be beneficial if, similar to the Discovery module which assesses all CIs present in the company, there was a way to assess CIs directly within ServiceNow Security Operations to obtain vulnerability information. Currently, third-party tools are required for this functionality.
ServiceNow Security Operations is moving towards GenAI capabilities. While current AI functionality is not optimal, future improvements are anticipated.
For how long have I used the solution?
I have been working in ServiceNow Security Operations for six months.
What was my experience with deployment of the solution?
We have configured only out-of-the-box features in ServiceNow Security Operations. It follows the standard process of creating security incidents automatically, which teams then resolve.
What do I think about the stability of the solution?
There are no complaints regarding stability.
What do I think about the scalability of the solution?
It is highly scalable because most tools integrate with ServiceNow Security Operations.
How are customer service and support?
I have contacted ServiceNow for various issues, including dashboard-related problems, and they have been helpful with everything. They provided quick resolutions.
The support for ServiceNow Security Operations rates nine and a half to ten out of ten.
How would you rate customer service and support?
How was the initial setup?
The setup process is easy. The implementation took four months, though the configuration requirements were minimal. The specific time depends on company requirements. ServiceNow Security Operations can function as a live maintenance tool or operate with a single version, depending on organizational needs.
What about the implementation team?
I am developing and using it as a development solution.
What's my experience with pricing, setup cost, and licensing?
It is relatively expensive but manageable.
What other advice do I have?
Initially, acquire basic knowledge about the system and understand how ServiceNow Security Operations operates with other tools. This understanding is essential before starting the implementation process to avoid confusion. On a scale of 1-10, this solution receives an 8.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other