{"id":9186,"date":"2022-12-08T14:06:36","date_gmt":"2022-12-08T22:06:36","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=9186"},"modified":"2023-06-26T17:11:17","modified_gmt":"2023-06-27T00:11:17","slug":"streamlining-vendor-assessment-with-servicenow-vrm-at-microsoft","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/streamlining-vendor-assessment-with-servicenow-vrm-at-microsoft\/","title":{"rendered":"Streamlining vendor assessment with ServiceNow VRM at Microsoft"},"content":{"rendered":"
This content has been archived, and while it was correct at time of publication, it may no longer be accurate or reflect the current situation at Microsoft.<\/p>\n<\/div>\n<\/div>\n
We\u2019ve adopted ServiceNow Vendor Risk Management (VRM) to manage our risk assessment during the procurement process for Internet of Things (IoT) devices across Microsoft.<\/p>\n
ServiceNow VRM provides a centralized, managed solution for assessing security risks for IoT devices and the vendors that supply them for us. With this solution, our vendor risk management processes at Microsoft are more automated and efficient, better monitored, and easier for our employees and vendors to use.<\/p>\n
At Microsoft, our business necessitates an extensive supply chain that depends on trusted non-Microsoft vendors. These vendors provide much of the hardware and software upon which we run our business. Our Microsoft security team ensures that our vendors and the hardware and software they provide adhere to our compliance and security requirements.<\/p>\n
As part of our broader governance, risk, and compliance processes, the vendors and partners that supply these products and services must undergo an assessment of their operations and the products or services they supply. The security team provides technical expertise to confirm that software and hardware adhere to modern security practices. We have multiple business groups that work with the security team to assess vendors. Each business group has nuances that affect the way the security team creates and processes vendor assessments.<\/p>\n
One such example is the IoT Security Assessment program. This program focuses on IoT devices procured and deployed throughout Microsoft. Each vendor and the product they supply must be vetted to maintain our security standards.<\/p>\n
Globally, we at Microsoft manage thousands of IoT devices supplied by many different vendors. These devices include card readers, cameras, kiosks, and HVAC systems equipment. Each of these devices and the software that supports them must undergo the security assessment processes established by our security team. The basic assessment process includes the following three high-level steps:<\/p>\n
In response to IoT Security Assessment process changes, including increased vendor data requirements, our security team had previously adopted a simple solution for tracking the assessment process. However, the volume of incoming requests and the detailed nature of IoT device assessments quickly surpassed the original solution\u2019s capabilities, which were centered around file-based assessments exchanged through email and stored in a shared folder.<\/p>\n
The original solution was largely a manual process that involved potential for human error, lost data, and an untracked workflow. We realized that the IoT Security Assessment program needed a more robust and automated process for managing vendors and devices. To begin the workflow reinvention process, we established specific goals for the new solution:<\/p>\n
Based on these goals, we researched available solutions. Ultimately, we decided on a solution from one of our trusted partners: ServiceNow Vendor Risk Management (VRM).<\/p>\n
The ServiceNow VRM platform provides centralized management across the entire vendor assessment lifecycle process. It has built-in capability for:<\/p>\n
We adopted ServiceNow VRM for the IoT Security Assessment program as a single tool to help us more securely engage vendors, assess supply chain risk, and follow IoT device security assessment through to completion.<\/p>\n
With ServiceNow VRM, our entire vendor assessment process is hosted online in the ServiceNow VRM portal. Through this centralized portal, employees can create, manage, and assign assessments. Vendors can also use the portal to review incoming assessment requests and complete assessments. All parties involved can review the progress of assessments, receive notification when action is required, and perform necessary actions without switching tools. Improving visibility for the entire process means that both employees and vendors can check the status of assessments, issues, and tasks, and more quickly identify emerging risks.<\/p>\n
Automated workflows in ServiceNow VRM improves collaboration. It also helps us establish consistent workflows and enables employees and vendors to reuse assessment components across products and devices.<\/p>\n
ServiceNow integrates directly with our Microsoft Azure Active Directory (Azure AD) tenant to supply single sign-on (SSO) and multifactor authentication to the ServiceNow VRM portal. This capability complies with our security standards while providing a seamless sign-on process for our employees and our vendors.<\/p>\n
In less than three months the IoT Security Assessment program transitioned from our original, manual solution to ServiceNow VRM. Our process started with defining our future requirements and ended with going live with ServiceNow VRM for all IoT security assessments. A quick migration reduced duplicate vendor management tasks in both the original solution and ServiceNow VRM, and it simplified the transition for employees and vendors.<\/p>\n
Establishing a schema for storing data about vendors and devices helped us better understand assessment requirements. ServiceNow VRM integrates with ServiceNow IT Service Management (ITSM) to track and resolve vendor assessment issues and tasks. It also supplies the schema for vendor records, which directly affects the simplicity and accuracy of the integration and future IT Security assessments.<\/p>\n
We use forms in ServiceNow VRM to create reusable assessment templates. All individual assessments are created using a form, which ensures consistency, reduces potential for human error, and reduces manual effort for assessment creation and management. We also perform all form and assessment tasks in the ServiceNow VRM portal, which creates experience continuity for our employees and security team members. Vendors simply complete individual assessments, which are then reviewed for validity. Assessment answers that require further attention or correction generate a prioritized list of issue records for the vendor to review and take action against.<\/p>\n
We manage all assessment workflow communication within the ServiceNow VRM portal. We\u2019ve customized communications for each of the Microsoft business groups using ServiceNow VRM, including the different assessment types used. All communication and handoff data are tracked, including which assessment is being performed, why it\u2019s being performed, and who is responsible for the process.<\/p>\n
Before deploying ServiceNow VRM to the larger group of IoT vendors, we ran a test pilot for the onboarding processes with a single vendor. We used this pilot to confirm processes, test end-to-end functionality, and make any necessary adjustments to our onboarding processes.<\/p>\n
Centralizing and automating our IoT vendor risk assessment process using ServiceNow VRM has vastly improved the end-to-end experience for our employees, vendors, and the IoT security team. Some of the most significant benefits include:<\/p>\n
<\/p>\n
Our IoT Security Assessment program is only the beginning of our process evolution. Here are the next steps that we will take on our journey:<\/p>\n
<\/p>\n
This content has been archived, and while it was correct at time of publication, it may no longer be accurate or reflect the current situation at Microsoft. We\u2019ve adopted ServiceNow Vendor Risk Management (VRM) to manage our risk assessment during the procurement process for Internet of Things (IoT) devices across Microsoft. ServiceNow VRM provides a […]<\/p>\n","protected":false},"author":146,"featured_media":9188,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"footnotes":""},"categories":[1],"tags":[],"coauthors":[674],"class_list":["post-9186","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","m-blog-post"],"yoast_head":"\n