Ram Devanathan1
ServiceNow Employee
ServiceNow Employee

As a centralized IT team member, do you often face these questions -

  • are my resources in the cloud tagged right - so my cloud bills and costs are assigned correctly?
  • are my resources in the cloud configured and deployed per the norms established at the corporate level?
  • is this on-prem distributed app ready to move to the cloud, or should it be retired in favor of a cloud-native architecture?
  • can I remediate configuration of misconfigured cloud resources - e.g. setup encryption on s3 bucket, disable root user without MFA authentication, enable monitoring for Azure VMs
  • what's the Cloud Center of excellence practice - how can I and my organization benefit from this?

If you do often face these questions, here's good news for you.

From the IT Operations Management products group, we are happy to present to you all the ITOM Governance product offerings. This comprises entitlements to the following store applications -

Application (Store)
Links
Assess your migration readiness
Version: 1.0.1 by Service-now.com

Doc Link

Store Listing

Validate and remediate your cloud resource configuration properties
Version: 1.0.5 by Service-now.com

Doc Link

Store Listing

Library of readymade actions and sub-flows for use in your cloud workflows
Version: 1.0.5 by Service-now.com

Doc Link

Store Listing

Define and enforce tagging policies for your IT and cloud resources, assess your tagging efficacy.
Version: 1.1.0 by Service-now.com

Doc Link

Store Listing

We would love to get your thoughts on these products and the workflows offered.

Read on for more details for knowing some of the scenarios where these apps will help you.

Cloud Migration Assessment

This app provides a workbench to view all your server workload information and start off assessment tasks to determine the next steps.

find_real_file.png 

You can drill-down into the server workload details, analyse additional information about the 'real' utilization of the server against its allocated capacity, the running process, software and traffic (connections) information further help to determine all needs of the workload as this is moved to the cloud. The 'real' utilization is quite important to determine the right t-shirt size to use for powering the workload in cloud, as this results in higher costs which may not be required.

Here's a video showing a typical use case for migration assessment. Should the on-prem gitlabs host be moved to the cloud or should the cloud service (GitLab's on cloud) be used for this? This will obviously be a decision involving multiple factors - cost, security, data residency, etc. The assessment task has to be driven to get clear agreement from all stakeholders around the approach to go for. The video is a quick view of the various aspects of setting up an assessment including setting up the team and watchlist members.

Cloud Configuration Governance

If you are worried about wrong configuration of cloud resources leading to perimeter or data breaches, then CCG can help by collecting the data from cloud resources, validating this data against policy rules, identify violations, and finally, offering remediation to fix the issues.

Here's a screenshot of the dashboard of CCG from an instance where we are checking AWS and Azure cloud resources.

find_real_file.png

 

Here's a quick overview (10m video) of the entire app showing you the broad capabilities of the app and how to extend this for your additional configuration governance needs.

 

 

Cloud Action Library

Cloud Action Library (CAL) is another store application, packaging a set of IntegrationHub flows and actions which can be used to power typical cloud operations.

Tag Governance

The Tag Governance app was released last year in the store and we see a great deal of interest for using this to drive allied use cases like Tag-based service mapping and CSDM on cloud resources. You can refer to this blog by my colleague Steve Emerson for more details. Here's a link to a video on Tag Governance from our official ServiceNow youtube channel.

Building governance rules and improving the efficiency of your cloud migrations is made a whole lot easier with these apps as you can see.

We would love to hear your feedback about these products and improvements you would like to see.

Best Wishes

Ram Devanathan

Sr. Principal Product Manager, ITOM

Comments
sourabhbs
Tera Contributor

Hi Ram,

We are trying to install the Cloud configuration Governance for AWS. Does this application work if we have setup credential-less discovery to AWS? I did try to create assume roles in the sn_itom_ccg_service_account_assume_role_config table but I seem to be getting Credential error. 

Ram Devanathan1
ServiceNow Employee
ServiceNow Employee

sure - pl email me at ram<at>servicenow<dot>com and suggest some times to meet - so we can lead you through this.

Version history
Last update:
‎02-15-2022 10:13 PM
Updated by: