Cybersecurity regulations such as NIS2 and ZoKB introduce a wide range of obligations for organizations. However, companies often focus primarily on what they are missing and overlook the capabilities they already have. During the workshop, we will look at the OpenText Service Desk and CMDB environment from the perspective of cybersecurity requirements and explore how to get the most out of existing tools.
We may already have a reliable incident management tool – but are we using it effectively to manage cybersecurity incidents? We may have a CMDB in place – but how can we improve data quality, asset completeness, and relationships between configuration items? We record infrastructure changes – but can we demonstrate that their security impact was assessed and approved? We manage access requests – but where is the line between recording requests and actually managing access rights?
Together, we will demonstrate how SMAX and UCMDB can support asset and configuration management, change management, incident management, operational documentation, supplier management, access management, and business continuity.
Rather than focusing only on gaps, we will primarily look for opportunities to build on what already works today. The objective of the workshop is to establish a shared view of where existing tools already support cybersecurity requirements and to identify concrete steps that can move organizations from basic records and processes toward demonstrable regulatory compliance.
Organizations are required to establish and maintain procedures for detecting, recording, assessing, and resolving cybersecurity incidents. This is one of the areas where the existing SMAX Service Desk can provide significant support.
Every incident can be recorded, categorized, assigned to a responsible resolver, and tracked throughout its entire lifecycle from reporting to closure. This creates an audit trail showing who recorded the incident, who handled it, and what measures were taken. SMAX can also manage priorities and escalations and monitor compliance with defined response and resolution times.
Related incidents can be linked together, making it easier to identify recurring issues and systemic root causes.
However, recording incidents alone is not sufficient for compliance with ZoKB. Organizations must clearly define which incidents qualify as cybersecurity incidents, how they are classified, and who is responsible for their assessment. Processes must also be linked to regulatory incident reporting requirements and internal escalation procedures.
Standardized response procedures should be established for individual categories of security incidents and tested regularly. We will show that SMAX already provides the core process and record-management capabilities, while organizational rules and responsibilities need to be defined and developed further.
Organizations are required to identify and maintain records of assets supporting regulated services. Asset management is therefore one of the fundamental prerequisites for regulatory compliance.
A CMDB can record servers, applications, databases, network devices, and other infrastructure components together with their technical attributes and relationships to business and IT services. This provides the foundation for understanding which resources support critical processes and services.
Asset information stored in the CMDB also makes it easier to assess the impact of incidents and planned changes.
However, simply having a CMDB does not guarantee compliance with ZoKB. Organizations need to verify that records are complete, accurate, and regularly updated. Owners of critical assets must be identified and responsibility for data quality must be clearly assigned.
The greatest challenge is ensuring that the CMDB continues to reflect the real environment over time. We will demonstrate that technology provides a strong foundation, but the quality and completeness of the data ultimately determine its value.
Organizations must manage changes that may affect the security of regulated services.
Change management is traditionally one of the strongest capabilities of a Service Desk platform. In SMAX, change requests, approvals, implementation activities, and post-implementation reviews can all be recorded and managed. Each change creates an audit trail that makes it possible to identify who proposed, approved, and implemented it.
A structured change process also reduces the risk of uncontrolled modifications to the environment and makes it possible to analyse relationships between changes and subsequent incidents.
ZoKB, however, places emphasis not only on recording changes but also on assessing their cybersecurity impact. Approval workflows therefore need to include a security perspective and identify changes with a significant impact on regulated services.
Another important step is to standardize change categories and define mandatory control activities before deployment. Emergency changes must also be recorded and reviewed afterwards.
We will demonstrate how an established SMAX change management process can be further aligned with cybersecurity requirements.
Organizations are required to manage and maintain records of access rights to information and communication systems.
SMAX can be used to record access requests, changes to permissions, and access revocation. Approval workflows create an audit trail showing who requested access and who approved it. This strongly supports accountability and traceability.
The service catalog can also standardize individual types of access requests and ensure consistent approval procedures. During an audit, the organization can provide a complete history of requests and approval decisions.
SMAX itself, however, is not an Identity and Access Management system. To meet ZoKB requirements, organizations also need to define periodic access review procedures and verify that assigned permissions correspond to users’ roles and responsibilities.
It is also necessary to connect the request process with the actual management of accounts and permissions in target systems. Privileged accounts and their approval processes represent another particularly important area.
We will show how SMAX can provide strong process support and integrate with dedicated identity management solutions.
Organizations are required to maintain information about configurations and dependencies between assets.
This is where the CMDB becomes one of the most important tools for supporting regulatory cybersecurity requirements. Configuration management captures not only individual assets but also their relationships and dependencies.
This makes it possible to quickly identify which services may be affected by the failure of a particular component. Relationships between applications, databases, servers, and network infrastructure provide valuable information for both change and incident management.
The CMDB can also serve as an important input for risk analysis and business continuity planning.
However, relationships between assets are often among the least complete areas of CMDB data. Dependencies between technology components and the services they support must therefore be maintained systematically.
Owners of configuration items should also be identified, and information must be regularly updated. To realize the full value of UCMDB, it needs to become a trusted source of information for both IT operations and cybersecurity processes.
We will demonstrate that the CMDB is not simply a list of devices, but a key information source for managing both security and operations.
Organizations are required to create and maintain operational and security documentation.
SMAX provides capabilities for storing knowledge articles, procedures, and operational documentation. This makes it possible to centrally manage instructions, methodologies, and operational procedures and keep them easily accessible and up to date.
The Knowledge Base also supports knowledge sharing across teams and helps standardize the way recurring situations are handled.
These capabilities provide a strong foundation for meeting ZoKB requirements. However, having a repository alone does not guarantee that documentation is complete or current.
Responsibility for individual documents must be defined together with processes for regular review. Additional security procedures may also be needed, such as cybersecurity incident response scenarios or disaster recovery procedures.
Documentation should also be linked to relevant services and assets recorded in the CMDB.
We will show how SMAX can provide a solid platform for documentation, while the real value comes from ensuring that the content is complete, relevant, and continuously maintained.
Organizations are required to manage cybersecurity risks arising from supplier relationships.
NIS2 places significantly greater emphasis on supply chain security. SMAX can maintain information about suppliers, service contracts, and relationships between suppliers and the services they support.
This makes it possible to identify which external partners support particular systems and services. Suppliers can also be linked to individual assets and configuration items, providing useful information about contacts and responsibilities during incidents or planned changes.
To meet ZoKB requirements, however, supplier records should also include cybersecurity assessments and the results of regular supplier reviews. Security obligations arising from contracts must be captured as well.
Another important area is assessing supplier criticality in relation to the services they support. This information should become an input into third-party risk management.
We will show how SMAX can provide a strong foundation for supplier records while cybersecurity supplier management needs to be further formalized through organizational and risk-management processes.
Organizations must ensure the ability to maintain or restore regulated services.
Business continuity is closely connected with information about services, assets, and their dependencies. UCMDB provides information about the technical components on which individual services depend, making it easier to identify critical systems and assess the impact of outages.
SMAX can also record incidents, major outages, and subsequent corrective actions. The Knowledge Base can serve as a repository for recovery plans and operational procedures.
Together, these capabilities provide an important foundation for business continuity processes.
To meet ZoKB requirements, however, organizations also need to formally identify critical services, define recovery objectives, and prepare scenarios for managing crisis situations. Responsibilities of individual teams during outages must be clearly defined and the prepared procedures should be tested regularly.
Another important area is connecting continuity plans with up-to-date information stored in the CMDB.
We will demonstrate how SMAX and UCMDB provide an important information foundation, while true readiness for crisis situations also requires well-defined organizational and process measures.