Handle security incidents using Advanced Work Assignment
Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.
Before you begin
Role required: sn_si.analyst and awa_agent
Procedure
Navigate to Workspaces > Security Incident Response Workspace.
Select the Inbox button.
Indicate your availability status by selecting your presence state in the Status field.
The available presence states are:
Available: You’re available and can accept security incidents. Whether you’ll be assigned incoming incidents is based on the configured service channel, queues and assignment rules.
Note: If auto-assignment has been enabled, security incidents are directly assigned to you.
Away: You aren’t available to accept assignments of incoming incidents.
- Offline (the default): You’re offline and aren’t available to accept assignments of incoming incidents.
- Accept or reject a security incident assignment.
Note: If rejection handling hasn’t been enabled in AWA, the Reject option isn’t available.
Accept the incident by selecting Accept.
The incident is assigned to you.
Reject the incident by selecting Reject and select a reason for the rejection.
Parent Topic:Using SIR Workspace
Related topics
Working with Security Incident Records
Prerequisites for the Playbooks
Rebuilding existing playbooks in Workflow Studio