Other additional Security Incident Response setup tasks
If you are an administrator in the global domain, you configure how Security Incident Response handles day-to-day operations.
Before you begin
Role required: sn_si.admin
Note:
These options are standard to many service management applications, and as such, they use service management terminology. For example, Request is used for the main task (that is, the security incident) and Task is used for subtasks or Response Tasks.
If you are an administrator in a domain lower than the global domain, you can view the Configurations screen, but cannot modify the settings.
Procedure
Navigate to All > Security Incident > Administration > Configuration.
The options for configuring the applications are organized under these tabs:
- The Business Process tab contains options for setting up the request life cycle, creating catalogs and requests, and configuring notifications.
- The Assignment tab contains options for setting up manual and auto-assignment.
- The Add-ons tab contains options for enabling the knowledge base, managed documents, and task activities.
- Fill in the fields on the Business process tab.
| Field | Description | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Lifecycle | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Work notes are required to close or cancel a request or task | Enable this option to require the user to enter work notes before a security incident or response task can be closed or canceled. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Copy task work notes to request | Enable this option to synchronize response task work notes with the work notes on the security incident. So when work notes in the task are added, the same work notes appear in the parent security incident. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Catalog and Request Creation | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Create or update requests by inbound email | Enable this option to create or update security incidents from inbound emails. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Requests are created using | Select catalog or regular form to activate the catalog and enable automatic publishing of security incident templates to the catalog.Select regular form only to deactivate the catalog and disable automatic publishing of security incident templates to the catalog. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Templates create a dedicated catalog item | Enable this option to activate automatic publishing of catalog items for the application. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Notifications | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| For a request or task, when the selected field changes, send notification to recipients | You can configure notifications to be sent to specific recipients when selected fields in security incidents and response tasks change. 1. From Table, select Request (security incident or Task (response task). 2. From Field, select the field to use for generating notifications. When a change is made to the selected field, a notification is sent to the identified recipients. 3. From Recipients, select one or more recipients. 4. If you select a specific user or a specific group, you are prompted to select a user or group. 5. To define more notifications using other fields or recipients, repeat the preceding steps for the next set of notification settings. 6. To remove a notification, select the Image omitted: DeleteNotification.png delete notification symbol icon to the right of the notification.</td></tr></tbody>
Lock down security administrationTo protect investigations and keep security incidents private, you can restrict Security Incident Response access to security-specific roles and ACLs. Non-security administrators can be restricted from access, unless you expressly allow them entry. Before you beginWhen the Security Incident Response application is activated, the System Administrator user is granted the sn_si.admin role by default. The System Administrator is the only administrator who can set up security groups and users. A security role is required to have access to Security Incident Response features and records. Role required: sn_si.admin Procedure
Image omitted: system-applications.png System applications.
Related topics Manage Restricted Caller AccessThe Restricted Caller Access (RCA) feature enables an administrator to define cross-scope access to an application or application resource and allow or deny access requests. This feature is enabled in Security Incident Response by default so security analysts can protect sensitive security-related information. A field called Caller access has been added to all tables and script includes in Security Incident Response, and the field defaults to Caller Tracking. This setting means that application scopes are allowed access to Security Incident Response tables and script includes. However, a tracking record is created for each record and stored in the Restricted Caller Access Privilege [sys_restricted_caller_access] table. Note: Take care when changing records from Caller Tracking to Caller Restricted. Records with this status cannot be accessed until an administrator manually allows access to it. The administrator must navigate to System Applications > Application Restricted Caller Access, locate the table or script include for which access has been requested, and change the Status field from Requested to Allowed. Related topics Restricted caller access privilege settings Set the application scope, application resource, and event access Run quick start tests for Security Incident ResponseValidate that Security Incident Response still works after you make any configuration changes, such as applying an upgrade or developing an application. Copy and customize these quick start tests to pass when using your instance-specific data. Security Incident Response quick start tests require activating Security Incident Response plugin (com.snc.security_incident) and loading the demo data.
Related topics | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||