Enable security incidents for vulnerabilities
Access threat intelligence context for security incidents directly within the Security Incident Response Workspace. TISC context helps you understand related threats and make informed decisions during incident response.
Before you begin
Roles required:
- sn_sec_tisc.analyst
- sn_si.analyst
About this task
Security incidents enable tracking and management of remediation efforts for vulnerabilities in TISC, supporting prioritized response and maintaining auditability. For more information, see Create Security Incident from a Vulnerability Record.
Procedure
Navigate to Workspaces > Security Incident Workspace.
Select the Security Incidents icon on the workspace.
Navigate to Lists > All.
Open a security incident record.
Navigate to the TISC Context section.
The Vulnerabilities entry point provides access to information about threat objects related to the selected vulnerability.
Select View Related Info to explore associated vulnerability data.
This displays a list of related threat objects associated with the vulnerability, including threat actors, attack patterns, campaigns, cases, vulnerability entries, and vulnerability assessments.
Select any object to view the corresponding record in the TISC workspace.
Parent Topic:TISC integration within SIR Workspace
Related topics