Understand Security Incident Response Orchestration workflows and workflow templates
-
- UpdatedAug 3, 2023
- 2 minutes to read
- Vancouver
- Security Incident Response Orchestration
Understand Security Incident Response Orchestration workflows and workflow templates
The Security Incident Response base system includes a series of workflows and workflow templates designed to work with security incident records.
Before you begin
Role required: sn_si.basic
About this task
Workflow templates, however, are triggered by selecting a value in the Category field in a security incident. When this occurs, the workflow template associated with the selection kicks off a workflow template that instructs the security analysts how to deal with a specific type of threat.
For example, if you select Denial of Service from the Category field in a security incident, the Security Incident - Denial of Service - Template is executed and the analyst is directed to determine whether the target of the DOS is business critical. If so, the next task causes the priority of the security incident to be set to 1 - Critical, and then executes the next task. And so on.
So Security Incident Response workflows and workflow templates are essentially the same, except the templates are used for a specific set of functions within a security incident.
Procedure