logo

NJP

Post-Incident Review Report Designer

Import · Mar 23, 2021 · video

hello everyone my name is madhumita and i'm part of the sar product management team today i will be demoing the post incident review reports designer functionality as a security admin i would be able to create report templates and be able to assign them to security incidents conditionally all of these steps are possible from within this page before we see how to build report templates i would like to highlight that a report template can have branding timeline and template scripts as optional components within it now let's see how to build report templates here is an example of a report template that we have stripped out of the box the rich text editor allows a lot of formatting options and this sample report shows how rich the formatting can be as a security admin i can include all the fields in the security incident response form that are both standard and custom here is an example of how we have included short description within the report in order to include data beyond what is present in this list the security admin can use template scripts here is an example of a sample template script that fetches malicious observables and we have referenced this in our report let us get back to the report to see how to include branding information the security admin can include branding information by selecting one of the branding records that are available here is a sample branding record the security admin can include header image footer image footer text and the related positions now let us again get back to the report template to see how timeline information can be included within the report this is how we include timeline information within the report the timeline consists of all the activity logs within the security incident now we all know that activities can pan across multiple pages counting to tens of hundreds of records the amount and relevance of information that goes into the timeline can be controlled with the help of timeline configuration here is a sample timeline configuration the security admin would be able to filter the activity type and also decide whether or not to include images and child tasks so far we have taken a look at how to build a template now let us also see how to assign these templates to security incidents it is possible through the help of report configuration here is a sample report configuration that assigns these templates to all the security incident belonging to the category phishing the security admin can assign one primary template and one or more additional templates here ends the job of the security admin now when a security incident moves to the review state the security analyst would be able to view and download these reports from within the post incident review tab by default the primary report gets displayed while the analyst can choose additional templates by clicking on the drop down the analyst can download the report directly or make certain configuration changes as an analyst i would only be able to make changes to the timeline filters and change it and save it while i also can go ahead and preview the report before downloading it that's all about the post incident review report functionality

View original source

https://www.youtube.com/watch?v=FEBrVBsyOf0