Technology Workflow - San Diego Release - SecOps Security Incident Response (SIR)
hello everyone thank you for joining me today we're going to discuss some new highlights a part of the san diego update within security operations my name is derek ricketts i'm a solutions consultant specializing in security operations so this exciting release updates are for applied to security incident response and vulnerability response we will be discussing the security incident response portion and this includes updates for the i.t space vulnerability teams and security intent teams to collaborate and resolve major security incidents and expand on our support of mitre attack so let's get started with security incident response the first highlight i'd like to touch on is the major security incident management and this is a war room experience that provides enterprise collaboration across security i.t hr legal and more there is a big challenge of threat landscape delivering cyber security crises at a rapid rate for many enterprises when these crises arise organizations need to come together quickly to meet them too often communication is siloed between groups and data which can get lost in the cracks the miter attack delivers a virtual war room that's needed but and necessary to shift in the post covet era with remote workforce force models in this workspace is to coordinate major security incidents and vulnerability response with a task organizer improve collaboration with teams evidence management and status reports major security incidents are created when your typical security incident is promoted and this starts what by an analyst taking that security incident and proposing the incident to be promoted to do so we would just right click up at the top of our typical incident form and select propose major security incident now there has to be a justification note written in typically so in this case we suspect a company-wide ransomware attack after looking over some of the analysis we saw that about 100 devices are affected so we want to note that in there as well then we would just propose that incident after we proposed that security incident to be promoted we move on to the major security incident management workspace which is a place where the major security incident manager can coordinate and direct the entire incident response process from here the manager has access to the entire collection of tools and integrations at their disposal and this gives them the ability to see every aspect of an incident quickly and easily creating what's known as the virtual war room at the top you can see the incident the original incident that we proposed so if we click into that incident we can view further analysis on our end additionally we can see the incident impact with the configuration items it affects but once we figure out and determine that this is an incident worth promoting we would select promote major security incident on the other hand if it was something that wasn't worth promoting or wasn't it it was turned out to be a a false positive we would just reject the major security incident so in this case we're going to promote it and then after performing further analysis um we see that it is indeed a ransomware attack so we can note that there doing that those additional analysis we saw instead of affecting 100 devices it turns out there are 300 devices affected we can update that here as well and then promote it directly from here and then once the incident is promoted you can see the overview tab was updated with all a quick snapshot of all the related metrics and scope of the progress pertaining to this incident and these metrics provide a comprehensive look at the major security incident in its related components such as task duration incident impact collaboration and and as well as instant progress charts with the diagrams included and these are populated with all the relevant data as the incident is updated next we'll take a look at the details tab of the ui where managers can view and edit the major details of the incident some of the vital data provided in this tab include the incident number primary state category subcategory and so on major security incident management leverages records from across a platform and outside sources these records are then attacked directly to the incidents where the data can be viewed and analyzed to work the incident on the right side of this tab in the compose section where are where the managers can view and add work notes if needed security teams need to better develop prioritize manage their detection and response mechanisms with the help of metrics such as adversarial behaviors detected health of those detections how well they are being detected and gaps and use cases an answer for some of those common business needs are the minor attack information associated with iocs and having the visibility surrounded by them now as we move forward with the demo start by looking at your typical security incident form now in addition to typical triag information the security analyst now has immediate access to the minor attack data and the ability to provide additional mapping in addition to the new powerful miter attack heat map and navigator as shown here the threat intelligence analyst can also view the same data through the stixx visualizer this feature gives them a quick and easy way to see relationships between intrusion set and malware along with attack patterns and tools that they use next let's talk about the security incident response threat and tell and orchestration portfolio updates there are new integrations that have been added to help security analysts manage and respond to incidents using sentinel 1 and misp as well as helping with communication and collaboration using microsoft teams and sharepoint when major security incidents arise the solution is adding new integrations to support microsoft teams and sharepoint as well as misp and sentinel one integrations next we have the collaboration tab and this is where you'll really see where the newly available integrations such as microsoft teams and sharepoint can be utilized for chat features file sharing and conferencing the manager who can coordinate collaboration workflows thank you for taking the time to go through the new features with me a part of the san diego release we hope to hear from you soon
https://www.youtube.com/watch?v=gs23l2v5bvU