Security Incidents
3 min
all security related incidents for the organization such as data breach, policy violation, phishing, and theft can be reported using security incidents security incidents may also be created automatically as a result of importing data from rbvm using the rbvm connector refer to configure the rbvm data import connector to import rbvm events docid\ gqnmax37i1grkwgivrasn you can edit these security incidents if required by opening them from the security incidents workspace creating a security incident open the security incidents workspace click new and either select a template or select create a new record enter information into the fields summary and description category based on the category, a relevant workflow is applied and initiated select the workflow instance tab to view the workflow you can abort or pause the workflow and resume it when paused if the security incident involves sensitive data select the is sensitive data lost/stolen? or sensitive data breach checkbox the checkbox displayed is based on the incident category if the security incident is a phishing attack, select the phishing attack? checkbox the checkbox is displayed only when the category is phishing click save tabs in security incidents if you do not see some of the tabs listed here, they may be hidden, click the icon at the right corner of the tabs list and select the tab you wish to reveal task based on the workflow, tasks are automatically added to the security incident you have to complete the tasks to resolve the incident additionally, you can add more tasks as required other actions you can perform for tasks are accept , reject , cancel , reassign , waiting , continue , and complete confidential participants this tab is available only when you select the confidential checkbox you can limit access to the security incident to selected users by adding confidential participants to add confidential participants click link and select the user to whom you wish to give access to the security incident press the shift key to select multiple users click select the selected users are added to the confidential participants list and only they will have access to the security incident to remove a confidential participant select the user whom you wish to deny access to the security incident click unlink the selected user is removed from the confidential participants list and will not have access to the security incident events link events to the security incident on linking an event, a child security incident can be created to view existing child incidents, or to create one, click the child security incidents tab child security incidents link existing incident or create new incident as a child incident to the security incident ci link the configuration item that is lost, stolen, or involved in any other way to the security incident problem create a new problem or link existing problem to the security incident change create a new change or link existing change to the security incident contract link contracts to the security incident activity history the history of all emails is displayed here includes emails you've sent to users, as well as system generated emails checklist create new checklists or link existing checklists for the security incident external task create tasks or link existing tasks to the security incident that needs to completed by an external team attachment attach files or add urls cost item the cost of the security incident is managed in this tab you can either add cost item from the existing list or create a new cost item knowledge create knowledge articles or link existing article to the security incident for reference escalation watch all escalations records are displayed audit history displays the important changes made to the security incident such as when the summary or description is modified, and when the status is updated workflow instance displays the workflow used for security incident you can abort, pause, and resume the workflow approval create new or link existing approvals to the security incident related posts link or unlink related posts to the security operations
