Working with Neurons for Security Operations Management
6 min
role chief information security officer, security administrator, security analyst, security manager minimum version 2020 3 with neurons for security operations management (som) capabilities, security incidents of your organization such as theft, data breach, phishing, and policy violation are addressed in a structured manner with automated workflows it also helps employees to easily report security incidents, and request for security services converts an event to a group business object, and creates network and security event types under the new event business object this gives you more flexibility in integrating an event with other systems the software integrates with risksense and uses an api call to import network and security events you can also create new network and security events and create incidents or changes to help manage your events track unmanaged devices on a dashboard and integrate with atlassian jira software and azure devops to automatically create issues installation and configuration this section explains the installation and configuration process for itsm enterprise in both cloud and on premise environments, for new and existing customers new customers itsm cloud line of business (lob) is included with itsm deployments for all new customers no additional installation or manual upgrades are required itsm enterprise license or enterprise solution package are required to access itsm enterprise workflows contact ivanti operations to activate lob content if upgrading licensing from standard to itsm enterprise existing customers itsm cloud existing cloud customers who wish to activate will need to engage ivanti professional services https //www ivanti com/services/professional services (pso), certified ivanti partner, or https //www ivanti com/en gb/services/professional services https //www ivanti com/en gb/services/professional servicesivanti operations docid\ xmvzlfcwdkupkfflhopic in order to enable the additional content new customers itsm on premise is included with new on premises installations and can be activated for customers who have the required enterprise licensing contact ivanti professional services https //www ivanti com/services/professional services or a certified ivanti partner to enable the additional content existing customers itsm on premise existing on premises customers who wish to upgrade to will need to engage with ivanti professional services https //www ivanti com/services/professional services or a certified ivanti partner features the following scripts are included in the software risksense cis by security event risksense create security events risksense security event details risk based vulnerability management (rbvm) integration using export api these scripts have been updated for 2023 1 if you have already installed an older version of , the previous scripts (risksense integration, risksense integration get cis, risksense integration link ci to ransomware incident) will not be overwritten risksense integration schedule set the start and end times to run the scripts above refer to creating a schedule in about the schedule entry and scheduled jobs workspaces docid\ oly9b8ak4f7dbrbymcikf refer to creating a scheduled workflow in using workflows docid\ p4kb1hcf81wnxmoqhbcjs unmanaged device dashboard special part use this to track unmanaged devices on a dashboard it isn't tied to a dashboard, so you can add it to any existing dashboard refer to using special parts in using the dashboard center docid\ namwim ahfhmj7qila1ee integration with the jira service desk connector the risksense integration works with the jira service desk connector (part of the ticket sharing and synchronization package) the jira service desk connector is a separate package that you can find in the ivanti marketplace refer to jira service connector for ivanti automation https //marketplace ivanticloud com/packages/jira servicedesk connector/ important edit and read only permissions for metadata components including fields, relationships, forms, lists, layouts, triggered actions, saved searches and pick lists are indicated by a green pencil or red dot icon in the components indicating a green pencil icon can be edited; components indicating a red dot icon are read only components with no icon displayed can be edited and deleted you can duplicate a read only component and then edit it metadata components marked with a yellow pencil icon indicate a soft lock, meaning they have limited edit permissions for more information on soft lock, see modifying a business object with soft lock docid\ prrpnuvje8dmzc oaqymn if you're not currently using the event business object, we recommend you delete the demo data from the package import before you use this software this makes it easier to find events that you create or import there are 2000+ demo records to delete demo data open the event workspace from the list view, change the page size to 100 highlight all events on the page, and then select delete repeat steps 2 3 for all pages user roles the following user roles are available in each user role has different capabilities, roles and responsibilities chief information security officer security administrator security analyst security manager
