Security incidents created from events and alerts
Summarize
Summary of Security Incidents Created from Events and Alerts
This feature allows ServiceNow customers to automatically create security incidents from alerts generated by event monitoring tools. Alerts are processed by Event Management and can trigger security incidents based on customizable rules or through manual selection for investigation.
Show less
Key Features
- Automated Incident Creation: An alert rule called "Create security incidents from critical alerts" enables automatic creation of security incidents from critical security-related events.
- Customizable Alert Rules: Users can define additional alert rules with different conditions to manage various types of security incidents.
- Manual Incident Creation: Security Admins can manually create incidents from suspicious alerts using the "Create Security Incident" button.
- Required Event Information: Events must include specific details such as node identification, event classification as Security, and a descriptive event summary.
- JSON Format for Additional Information: Additional event information can be sent using a specified JSON format to populate the security incident fields.
Key Outcomes
By implementing this functionality, customers can streamline their incident response processes, ensuring that critical security events are captured and addressed promptly. The ability to customize alert rules and manually create incidents provides flexibility in handling various security scenarios. Moreover, tracking event details and maintaining accurate work notes enhances overall incident management and reporting capabilities.
As events are imported from alert monitoring tools, they are first processed by Event Management and grouped into alerts. These alerts can be used to create security incidents based on customizable alert rules, or manually reviewed to select those alerts to be investigated as a security incident.
You can find a sample alert rule called Create security incidents from critical alerts in the Alert Rules module of the Event Management application. This alert rule automatically creates security incidents when critical security-related events are received from within ServiceNow or from third-party monitoring applications. After the security incident has been created, it will be updated as new events are received. You can modify the task template in the alert rule to change the initial values for the security incident created by this alert rule. To handle each distinct variety of security incident that you would like to create, you can define other alert rules with different conditions.
Alternatively, if you are a user with the Security Admin role, you can manually create a security incident by clicking the Create Security Incident button from any suspicious alert.
- The node set to the name, IP address, or sys_id of the CI that becomes the affected resource.
- The event classification is set to Security to distinguish them from other IT events.
- The event description, which populates the description of the security incident.
- The additional information can include any extra information that does not fit into the previously listed fields or other event fields, such as the category, attack vectors, return URL, or correlation ID. The format is a
string that lists field names along with their values, using the following JSON format:
{ "fieldName" : "fieldValue", "fieldName" : "fieldValue" }