Submit block list entries from a security incident for the Check Point NGTP integration
Observables attached to a security incident record are submitted for approval as Block List entries to different Block Lists. An optional approval process for Block List entries is part of the preconfigured workflow. The Gateway imports Block List entries — IP addresses, URLs, domains — that are included in Block Lists.
Antes de Iniciar
- Security Incident Analyst (sn_si.analyst) to submit block list entries.
- Security Incident Administrator (sn_si.admin) to approve block list entries. This authority can be assigned as required by your organization.
Por Que e Quando Desempenhar Esta Tarefa
Users with the sn_si.analyst role submit Block entries by requesting a block on observables attached to a security incident record. Once submitted, a Block List entry with a status of Pending is generated and sent for approval. The following example shows a block request for a URL observable.