Security Operations SOAR: Step 5 - Incident Manager

Table of Contents

Below you'll find a table of contents for the Incident Manager journey.

soar-incident-manager.png

Streamline incident response with SecOps SOAR Incident Manager. Keep your team organized and focused by managing critical incidents from start to finish in one central platform. Collaborate across departments, track tasks with clear timelines, and organize information chronologically for easy reference. Improve team efficiency and ensure everyone's on the same page with a clear picture of the situation, decisions made, and next steps. Turn incident response into a well-oiled machine with SecOps SOAR Incident Manager.

Prerequisites

  • Entitlement for SecOps SOAR on the account and project
  • Administrative permissions to Chronicle SOAR

Actions

soar-incident-manager-define-departments.png
Define Departments

The first step is to define the departments that you will be working with. As you can see in the SOAR Settings > Incident Manager > Departments page, a default department is provided by default. This is to make sure that every internal user that you add to the incident will be automatically assigned to a department.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative permissions to Chronicle SOAR
Steps
  1. Navigate to SOAR Settings > Incident Manager > Departments.

  2. In the Departments page, click Add Department and fill out the new department information. At any stage you can choose to change the default department. The default department is the one that internal users are automatically added to.

  3. Add in all the departments that you will be working with in the Incident Manager. You can also add departments that are external to your company.

Relevant Links

soar-incident-manager-define-auditors.png

Define Auditors

An auditor is defined as an Incident Manager power user. The auditor is automatically added to every incident that is handled in the Incident Manager. They also have the ability to close and reopen incidents, as well as seeing closed incidents. The platform administrators are automatically considered as auditors.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative permissions to Chronicle SOAR
Steps
  1. Navigate to SOAR Settings > Incident Manager > Auditors.

  2. Click Add Auditors.

  3. Choose the required user. This list is populated from any users in the system.

  4. Choose the required department. This list is populated from the list of departments you previously created in SOAR Settings.

Relevant Links

soar-incident-manager-define-authorized-environments.png

Define Authorized Environments

Each customer is allowed to handle cases from a certain number of environments only. The number of environments is according to your license. The default environment is automatically added here.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative permissions to Chronicle SOAR
Steps
  1. Navigate to SOAR Settings > Incident Manager > Authorized Environments. All the environments in your company will appear on the page.

  2. Select those environments whose cases, if the need arises, can be handled in the Incident Manager. You can hide all the other environments once you have chosen the ones you need using a checkbox at the top of the page.

Relevant Links

soar-incident-manager-create-incident-reports.png

Create Incident Reports

Generate clear reports to justify ROI to management, demonstrate transparency to stakeholders, and make data-driven decisions for future improvements. Turn incident data into actionable knowledge with reports in SecOps SOAR Incident Manager.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative permissions to Chronicle SOAR
Steps
  1. Click Menu on the Dashboard tab in the Incident Manager.

  2. Select Incident Report. A Microsoft Word document (.docx) is downloaded to your desktop containing all the incident details.

Relevant Links

soar-journey-complete.png

Congratulations! Your Onboarding Journey for Chronicle SOAR is complete!

Version history
Last update:
3 weeks ago
Updated by: