Review the following information before you set up your MISP integration for Security Operations.

Table 1. Checklist
Setup task Description
Verify that you have assigned the required ServiceNow AI Platform, Threat Intelligence, and Security Incident Response roles. The following roles are used across the MISP features on the ServiceNow AI Platform:
  • The administrator (admin) installs the applications from the ServiceNow Store and assigns the security incident administrator (sn_si.admin) and threat intelligence administrator (sn_ti.admin) roles.
  • sn_si.admin and sn_ti.admin can configure the integration and set up the automatic MISP event creation profiles.
  • sn_sec_misp.write - The MISP analyst role has read and write permissions for MISP data that includes the event and attribute data.

For more information, see Setup Threat Intelligence.

Assign the required MISP user roles. Review the MISP user roles and the permissions required to use the MISP integration for Security Operations.
Note: For more information about the user roles in MISP, see the Roles section in the MISP documentation website.
Verify that you are using MISP version 2.4.137 or later. The MISP integration for Security Operations is tested with a minimum MISP version 2.4.137.
Verify that the ServiceNow core applications that are required to support the MISP module are installed and activated.
Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation.
  • Security Incident Response
  • ServiceNow IntegrationHub Runtime (com.glide.hub.integration.runtime)
  • ServiceNow IntegrationHub Action Step - REST (com.glide.hub.action_step.rest)

For more information on setting up your ServiceNow AI Platform instance for the integration, see get entitlement for a Security Operations product or application and activate a ServiceNow Store application.

Domain separation Verify the domain separation section if you intend to separate data, processes, and administrative tasks.