Before you use the Threat Intelligence Security Center, you must download it from the ServiceNow Store.
Roles installed
Review the following information and verify that you’ve completed all the tasks for a smooth integration. Below is the list of different user persona defined to access and work with the application:
- Threat Intelligence Analyst (sn_sec_tisc.analyst)
- Threat Intelligence Administrator (sn_sec_tisc.admin)
表 : 1. Entitlements applicable for TISC Roles
| Setup |
Description |
| Assign and verify the required ServiceNow AI Platform and Threat Intelligence Security Center roles. |
The following roles are required for configuration and verification of the expected results:
- As an admin, you must install the TISC application from the ServiceNow Store and assign the role as sn_sec_tisc.admin.
- This sn_sec_tisc.admin role performs the following tasks:
- Configures the Data Sources to ingest the data. For more information, see Threat Intelligence Feeds.
- Configured the integrations required for Enriching Observable data in TISC. For more information, see TISC Enrichment Integrations.
- Configures Data Import Approval Roles for importing data using Import Assistant. For more information, see Working with Data Imports.
- Configures Threat Score Calculator using required criteria for automatic calculation of Threat Score of observables. For more information, see Define Threat Score Calculator.
- Configures required Taxonomies and Taxonomy Values. For more information, see Creating Taxonomies.
- Configure the MITRE ATT&CK repository relevant to your organization. For more information, see MITRE-ATT&CK Repository.
注: As a sn_sec_tisc.admin, you can also assign the sn_sec_tisc.analyst role.
- The sn_sec_tisc.analyst role performs the following tasks:
|
Dependency Plugins
| Plugin |
Description |
This following applications are required for installation of this application:
- Security Case Management common workspace components [com.snc.escm.ws_commons].
- Threat Intelligence Support Common [com.snc.threat].
- Column Level Encryption (com.glide.encryption)
- Large JSON and XML Payload Builder API (com.glide.streaming_builder)
- Security Support Core (com.snc.security_support.core)
|
Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you configure this integration. |