Combined Security Incident Response release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Security Incident Response Release Notes for Upgrades from Yokohama to Zurich
This consolidated release notes document outlines the key new features, changes, and important upgrade information for ServiceNow Security Incident Response (SIR) as customers upgrade from the Yokohama to Zurich release family. It provides a comprehensive guide to enhancements that improve incident management, integration capabilities, automation, and analyst efficiency within the Security Incident Response application.
Show less
New Features
- Process Mining: Analyze historical security incident records to identify bottlenecks and delays in incident resolution, using methods such as multi-hop and bottleneck analysis.
- CrowdStrike Next-Gen SIEM Integration: Automate discovery, creation, and management of security incidents from CrowdStrike detections with profile administration, field mapping, filtering, aggregation, and synchronization of comments and status updates.
- Splunk ES and Splunk Integration Enhancements: Enable bidirectional updates, historical and ongoing event retrieval, and closure synchronization with ServiceNow Security Incident Response.
- Profile Admin Role: New role (snsi.ingestionprofileadmin) enables configuration and management of integration profiles for Splunk, Splunk ES, and Azure Sentinel.
- Third-Party Entities and CVE Linkage: Identify indirectly linked vulnerable items (VITs) through third-party entities associated with CVEs to enhance vulnerability tracking.
- On-Call Scheduling: Admins can create shifts, assign members, and manage schedules to ensure analyst availability; analysts can specify availability and contact preferences.
- Report Templates: Admins create reusable report templates for incident and executive summaries; analysts can generate and share reports via email.
- Conference Call Integration: Initiate conference calls via Microsoft Teams, Cisco Webex, or Zoom directly within SIR to facilitate collaboration during incident resolution.
- Relationship Graph Enhancements: Admins define default child nodes and labels; analysts can modify nodes and save graph state for efficient incident visualization.
- Proofpoint Integration: Automatically create incidents from email threat detections and block business email compromise threats using Proofpoint TAP.
- Data Loss Prevention (DLP) Workspace: Preview incident evidence files within DLP analyst and end-user workspaces.
- Integration with Cortex XSIAM: Profile admins manage ingestion profiles, map and filter incidents, aggregate alerts, and synchronize work notes for faster threat response.
- LLM-Powered Integration Builder: Quickly generate and customize integration code from API documentation, simplifying integration setup and maintenance.
- Deny Rules for Phishing Emails: Security admins can define rules to prevent false positive phishing emails from being converted into security incidents.
- MITRE D3FEND Framework: Ingest defense data and visualize attack-defense techniques interactively within security incidents.
- Editable Related Records: Analysts can update associated observables and related records directly from the incident context.
- Advanced Work Assignment (AWA): Automate incident assignments based on analyst availability, skills, and capacity to optimize response times.
- Duplicate Incident Prevention: Prevent creation of duplicate security incidents when IT incidents escalate to security incidents.
- Ingest Third-Party Risk Scores: Factor external risk scores into incident risk calculations for improved prioritization.
- Category Management: Admins can create and manage categories and subcategories in SIR Workspace to better classify incidents.
- Security Incident Details Tab: Includes fields for Functional Impact, Recoverability, and Information Impact to enhance triage and reporting accuracy.
- Bulk Close of Security Incidents: Close multiple incidents simultaneously using predefined closure comments or codes to save time.
- Send Observables to Threat Intelligence Service Catalog (TISC): Add metadata such as confidence scores and TISC tags before sending observables for threat intelligence sharing.
- User Access Visibility: Display initials of users currently viewing the same incident to avoid conflicts.
- Universal Search for Observables: Search across all observable fields within a security incident for faster data retrieval.
- IBM QRadar Integration: Fetch closed offenses and optimize offense polling batch sizes to improve integration performance.
Changes
- Microsoft Teams and SharePoint Integrations: Simplified setup for integration with Major Security Incident Management Workspace.
- Workflow Migration: Security Incident Response workflows and orchestration flows migrated to Workflow Studio for improved management.
- Security Incident Related Records: Support for linking multiple ITSM incidents, problems, or change requests to a single security incident to coordinate multiple IT actions.
- Attachment Restrictions: Modifying attachments on closed security incidents is no longer allowed.
- Access Controls: View and update permissions for security incidents can be
Consolidated page of all release notes for Security Incident Response from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Security Incident Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Security Incident Response to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Security Incident Response.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Security Incident Response features.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Security Incident Response features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Security Incident Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Security Incident Response.
| Release | Release notes |
|---|---|
Yokohama |
Install Security Incident Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
No updates for this release. |
Additional requirements
If any additional requirements were introduced or changed for Security Incident Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Security Incident Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Security Incident Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
Localization information
If there are specific localization considerations for Security Incident Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Security Incident Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Security Incident Response for more information. |
Zurich |
See Security Incident Response for more information. |