Checklist for MSIM setup
Summarize
Summary of Checklist for MSIM setup
This checklist guides ServiceNow customers through the complete installation and configuration process of the Major Security Incident Management (MSIM) application, version 1.1.1, available from the ServiceNow Store. It ensures all components, roles, integrations, and settings are correctly established to enable effective management of major security incidents.
Show less
Setup and Installation
- Application Installation: Confirm the MSIM application and its dependent applications (such as File Explorer Core, Microsoft SharePoint File Explorer Connector, Microsoft Teams Chat Connector, and Security Incident Response v12.8.1) are installed and activated in the proper order.
- User Roles Assignment: Assign appropriate MSIM roles including MSI Administrator, MSI Manager, and MSI Responder to users involved in incident lifecycle management.
Microsoft SharePoint Configuration
- Set up Microsoft SharePoint v1.0.0 integration by configuring REST and Graph connections to your ServiceNow instance.
- Create or use an existing SharePoint site, then establish a dedicated document library for storing incident-related documents.
- Manage user and group permissions within SharePoint to control access appropriately.
- Configure the Microsoft SharePoint Drive and File Explorer Connector components, including Folder and File Actions and Folder Templates, to organize incident documentation by incident type.
Microsoft Teams Integration
- Establish and verify Microsoft Teams Chat Connector setup by configuring MS Teams Graph connections and credentials within the ServiceNow AI Platform instance.
- Create chat channel templates for collaboration on major security incidents.
MSIM Configuration and Administration
- Administration Settings: As an MSI Administrator, configure settings to allow security analysts to propose, promote, and link incidents; manage notification preferences; and customize security tags and default template messages to differentiate incident statuses.
- Notification Settings: Enable email notifications to alert configured users and groups when incidents are proposed or promoted within MSIM.
- Promotion Flow Activation: Ensure both SI to MSI Promotion Flow Designer flows (for SharePoint and Teams) are copied and activated independently to fully enable incident promotion functionality across both components.
Practical Benefits
Following this checklist enables ServiceNow customers to deploy a fully integrated MSIM environment that leverages SharePoint for document management and Microsoft Teams for communication. Proper role assignments and configuration ensure secure, efficient collaboration and incident lifecycle management, while notification and promotion flows keep all stakeholders informed and processes streamlined.
Before using the ServiceNow® Major Security Incident Management (MSIM) application, download the application from the ServiceNow® Store.
Track your progress with the setup, installation, and configuration from the following table.
| Setup task | Description |
|---|---|
|
Verify that the Major Security Incident Management application is installed and activated from the ServiceNow® Store. |
Major Security Incident Management v1.1.1 is available on ServiceNow® Store. Follow these instructions: downloading an application from the ServiceNow Store. |
|
Verify that the following applications are installed in the given order. |
The following applications will be installed by default after you install Major Security Incident Management application in the current application release version:
|
|
Verify that the user roles are assigned to Major Security Incident as appropriate. |
The following roles are involved throughout the incident life-cycle of Major Security Incident remediation process:
|
|
Verify that you have successfully setup Microsoft SharePoint v1.0.0 configuration. |
Microsoft SharePoint manages sites, folders, files, groups, and users in Microsoft SharePoint. Add Microsoft SharePoint data to your ServiceNow® instance. To do this you must setup Graph and Rest connections. For information, see Microsoft SharePoint spoke v1.1.2 documentation on how to setup REST and Graph connections Configuration. Establish Graph and REST connection to connect to your ServiceNow® instance from Microsoft SharePoint. |
|
Verify that you have created a Microsoft SharePoint site to create a document library. |
Create a Microsoft SharePoint site, if required or you can use an existing site to create the document library. |
|
Verify that you have created a document library under the Microsoft SharePoint site. |
Create a dedicated document library under a new or existing Microsoft SharePoint site. |
|
Verify that required permissions are provided to the users and assigned to the required user groups in the Microsoft SharePoint. |
Manage access from Microsoft SharePoint site to different users and user groups. |
|
Verify that you have created and configured Microsoft SharePoint Drive and necessary configuration settings. |
To verify the drive configurations, setup Microsoft SharePoint File Explorer Connector, Folder, and File Actions and Folder Templates:
|
| Verify that you have successfully established a connection to Microsoft Teams Chat Connector application. |
To establish Microsoft Teams Chat Connector application connection with ServiceNow® instance, follow the procedure explained here: Establish MS Teams Graph connection on ServiceNow AI Platform. |
|
Verify that you have configured Microsoft teams with ServiceNow AI Platform® instance and created connections and credentials configurations. |
To verify Microsoft Teams configuration with ServiceNow® instance, follow the procedure as explained here:
|
| Verify that the Major Security Incident Administration - Configuration settings are successful. |
As an MSI Administrator, you must be able to:
|
| Verify that the Major Security Incident Administration - Notifications settings are successful. | As an MSI Administrator, trigger email notifications when a security incident is proposed and are sent to all those users and groups who are configured to the notifications list. For more information, see Set notification preferences for MSIM. |
| Verify that the SI to MSI Promotion Flow Designer flows are copied and activated. | Both the SI to MSI Promotion (SharePoint) and SI to MSI Promotion (Teams) flows must be copied and activated independently. If only one flow is active, only the corresponding component (File Explorer or Chat) is set up when a security incident is promoted. |