Getting started with MISP integration for Security Operations
Review the following information before you set up your MISP integration for Security Operations.
| Setup task | Description |
|---|---|
| Verify that you have assigned the required ServiceNow AI Platform, Threat Intelligence, and Security Incident Response roles. | The following roles are used across the MISP features on the ServiceNow AI Platform:
For more information, see Setup Threat Intelligence. |
| Assign the required MISP user roles. | Review the MISP user roles and the permissions required to use the MISP integration for Security Operations. Note: For more information about the user
roles in MISP, see the Roles section in the MISP documentation website. |
| Verify that you are using MISP version 2.4.137 or later. | The MISP integration for Security Operations is tested with a minimum MISP version 2.4.137. |
| Verify that the ServiceNow core applications that are required to support the MISP module are installed and activated. | Verify that the following Security Operations applications are installed and
activated from the ServiceNow Store. If not installed, install and activate
one application at a time in the following order to ensure a smooth installation.
For more information on setting up your ServiceNow AI Platform instance for the integration, see get entitlement for a Security Operations product or application and activate a ServiceNow Store application. |
| Domain separation | Verify the domain separation section if you intend to separate data, processes, and administrative tasks. |