Using the Zero-day Vulnerability Playbook
Use these steps to learn how you can use the Zero-day Vulnerability Playbook in the MSIM Workspace and its capabilities.
Before you begin
Role required: sn_msi.workspace_manager
Procedure
- Navigate to Workspaces > Major Security Incident Management > Major Security Incidents.
-
Select MSI number
It takes you to the playbook page.
- Go to the Ellipsis menu.
-
Select Add Playbook.
It opens the playbook selection menu.
- Select the Zero- day Vulnerability Playbook.
- Select Add Playbook.
- Select each lane to explore the tasks this playbook performs.
- Select the first lane Identification & Assessment.
-
It has two activities Determine vulnerable assets and Determine impacted customers which creates an MSI task.
Note:All the tasks can be customized according to your needs.
-
Open Determine vulnerable assets.
It’s used to identify the assets that are exposed to risks or vulnerabilities.
- Enter the title and provide a detailed description of the task to clarify the objective.
- Set the priority to confirm the incident is addressed with the appropriate urgency.
-
Select the appropriate Assignment Group from the menu.
Note:Selecting an assignment group is required.
- Set the due date based on the urgency of the incident.
-
Select Mark Complete to complete the task.
This activity creates an MSI task and assigns it to that particular assignment group.
-
Move to the next activity Determine impacted customers.
It’s used to identify customers affected by vulnerabilities or security incidents.
- Enter the title and provide a detailed description of the task to clarify the objective.
-
Select Mark Complete to complete the task.
Note:All the lanes are sequential. Complete one lane to unlock and move on to the next.
- Move to second lane Monitoring and Intelligence.
-
It has one activity Monitor threat intel for additional info on Vulnerability.
It’s used to track and analyze threat intelligence to gather more information on vulnerabilities.
- Enter the title and provide a detailed description of the task.
- SelectMark Complete to complete the task.
- Move to the third lane Communication and Response.
- It has two activities Draft communication about vulnerability and Prepare mitigation plan.
-
Open Draft communication about vulnerability.
It’s used to prepare and draft communication to inform stakeholders about the vulnerability.
- Enter the title and provide a detailed description of the task.
-
Select the appropriate Assignment Group from the menu to assign the vulnerability to a specific team.
Note:Selecting an assignment group is required.
- Select Mark Complete to complete the task.
-
Move to the next activity Prepare mitigation plan.
It’s used to develop a detailed plan to mitigate the impact of the vulnerability and reduce associated risks.
- Enter the title and provide a detailed description of the task to clarify the objective.
-
Select the appropriate Assignment Group from the menu.
Note:Selecting an assignment group is required.
- Select Mark Complete to complete the task.