Consolidated page of all release notes for Security Incident Response from Xanadu to Yokohama.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Security Incident Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Yokohama.
Tip: If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."
Important information for upgrading Security Incident Response to Yokohama
Before you upgrade to Yokohama, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release |
Release notes |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
New features
Between your current release family and Yokohama, new features were introduced for Security Incident Response.
| Release |
Release notes |
Xanadu |
- Security Incident Response integration with AWS Security Hub
- Security Incident Response supports the AWS Security Hub findings integration. This enables you to ingest AWS Security Hub findings and automatically create security incidents in Security Incident Response.
- Security Incident Response supports a bidirectional exchange of data with AWS Security Hub. SIR ingests findings from AWS Security Hub to create aggregated security incidents. Simultaneously, any
change in a security incident is also updated on the related AWS Security Hub findings.
- Internet Content Adaption Protocol (ICAP) integration for DLP IR
- Internet Content Adaption Protocol (ICAP) integration helps you to track the usage and movement of sensitive data on various platforms.
- Configure and schedule DLP alerts ingestion from the specified Amazon S3 buckets which includes the capability to perform the delta imports to ensure only new or modified data is ingested.
- Display the ingested alerts in the DLP workspace by providing the key details on each alert such as the match content, alert severity, and relevant metadata.
- Download associated evidence files directly from the DLP workspace for further investigation or review.
- Enable users to apply automatic responses based on predefined criteria such as alert escalation, notifications, or enforcement policies.
- Remediate response actions such as blocking or quarantining sensitive data, or sending out alerts to stakeholders.
- Customize and define the severity mapping between ICAP DLP incidents with ServiceNow incidents.
- Playbook for zero-day vulnerability
- Get step-by-step procedure to address and mitigate zero-day threats—vulnerabilities in the software that are unknown to the vendor, leaving systems exposed to attacks.
- Configure Shift Handover Templates
- Provide detailed communication of critical information, tasks, and updates between outgoing and incoming personnel for a seamless transition between shifts by using the Shift Handover feature. Improve operational continuity,
reduce errors, and increase overall efficiency in the workplace.
- Configure Slack chat connector for major security incidents
- View and filter collaboration chat activities on Slack to more efficiently collaborate to resolve major security incidents.
- Playbook for Legal Request
- Get step-by-step guidance on how you can inform the legal team about the latest summary of a major security incident so they can notify the SEC in the 4-day time frame that is required for material breaches.
- Add Zscaler Internet Access URL category lists
- Enable Zscaler approvers to add observables to the list of required approvals or remove them when the Require Approval option is selected.
- Configure how an automatic event is created and MISP event data
- Add security tags during automatic MISP profile configuration.
- Mapping DLP incident status with Netskope
- Provide the mappings between the DLP Incident status in your ServiceNow instance and the Netskope Object status.
- Define the new Risk Score Calculator Rules
- The Risk score configuration in the Security Incident Response workspace has been enhanced with the following capabilities:
- Set up a Risk Score Calculator from either script or condition builders.
- Apply multiple conditions while setting up rule-based scoring.
- Apply weightage to each scoring line. Weights should add up to 100.
- For rule-based scoring, select table fields and values for setting up a condition.
- Capture conditions and scoring via scripts.
- Manually execute risk score calculators to recalculate after making changes.
- Managing MSIM status reports
- Share mobile-friendly Executive Status Reports with users outside your ServiceNow instance, including third-party vendors, other entities, or email distribution lists.
|
Yokohama |
- Process Mining for security incidents
- Identify factors contributing to delays in processing Security Incident Response (SIR) incidents that take a long time to close or resolve by scanning historical SIR records through Process Mining. Time-consuming factors can include multiple reassignments, prolonged hold
times, and periods of inactivity.
- CrowdStrike Next-Gen SIEM integration
-
As a Profile Admin:
- Discover CrowdStrike Next-Gen SIEM detections that are candidates for security incidents and automate the creation of these security incidents.
- Create detection profiles.
- Map CrowdStrike Next-Gen SIEM Detection and Events Fields to SIR security incident fields.
- Filter CrowdStrike Next-Gen SIEM defects.
- Aggregate detections to existing open security incidents so that you don't have to create duplicate security incidents.
- Schedule ongoing detection ingestion.
- Automate CrowdStrike Next-Gen SIEM detection status updates for Security Incident Response.
- Synchronize CrowdStrike Next-Gen SIEM detection comments with SIR Work notes.
- Create an event profile
-
- Enables bidirectional updates and closure synchronization between Splunk ES and Splunk integrations.
- Enables retrieval of historical, and ongoing data including closed events, with an option to pull the closed events into the
ServiceNow
Splunk ES instance.
- Receive updates for the mapped fields in SIR.
- Components installed with Security Incident Response
- A new Profile Admin role (sn_si.ingestion_profile_admin) provides access to configure plugins, and create, edit, delete, and manage profiles for the Splunk, Splunk ES, and Azure Sentinel Integration for Security Operations application.
- Add indirectly linked VITs to CVEs
- Identify all the Third-Party Entities (TPEs) associated with a Common Vulnerabilities and Exposures (CVE) and then calculate and display the total number of vulnerable items (VITs) indirectly linked to those CVEs through the
TPEs by setting the sn_ti.include_cve_vit_indirect_relation property.
- Configure on-call schedules
- As an admin:
- Create a shift and assign or remove members to/from the shift.
- Create/edit on-call schedules for groups.
- View any group’s on-call schedule, including those to which they belong.
As an analyst:
- Specify your availability and preferred contact methods.
- View your on-call schedule and see other members of your shift.
- Configure report templates in Security Incident Response
- As an admin, create report templates that can be used to generate an incident summary or an executive summary for analysis and sharing.
As an analyst, use the templates to generate analyst summary or executive summary
reports for a SIR incident that can be shared over email.
- Security Incident Response conference call integration
- Initiate conference calls using communication channels such as Microsoft Teams, Cisco Webex, or Zoom with customers and peer agents to resolve security incidents over a call by using the SIR conference call feature.
- Enhancements to relationship graphs
-
As an admin:
- Define default child nodes to populate in the relationship graph.
- Configure relationship labels.
As an analyst:
- Add or remove child nodes at the parent node level.
- Save the state of the relationship graph.
- Retrieve updated data.
- Proofpoint integration for Security Operations
- Proofpoint integration for Security Operations supports integration between SOAR (Security Orchestration, Automation, and Response) and Proofpoint Targeted Attack Protection (TAP) software. This integration provides the following benefits:
- Detect and block threats such as business email compromise and tags suspicious emails for tracking, analysis, and audit.
- Import data to automatically create security incidents for email events that are not captured by TAP products.
- Data Loss Prevention Incident Response Analyst Workspace
- Preview the evidence file of the incident from either the Data Loss Prevention analyst workspace or the DLP end user workspace.
|
Changes
Between your current release family and Yokohama, some changes were made to existing Security Incident Response features.
| Release |
Release notes |
Xanadu |
|
Yokohama |
|
Removed
Between your current release family and Yokohama, some Security Incident Response features or functionality were removed.
| Release |
Release notes |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Deprecations
Between your current release family and Yokohama, some Security Incident Response features or functionality were deprecated.
| Release |
Release notes |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Activation information
Review information on how to activate Security Incident Response.
| Release |
Release notes |
Xanadu |
Install Security Incident Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
|
Yokohama |
Install Security Incident Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
|
Additional requirements
If any additional requirements were introduced or changed for Security Incident Response we have noted them here.
| Release |
Release notes |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Security Incident Response we have noted them here.
| Release |
Release notes |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Accessibility information
Review details on accessibility information for Security Incident Response, such as specific requirements or compliance levels.
| Release |
Release notes |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Localization information
If there are specific localization considerations for Security Incident Response we have noted them here.
| Release |
Release notes |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Security Incident Response we have noted them here.
| Release |
Release notes |
Xanadu |
- Define and calculate the risk score of security incidents through the Risk Score Calculator, which is based on user-defined criteria. The risk score is auto-calculated for the security incident records.
- Track the handover of important work items between shifts through the Shift Handover application.
- Automatically create dedicated Slack channels for Incident Managers to engage with Incident Responders to manage major security incidents with the MSIM
Slack integration.
- Facilitate the ability of the Incident Manager to provide a summary of a major security incident to their Legal teams by using the MSIM Legal Request playbook. The Legal team can use that summary when filing an 8K or 10K form to comply with regulatory bodies such as the SEC when disclosing security breaches.
- Share mobile-friendly MSIM Executive Status Reports generated in email format. You can also share the Executive Status Reports with users outside your ServiceNow® instance, including third-party vendors, other entities, or email distribution lists.
|
Yokohama |
- Identify inefficiencies and optimize the resolution process of security incidents for faster closure by using Process MIning.
- Implemented CrowdStrike Next-Gen SIEM integration enabling real-time ingestion of correlated detections, and enrichment data.
- Enhanced Splunk ES integrations to improve incident classification and enable efficient retrieval of historical data and alerts.
- Include the number of VITs indirectly associated with a CVE through TPEs.
- Help managers ensure there are no gaps in coverage and analysts are always available to address security incidents by configuring shifts for analysts.
- Define default child nodes to populate in the relationship graph, and add or remove child nodes at the parent node level.
See Security Incident Response for more information.
|