Set up Threat Intelligence Security Center
Summarize
Summary of Set up Threat Intelligence Security Center
The Threat Intelligence Security Center (TISC) is a ServiceNow application that must be downloaded from the ServiceNow Store before use. It enables customers to ingest, enrich, analyze, and manage threat intelligence data efficiently within their ServiceNow environment. Proper role assignments and prerequisite plugins are essential for successful configuration and operation.
Show less
Key Features
- Role-Based Access: Two primary user personas are defined:
- Threat Intelligence Administrator (snsectisc.admin): Responsible for installing the TISC app, configuring data sources, integrations for enriching observable data, data import approvals, threat score calculators, taxonomies, and the MITRE ATT&CK repository.
- Threat Intelligence Analyst (snsectisc.analyst): Can view data overviews, import intelligence data, search and manage ingested data, perform enrichment actions, and create/manage cases.
- Scripting Access Roles: Specific roles provide scripting permissions on key tables related to integrations, enrichment, and threat score calculation.
- Integration Configuration: Administrators must configure data sources, enrichment integrations, and define threat scoring criteria to automate threat intelligence processing.
Prerequisites and Dependencies
Before configuring TISC, ensure the following plugins and applications are installed and activated, as they provide essential support components:
- Security Case Management and common workspace components
- Threat Intelligence Support Common
- Column Level Encryption
- Large JSON and XML Payload Builder API
- Security Support Core
- Node Map Experience Component
- Reporting UI Component for Workspace
- Rich Text Editor Component for Security Operations
- Security Integration Framework
- Security Support Common and Orchestration
Practical Guidance for ServiceNow Customers
- Installation: Download and install the TISC application from the ServiceNow Store.
- Role Assignment: Assign the snsectisc.admin role to administrators to enable configuration capabilities and optionally assign snsectisc.analyst roles to users who will perform analysis and case management.
- Configuration: Set up data sources, enrichment integrations, import approvals, threat score calculators, taxonomies, and MITRE ATT&CK repository relevant to your organization’s needs.
- Verification: Confirm all prerequisite plugins and core applications are installed and activated to ensure smooth integration and functionality.
By following these steps, customers can efficiently configure and use the Threat Intelligence Security Center to enhance their security operations with integrated threat intelligence management.
Before you use the Threat Intelligence Security Center, you must download it from the ServiceNow Store.
Roles installed
- Threat Intelligence Analyst (sn_sec_tisc.analyst)
- Threat Intelligence Administrator (sn_sec_tisc.admin)
| Setup | Description |
|---|---|
| Assign and verify the required ServiceNow AI Platform and Threat Intelligence Security Center roles. | The following roles are required for configuration and verification of the expected results:
|
Granular roles in TISC with scripting access
| Role | Table |
|---|---|
| sn_sec_tisc.integration_write | sn_sec_tisc_enrichment_integration |
| sn_sec_tisc.rules_write | sn_sec_tisc_threat_score_calculator_rule |
Dependency Plugins
| Plugin | Description |
|---|---|
This following applications are required for installation of this application:
|
Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you configure this integration. |