Improve security incident routing for the security analysts by configuring the Advanced Work Assignment (AWA) for Security Incident Response Workspace.
Procedure
-
Configure a service channel.
-
Navigate to .
-
Select the Security Incident service channel.
-
Configure assignment rules for assigning security incidents.
-
Navigate to .
-
Select Security Incident assignment rule.
The Security Incident assignment rule is available in the base system. For information about how to customize assignment rules, see Configure agent assignment rules.
- Optional:
Enable auto-assignment of analysts by selecting Enable auto-assign work items.
- Optional:
Enable security analysts to reject a security incident by navigating to the Rejection handling tab and selecting Allow agent to reject.
-
Determine which incidents to route to a particular security analyst through a given service channel by configuring queues.
-
Navigate to .
-
Select Security Incident Queue.
The Security Incident Queue is available in the base system. You can customize the queue as needed.
Create additional queues if you need. For each new queue, define Work Item Routing Conditions to ensure that security incidents are directed to the appropriate queue. For more
information, see Create a work item queue.
-
In the Assignment Eligibility section, select New.
-
On the form, fill in the fields.
-
Select Submit.
-
Configure presence states for security analysts to enable them to indicate whether they’re available to receive work.
-
Navigate to .
-
Add or update available presence states for an analyst.
By default, the Available state is inactive. If the Available state isn’t enabled,
AWA doesn’t route incidents to security analysts. For more information, see
Configure agent presence states.
-
Configure reject reasons for an analyst to select when rejecting a security incident.
Note: If you don’t enable rejection handling, security incidents are auto-assigned to analysts based on the configured service channel, queues, assignment rules, and analyst's availability.
-
Navigate to .
-
Add or update rejection reasons available to a security analyst.