Create a security incident knowledge article
As you work with security incidents and response tasks, knowledge articles automatically display to provide pertinent information about the task you're performing. Your organization can create and maintain articles in the security incident knowledge base.
Before you begin
Role required: sn_si.knowledge_admin
About this task
If needed, you can organize knowledge articles into runbooks, which create associations between the articles and specific tasks. For example, you can configure a runbook with conditions that cause a knowledge base article about phishing to be displayed when you're creating a security incident for a phishing attack. For more information, see Create a Security Incident Response runbook.
Knowledge articles in runbooks can also be associated with specific tasks in a playbook. For more information, see Associate a knowledge article with a playbook task.
- Employees have one source of information that is easy to search.
- Information can be kept up-to-date, as knowledge articles have a defined life cycle: create, review and update, publish, and retire.
- When you manually create a security request, incident, or response task, a list of relevant articles is presented as you type the short description.
Procedure
What to do next
Any additional steps required to publish the article, such as approvals, depend on the publishing workflow for the knowledge base.