Set up Threat Intelligence Security Center
Summarize
Summary of Set up Threat Intelligence Security Center
The Threat Intelligence Security Center (TISC) application must be downloaded from the ServiceNow Store before use. It provides a centralized platform for managing threat intelligence data by ingesting, enriching, and analyzing threat information to enhance security operations.
Show less
Roles and Access
TISC defines specific user roles to manage and interact with the application effectively:
- Threat Intelligence Administrator (snsectisc.admin): Responsible for configuring data sources, integrations, data import roles, threat scoring, taxonomies, and the MITRE ATT&CK repository. This role also assigns the Threat Intelligence Analyst role.
- Threat Intelligence Analyst (snsectisc.analyst): Focuses on viewing data dashboards, importing threat intelligence, searching and managing data, performing enrichment on observables, and creating/managing cases.
Granular scripting roles are also provided for integration, enrichment, and threat scoring configurations, enabling controlled programmatic access to specific tables.
Configuration and Setup
To ensure smooth integration and operation, administrators must:
- Install TISC from the ServiceNow Store and assign the snsectisc.admin role.
- Configure data sources to ingest threat intelligence feeds.
- Set up enrichment integrations to enhance observable data.
- Define data import approval roles to manage data imports securely.
- Configure threat score calculators based on organizational criteria for automatic scoring.
- Create and manage taxonomies and taxonomy values relevant to threat data classification.
- Integrate and customize the MITRE ATT&CK repository according to organizational needs.
Required Dependencies
The TISC application relies on several critical ServiceNow core plugins and applications, which must be installed and active before configuration, including:
- Security Case Management and common workspace components
- Threat Intelligence Support Common
- Column Level Encryption
- Large JSON and XML Payload Builder API
- Security Support Core
- Node Map Experience Component
- Reporting UI Component for Workspace
- Rich Text Editor Component for Security Operations
- Security Integration Framework
- Security Support Common and Orchestration
Verifying these dependencies ensures the TISC application functions correctly and integrates seamlessly with the ServiceNow Security Operations ecosystem.
Before you use the Threat Intelligence Security Center, you must download it from the ServiceNow Store.
Roles installed
- Threat Intelligence Analyst (sn_sec_tisc.analyst)
- Threat Intelligence Administrator (sn_sec_tisc.admin)
| Setup | Description |
|---|---|
| Assign and verify the required ServiceNow AI Platform and Threat Intelligence Security Center roles. | The following roles are required for configuration and verification of the expected results:
|
Granular roles in TISC with scripting access
| Role | Table |
|---|---|
| sn_sec_tisc.integration_write | sn_sec_tisc_enrichment_integration |
| sn_sec_tisc.rules_write | sn_sec_tisc_threat_score_calculator_rule |
Dependency Plugins
| Plugin | Description |
|---|---|
These following applications are required for installation of this application:
|
Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you configure this integration. |