Security Incident Management Premium dashboard
Summarize
Summary of Security Incident Management Premium dashboard
The Security Incident Management Premium dashboard leverages advanced Platform Analytics visualizations to help security managers monitor the lifecycle of security incidents—from detection and analysis through containment, eradication, and recovery. It requires the licensed version of Performance Analytics to function.
Show less
This dashboard provides critical insights into the volume, performance, and progress of security incidents, enabling security teams to maintain a clear view of their security posture and prioritize response efforts effectively.
End users and roles
- Security Response Manager (snsi.manager): Gains visibility into the overall state and volume of security incidents related to applications and services, with capability to adjust assignment groups.
- Security Response Administrator (snsi.admin): Quickly identifies areas of concern, fully controls Security Incident Response data, administers territories and skills, and adjusts risk calculation parameters to focus on the most pertinent vulnerabilities.
- Security Response Analysts (snsi.analyst): Prioritize vulnerabilities based on organizational criticality; Tier 1 and 2 analysts can create and update security incidents, requests, tasks, and related problems, changes, and outages.
Key Indicators and Metrics
The dashboard includes several workbench widgets and tabs with important indicators to measure incident management effectiveness:
- Process by State and Process by Age Tabs: Track average age of open incidents, average reassignment times, average age of last update, and percentage of incidents not updated in the last 5 days.
- Data Quality Tab: Offers interactive filters for incident category, risk, priority, and severity, applied to indicators such as incidents open for more than 30 days by assignment group and state, incidents with inactive or no assignees, and incidents not updated in over 30 days.
- KPI Tab: Displays key performance indicators including percentage of new critical incidents, average age and close time of open incidents, reassignment rates, first-assignment closure rates, self-service closure rates, unresolved incident percentages, and average close time of incident tasks.
Breakdowns
Indicators can be broken down by several dimensions to provide detailed insights:
- Security Group
- Security Incident Age
- Security Incident Category
- Security Incident Priority
- Security Incident State
This dashboard uses advanced Platform Analytics visualizations to aid security managers to track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery. The licensed version of Performance Analytics is therefore required.