Itrac Workflows; Understanding Itrac Workflows - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

iTRAC Workflows

6
The iTRAC
workflows are designed to provide a simple, flexible solution for automating and
TM
tracking an enterprise's incident response processes. iTRAC leverages the Sentinel
incident system to track security or system problems from identification (through correlation rules
or manual identification) through resolution.
Section 6.1, "Understanding iTRAC Workflows," on page 123
Section 6.2, "Introduction to the User Interface," on page 124
Section 6.3, "Template Manager," on page 125
Section 6.4, "Template Builder Interface," on page 126
Section 6.5, "Steps," on page 129
Section 6.6, "Transitions," on page 141
Section 6.7, "Activities," on page 149
Section 6.8, "Process Management," on page 155

6.1 Understanding iTRAC Workflows

Workflows can be built using manual and automated steps. Advanced features such as branching,
time-based escalation, and local variables are supported. Integration with external scripts and plug-
ins allows for flexible interaction with third-party systems. Comprehensive reporting allows
administrators to understand and fine-tune the incident response processes.
NOTE: Access to manage iTRAC templates, activities, and processes can be enabled on a user-by-
user basis by any user with the ability to change user permissions.
The iTRAC system uses three Sentinel objects that can be defined outside the iTRAC framework:
Sentinel Objects Used by iTRAC
Table 6-1
Incident
Incidents within Sentinel are groups of events that represent an actionable
security incident, plus associated state and meta-information.
Incidents are created manually or through Correlation rules, and can be
associated with a workflow process. They can be viewed on the Incidents tab.
Activity
An Activity is a predefined automatic unit of work, with defined inputs, command-
driven activity, and outputs (for example, automatically attaching asset data to the
incident or sending an e-mail).
Activities can be included in a workflow template and executed during workflow
processes, or they can be executed within an incident.
Role
Sentinel users can be assigned to one or more roles. Manual steps in the
workflow processes can be assigned to a role.
iTRAC Workflows have four major components that are unique to iTRAC:
6
internal
TM
iTRAC Workflows
123

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents