Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual page 407

Table of Contents

Advertisement

Network
Figure A-15
Incident Response Through iTRAC
Sentinel iTRAC transforms traditional security information management from a passive alerting and
viewing role to an actionable incident response role by enabling organizations to define and to
document incident resolution processes and then guide, enforce and track resolution processes after
an incident or violation has been detected.
Sentinel comes with "out-of-the-box" process templates that use the SANS Institute's guidelines for
incident handling. Users can start with these predefined processes and configure specific activities to
reflect their organization's best practices. These processes can be automatically triggered from
incident creation or correlation rules or manually engaged by an authorized security or audit
professional. iTRAC keeps an audit trail of all actions to support compliance reporting and historical
analysis.
A worklist provides the user with all tasks that have been assigned to the user and a process monitor
provides real-time visibility into process status during a resolution process life cycle.
iTRAC's activity framework enables users to customize automated or manual tasks for specific
incident-resolution processes. The iTRAC process templates can be configured by using the activity
framework to match the template with an organization's best practices. Activities are executed
directly from the Sentinel Control Center.
Sentinel 6.1 Rapid Deployment Architecture 407

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents