Day 1
Module 1: Implementation Planning
Objectives
- Identify Goals of Security Incident Response
- Discuss how Security Incident Response Meets Customer Expectations
- Explain Security Incident Response Dashboards & Reports
- Identify Security Incident Response Components
Labs
- Lab 1.1 Initial Application Setup
Module 2: Security Incident - Form and Field Basic Configurations
Objectives
- Explore Security Incident Form Configurations
- Review Security Incident Record Lifecycle
- Explore Security Incident Risk Calculations and Configurations
- Discuss Security Incident Security Tag Configuration
Labs
- Lab 2.1 Security Incident Response Workspace
- Lab 2.2 Security Incident Process Selection
- Lab 2.3 Security Incident Calculator Groups
- Lab 2.4 Configuring Security Tags
Module 3: Incident generation Configuration
Objectives
- Explore Security Incident Service Catalog Configuration
- Discuss Security Incident Email Parsing
- Explain Security Incident User Reported Phishing Configuration
- Explore Security Incident Integrations
Labs
- Lab 3.2 Configure Email Parsing
- Lab 3.3 Use Case: User Reported Phishing
Day 2
Module 4: Playbook Configuration - Advanced Configuration
Objectives
- Configure Playbooks and Runbooks in the SIR Workspace
- Explain and Configure Post Incident Reviews
- Overview Now Assist for SecOps
Labs
- Lab 4.1 Configuration Security Incident Playbooks
- Lab 4.3 Post Incident Reviews
Module 5: Threat Intelligence Configuration
Objectives
- General Threat Intelligence Overview
- Explore MITRE – ATT&CK Configuration
Labs
- Lab 5.2 Leverage the MITRE-ATT@CK Framework
Module 6: Integrations supporting ServiceNow’s Security Incident Response
Objectives
- ServiceNow Store Overview
- Explore Integration Use Cases
- Discuss Capability Framework
- Explain how to create Custom Integrations
Labs
- Lab 6.3: Integrations and Capabilities
- Lab 6.4 Custom Security Incident Integration
Module 7: Other Supporting SecOps Applications
Objectives
- Overview of Major Security Incident Management
- Configure Major Security Incident Management
- Explore the Threat Intelligence Security Center Application
- Data Lass Prevention Application Overview
Labs
- Lab 7.2 Configuring Major Security Incident Response