
iTRAC Workflows
5
107
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
5
iTRAC Workflows
Section 5.1, “Understanding iTRAC Workflows,” on page 107
Section 5.2, “Introduction to the User Interface,” on page 108
Section 5.3, “Template Manager,” on page 109
Section 5.4, “Template Builder Interface,” on page 110
Section 5.5, “Steps,” on page 114
Section 5.6, “Transitions,” on page 125
Section 5.7, “Activities,” on page 133
Section 5.8, “Process Management,” on page 142
5.1 Understanding iTRAC Workflows
iTRAC Workflows are designed to provide a simple, flexible solution for automating and tracking
an enterprise’s incident response processes. iTRAC leverages Sentinel’s internal incident system to
track security or system problems from identification (through correlation rules or manual
identification) through resolution.
Workflows can be built using manual and automated steps. Advanced features such as branching,
time-based escalation, and local variables are supported. Integration with external scripts and plug-
ins allows for flexible interaction with third-party systems. Comprehensive reporting allows
administrators to understand and fine-tune the incident response processes.
NOTE:
Access to manage iTRAC templates, activities, and processes can be enabled on a user-by-
user basis by any user with the ability to change user permissions.
The iTRAC system uses three Sentinel objects that can be defined outside the iTRAC framework:
Table 5-1
Sentinel Objects used by iTRAC
iTRAC Workflows have four major components that are unique to iTRAC:
Incident
Incidents within Sentinel are groups of events that represent an actionable
security incident, plus associated state and meta-information.
Incidents are created manually or through correlation rules, and can, but need not
be associated with a workflow process. They can be viewed on the Incidents tab.
Activity
An Activity is a pre-defined automatic unit of work, with defined inputs, command-
driven activity, and outputs (for example, automatically attaching asset data to the
incident or sending an e-mail).
Activities can be included in a workflow template and executed during workflow
processes, or they can be executed within an incident.
Role
Sentinel users can be assigned to one or more Roles. Manual steps in the
workflow processes can be assigned to a Role.
Summary of Contents for SENTINEL 6.1 SP2
Page 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Page 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Page 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Page 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...