Getting started with MISP integration for Security Operations
Review the following information before you set up your MISP integration for Security Operations.
| Setup task | Description |
|---|---|
| Verify that you have assigned the required ServiceNow AI Platform, Threat Intelligence, and Security Incident Response roles. | The following roles are used across the MISP features on the ServiceNow AI Platform:- The administrator \(admin\) installs the applications from the ServiceNow Store and assigns the security incident administrator \(sn\_si.admin\) and threat intelligence administrator \(sn\_ti.admin\) roles. - sn\_si.admin and sn\_ti.admin can configure the integration and set up the automatic MISP event creation profiles. - sn\_sec\_misp.write - The MISP analyst role has read and write permissions for MISP data that includes the event and attribute data. For more information, see Setup Threat Intelligence. |
| Assign the required MISP user roles. | Review the MISP user roles and the permissions required to use the MISP integration for Security Operations.Note: For more information about the user roles in MISP, see the Roles section in the MISP documentation website. |
| Verify that you are using MISP version 2.4.137 or later. | The MISP integration for Security Operations is tested with a minimum MISP version 2.4.137. |
| Verify that the ServiceNow core applications that are required to support the MISP module are installed and activated. | Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation. - Security Incident Response - ServiceNow IntegrationHub Runtime \(com.glide.hub.integration.runtime\) - ServiceNow IntegrationHub Action Step - REST \(com.glide.hub.action\_step.rest\) For more information on setting up your ServiceNow AI Platform instance for the integration, see get entitlement for a Security Operations product or application and activate a ServiceNow Store application. |
| Domain separation | Verify the domain separation section if you intend to separate data, processes, and administrative tasks. |
- MISP user roles and permissions
Review the user roles that are required in the MISP integration for Security Operations integration.
Parent Topic:MISP administration
Related topics
Install and configure the MISP integration for Security Operations
Review the MISP integration settings
Configure MISP sighting searches