Working on the Redaction Library
Redaction is the process of replacing sensitive information from shared data to protect confidentiality during intelligence sharing.
Before you begin
Role required: sn_sec_tisc.admin
About this task
This feature allows the you to redact or replace sensitive or personalized information with specific values.
Within the outbound intelligence sharing record, you can apply redaction library to automatically filter out specific attributes or content before the payload is generated.
In Threat intelligence sharing, the sensitive information which is defined as redaction category values, and is replaced with the corresponding redaction category.
This is especially useful when sharing data with external organizations, where only the relevant and non-sensitive information should be disclosed.
By leveraging the Redaction Library feature, TISC administrators and analysts can define reusable redaction configurations and apply them consistently across multiple sharing templates.
Procedure
Navigate to Workspaces > Threat Intelligence Security Center.
Select Administration icon on the workspace.
Go to Outbound Intel Sharing.
Select Redaction Library.
The Redaction Library list view is displayed.
Select New.
On the form, fill in the fields.
Field Description Redaction Category Specify the redaction category for the outbound intelligence sharing record. Status The status of the redaction category. By default, all the redaction categories are enabled. However, you can choose to disable a specific redaction category. Click Save.
Go to Redaction Category Values section.
Select New to create Redaction Category Value record.
| Field | Description |
|---|---|
| Redaction Category | Indicates the redaction category. Few examples of Redaction Category are as follows: - IP Address \(IPv4/IPv6\) - Organization\_Name - Domain Name - Email Address - Identification\_Number |
| Value | Indicates the value that needs to be redacted. |
- System Property for Redaction Library:
| Name | Description |
|---|---|
| sn\_sec\_tisc.case\_sensitive\_for\_redaction | This property enables or disables case sensitivity when applying redaction to shared intelligence.Default: Disabled ( Note: By default, this property is disabled making the redaction case insensitive. For example, Service_Now and service_now would both be redacted equally. Enabling it ( |
Select Save.
Bulk Import of Redaction Categories and Values
Import redaction categories. Bulk importing of redaction categories and their associated values.
Parent Topic:Exploring Outbound Intel Sharing
Related topics
Configuring Outbound Intel Sharing Controls
Configuring Outbound Intel Data Exclusion Rule
Configuring Outbound Intel Sharing Profiles
Configuring Outbound Intel Sharing Groups