QuestionQ12

Platform operations

Your company's SOC analysts frequently submit manual change requests to a system administrator to modify firewall rules on a specific router. The firewall integration is installed and configured with credentials. You want to use the integration to trigger firewall-rule changes directly from Google Security Operations (SecOps) SOAR. Your system administrator requires the ability to manually approve requested changes before deployment. How should you implement the on-demand workflow for analysts to trigger?

Explanation

Google SecOps SOAR requests provide an on-demand, field-based intake mechanism that can trigger a playbook. The playbook can pass the requested firewall-rule value to the firewall integration action and configure that action as a manual, administrator-assigned pending action. The playbook pauses until the administrator approves or declines the action, providing approval before the rule is deployed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!