Provides the necessary functionality to support Security Operations applications, including Security Incident Response and Vulnerability Response. This application supports integrations, email processing, filter groups, security tags, workflows, and so on.
Dependency for Vulnerability Response and Security Incident Response applications.
New
As the new AVR integrations are created in New Integration Framework (app-vul-int-framework), there were some additional changes done to incorporate the same. Along with this, as Wiz integration supports all the types of integrations: AVR, CVR and Host VR, and AVR integration logic earlier worked only on integration_type=APPVUL, additional checks are incorporated to consider additional_integration_types field.
Permissions and roles:
- Role required:
- System Admin (admin) or Vulnerability Admin (sn_vul.vulnerability_admin) for VR.
- Security Incident Administrator (sn_si.admin) for SIR.