Once security events raised by our SIEM/SOC have been reviewed and investigated by you, they need to be closed to ensure that you have an accurate record of their outcome, which is a key requirement of compliance standards such as ISO27001 and PCI DSS.
Closing events in the my.defense.com platform is super straightforward - simply follow the steps outlined below.
Closing events from the security event view
From the my.defense.com dashboard, select SIEM in the navigation on the left-hand side
Next, select Security Events from the navigation sub-menu
Locate the security event you wish to close and click View security event, which is located under the actions heading on the right-hand side
Once you have reviewed the event and are happy to close it, select Close Security Event in the top right-hand corner
Complete the Justification field - including details on why the event is being closed and what the outcome of the event was.
Finally, select Security Incident or False Positive, and the event will be closed down.
Closing events from the threat view
From the my.defense.com dashboard, select Threats from the navigation on the left-hand side
Locate the threat you wish to close. You can filter by the type Security Event to view all open threats generated by our SIEM/SOC
Click the View threat action button on the right-hand side
Next, head to the Remediations tab
Now select the remediation you wish to update by clicking the checkboxes and selecting either Remediated or False Positive from the status dropdown at the bottom of the page
Once that's done, click Apply
Next, you'll be asked to complete the Overview field - including details on why the event is being closed and what the outcome of the event was
Once the overview is complete, select Submit, and the threat will be closed
Please note:
Closing a threat or security event will also close the threat/security event it's linked to.
Anything entered into the Justification or Overview fields will be included in your monthly SIEM report.
And that's it! You now know how to close security events π
