Skip to content

Commit e06658b

Browse files
natasha-moore-elasticmergify[bot]
authored andcommitted
Update text about risk scoring recalculation after file upload (#5924)
(cherry picked from commit dd3b9e7) # Conflicts: # docs/serverless/advanced-entity-analytics/asset-criticality.mdx
1 parent b76c1eb commit e06658b

File tree

2 files changed

+119
-2
lines changed

2 files changed

+119
-2
lines changed

docs/advanced-entity-analytics/asset-criticality.asciidoc

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ Entities do not have a default asset criticality level. You can either assign as
3030

3131
When you assign, change, or unassign an individual entity's asset criticality level, that entity's risk score is immediately recalculated.
3232

33-
NOTE: If you assign asset criticality using the file import feature, risk scores are **not** immediately recalculated. The newly assigned or updated asset criticality levels will impact entity risk scores during the next hourly risk scoring calculation.
33+
NOTE: If you assign asset criticality using the file import feature, risk scores are **not** immediately recalculated. However, you can trigger an immediate recalculation by clicking **Recalculate entity risk scores now**. Otherwise, the newly assigned or updated asset criticality levels will be factored in during the next hourly risk scoring calculation.
3434

3535
You can view, assign, change, or unassign asset criticality from the following places in the {elastic-sec} app:
3636

@@ -84,7 +84,9 @@ To import a file:
8484
NOTE: The file validation step highlights any lines that don't follow the required file structure. The asset criticality levels for those entities won't be assigned. We recommend that you fix any invalid lines and re-upload the file.
8585
. Click **Assign**.
8686

87-
This process overwrites any previously assigned asset criticality levels for the entities included in the imported file. The newly assigned or updated asset criticality levels are immediately visible within all asset criticality workflows and will impact entity risk scores during the next risk scoring calculation.
87+
This process overwrites any previously assigned asset criticality levels for the entities included in the imported file. The newly assigned or updated asset criticality levels are immediately visible within all asset criticality workflows.
88+
89+
You can trigger an immediate recalculation of entity risk scores by clicking **Recalculate entity risk scores now**. Otherwise, the newly assigned or updated asset criticality levels will be factored in during the next hourly risk scoring calculation.
8890

8991
[discrete]
9092
== Improve your security operations
Lines changed: 115 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
1+
---
2+
slug: /serverless/security/asset-criticality
3+
title: Asset criticality
4+
description: Learn how to use asset criticality to improve your security operations.
5+
tags: [ 'serverless', 'security', 'overview', 'analyze' ]
6+
status: in review
7+
---
8+
9+
<DocBadge template="technical preview" />
10+
11+
<DocCallOut title="Requirements">
12+
To view and assign asset criticality, you must:
13+
* Have the appropriate user role.
14+
* Turn on the `securitySolution:enableAssetCriticality` <DocLink slug="/serverless/security/advanced-settings" section="enable-asset-criticality-workflows" >advanced setting</DocLink>.
15+
16+
For more information, refer to <DocLink slug="/serverless/security/ers-requirements">Entity risk scoring prerequisites</DocLink>.
17+
</DocCallOut>
18+
19+
The asset criticality feature allows you to classify your organization's entities based on various operational factors that are important to your organization. Through this classification, you can improve your threat detection capabilities by focusing your alert triage, threat-hunting, and investigation activities on high-impact entities.
20+
21+
You can assign one of the following asset criticality levels to your entities, based on their impact:
22+
23+
* Low impact
24+
* Medium impact
25+
* High impact
26+
* Extreme impact
27+
28+
For example, you can assign **Extreme impact** to business-critical entities, or **Low impact** to entities that pose minimal risk to your security posture.
29+
30+
## View and assign asset criticality
31+
32+
Entities do not have a default asset criticality level. You can either assign asset criticality to your entities individually, or <DocLink slug="/serverless/security/asset-criticality" section="bulk-assign-asset-criticality">bulk assign</DocLink> it to multiple entities by importing a text file.
33+
34+
When you assign, change, or unassign an individual entity's asset criticality level, that entity's risk score is immediately recalculated.
35+
36+
<DocCallOut title="Note">
37+
If you assign asset criticality using the file import feature, risk scores are **not** immediately recalculated. However, you can trigger an immediate recalculation by clicking **Recalculate entity risk scores now**. Otherwise, the newly assigned or updated asset criticality levels will be factored in during the next hourly risk scoring calculation.
38+
</DocCallOut>
39+
40+
You can view, assign, change, or unassign asset criticality from the following places in the ((elastic-sec)) app:
41+
42+
* The <DocLink slug="/serverless/security/hosts-overview" section="host-details-page">host details page</DocLink> and <DocLink slug="/serverless/security/users-page" section="user-details-page">user details page</DocLink>:
43+
44+
![Assign asset criticality from the host details page](../images/asset-criticality/-assign-asset-criticality-host-details.png)
45+
46+
* The <DocLink slug="/serverless/security/hosts-overview" section="host-details-flyout">host details flyout</DocLink> and <DocLink slug="/serverless/security/users-page" section="user-details-flyout">user details flyout</DocLink>:
47+
48+
![Assign asset criticality from the host details flyout](../images/asset-criticality/-assign-asset-criticality-host-flyout.png)
49+
50+
* The host details flyout and user details flyout in <DocLink slug="/serverless/security/timelines-ui">Timeline</DocLink>:
51+
52+
![Assign asset criticality from the host details flyout in Timeline](../images/asset-criticality/-assign-asset-criticality-timeline.png)
53+
54+
### Bulk assign asset criticality
55+
56+
You can bulk assign asset criticality to multiple entities by importing a CSV, TXT or TSV file from your asset management tools.
57+
58+
The file must contain three columns, with each entity record listed on a separate row:
59+
60+
1. The first column should indicate whether the entity is a `host` or a `user`.
61+
1. The second column should specify the entity's `host.name` or `user.name`.
62+
1. The third column should specify one of the following asset criticality levels:
63+
* `extreme_impact`
64+
* `high_impact`
65+
* `medium_impact`
66+
* `low_impact`
67+
68+
The maximum file size is 1 MB.
69+
70+
File structure example:
71+
72+
```
73+
user,user-001,low_impact
74+
user,user-002,medium_impact
75+
host,host-001,extreme_impact
76+
````
77+
78+
To import a file:
79+
1. Go to **Project Settings** → **Stack Management** → **Asset criticality**.
80+
1. Select or drag and drop the file you want to import.
81+
82+
<DocCallOut title="Note">
83+
The file validation step highlights any lines that don't follow the required file structure. The asset criticality levels for those entities won't be assigned. We recommend that you fix any invalid lines and re-upload the file.
84+
</DocCallOut>
85+
86+
1. Click **Assign**.
87+
88+
This process overwrites any previously assigned asset criticality levels for the entities included in the imported file. The newly assigned or updated asset criticality levels are immediately visible within all asset criticality workflows.
89+
90+
You can trigger an immediate recalculation of entity risk scores by clicking **Recalculate entity risk scores now**. Otherwise, the newly assigned or updated asset criticality levels will be factored in during the next hourly risk scoring calculation.
91+
92+
## Improve your security operations
93+
94+
With asset criticality, you can improve your security operations by:
95+
96+
* <DocLink slug="/serverless/security/asset-criticality" section="prioritize-open-alerts">Prioritizing open alerts</DocLink>
97+
* <DocLink slug="/serverless/security/asset-criticality" section="monitor-an-entitys-risk">Monitoring an entity's risk</DocLink>
98+
99+
### Prioritize open alerts
100+
101+
You can use asset criticality as a prioritization factor when triaging alerts and conducting investigations and response activities.
102+
103+
Once you assign a criticality level to an entity, all subsequent alerts related to that entity are enriched with its criticality level. This additional context allows you to <DocLink slug="/serverless/security/analyze-risk-score-data" section="triage-alerts-associated-with-high-risk-or-business-critical-entities">prioritize alerts associated with business-critical entities</DocLink>.
104+
105+
### Monitor an entity's risk
106+
107+
The risk scoring engine dynamically factors in an entity's asset criticality, along with `Open` and `Acknowledged` detection alerts to <DocLink slug="/serverless/security/entity-risk-scoring" section="how-is-risk-score-calculated">calculate the entity's overall risk score</DocLink>. This dynamic risk scoring allows you to monitor changes in the risk profiles of your most sensitive entities, and quickly escalate high-risk threats.
108+
109+
To view the impact of asset criticality on an entity's risk score, follow these steps:
110+
111+
1. Open the <DocLink slug="/serverless/security/hosts-overview" section="host-details-flyout">host details flyout</DocLink> or <DocLink slug="/serverless/security/users-page" section="user-details-flyout">user details flyout</DocLink>. The risk summary section shows asset criticality's contribution to the overall risk score.
112+
1. Click **View risk contributions** to open the flyout's left panel.
113+
1. In the **Risk contributions** section, verify the entity's criticality level from the time the alert was generated.
114+
115+
![View asset criticality impact on host risk score](../images/asset-criticality/-asset-criticality-impact.png)

0 commit comments

Comments
 (0)