To export an incident to NCIRCC:
This opens the export settings window.
If you specified the category and type of the incident in the incident card, you need to save the incident before exporting it to NCIRCC.
Company name, Asset owner, Incident category, Incident type, Description, value of the TLP protocol, Incident creation date, Status, Affected system name, Affected system category, Affected system function, Location.
The Operator name, INN, and Operator address fields are populated automatically with the values specified when setting up the NCIRCC integration. However, the field values can be edited when preparing the data export to NCIRCC.
Personal data leak fields are available for the Notification about a computer incident category for the following notification types:
You can use the Add new element button to add a string to the table. In the Name column, you must indicate the name of the application (for example, MS Office
). Specify the application version in the Version column (for example, 2.4
).
CVE-2020-1231
.This field becomes available if you selected Notification about a detected vulnerability as the incident category.
Microsoft operating systems and their components
.This field becomes available if you selected Notification about a detected vulnerability as the incident category.
The available settings on the tab depend on the selected category and type of incident:
KUMA 1.5
.This tab is active only if you select the Affected system has Internet connection check box.
If you need to edit or supplement the information previously specified on the Technical details tab, you should do this in your GosSOPKA account, even if NCIRCC experts requested additional information from you, and you can edit the exported incident.
The categories of the listed assets must match the category of the affected CII in your system.
Information about the incident is submitted to NCIRCC, and the Export to NCIRCC incident setting is changed to Exported. At NCIRCC, the incident received from you is assigned a registration number and status. This information is displayed in the incident window in the NCIRCC integration section.
It is possible to change the data in the exported incident only if the NCIRCC experts requested additional information from you. If no additional information was requested, but you need to update the exported incident, you should do it in your GosSOPKA dashboard.
After the incident is successfully exported, the Compare KUMA incident to NCIRCC data button is displayed at the bottom of the screen. When you click this button, a window opens, where the differences in the incident data between KUMA and NCIRCC are highlighted.
Page top