Splunk Inc.
Incident response management based on environmental characteristics

Last updated:

Abstract:

Systems, methods, and software described herein provide for managing service level agreements (SLAs) for security incidents in a computing environment. In one example, an advisement system identifies a rule set for a security incident based on enrichment information obtained for the security incident, wherein the rule set is associated with action recommendations to be taken against the incident. The advisement system further identifies a default SLA for the security incident based on the rule set, and obtains environmental characteristics related to the security incident. Based on the environmental characteristics, the advisement system determines a modified SLA for the security incident.

Status:
Grant
Type:

Utility

Filling date:

26 Sep 2018

Issue date:

4 Feb 2020