Help Center/ SecMaster/ User Guide/ Playbook Overview/ Real-time Notification of Critical Organization and Management Operations
Updated on 2024-09-27 GMT+08:00

Real-time Notification of Critical Organization and Management Operations

Playbook Overview

This built-in playbook can notify you of key O&M operations by email in real time.

The Real-time notification of critical Organization and Management operations playbook has matched the Real-time notification of critical Organization and Management operations workflow. This workflow uses Simple Message Notification (SMN) to send notifications. So you need to create and subscribe to a notification topic in SMN.

Prerequisites

  • You have enabled access to CTS logs on the Data Integration page under Settings in the current workspace. For details, see Data Integration.
    Figure 1 Access to CTS logs
  • The corresponding O&M defense model has been enabled. For details, see Step 2: Enable the Alert Model.

Step 1: Create and Subscribe to a Topic

The Real-time notification of critical Organization and Management operations workflow uses Simple Message Notification (SMN) to send notifications. You need to create and subscribe to a topic for receiving notifications.
  1. Log in to the management console.
  2. In the upper left corner of the page, click and choose Management & Governance > Simple Message Notification.
  3. Create a topic.
    1. In the navigation pane on the left, choose Topic Management > Topics. In the upper right corner of the displayed page, click Create Topic.
      Figure 2 Create Topic
    2. In the Create Topic dialog box displayed, configure topic information and click OK.
      • Topic Name: SecMaster-Notification is recommended.
      • Display Name: SecMaster notification topic is recommended.
      • Retain the default settings for other parameters.
  4. Add a subscription.
    1. On the Topics page, locate the row that contains the SecMaster-Notification topic and click Add Subscription in the Operation column.
    2. On the displayed Add Subscription slide-out panel, configure subscription information and click OK.
      • Protocol: Select Email.
      • Endpoint: Enter the email address of the subscription endpoint, for example, username@example.com.

Step 2: Enable the Alert Model

Before using the Real-time notification of critical Organization and Management operations playbook, you need to enable some alert models, including the ones for O&M - Attaching NICs, O&M - Creating VPC peering connections, and O&M- Binding EIPs to resources.

  1. Click in the upper left corner of the page and choose Security & Compliance > SecMaster.
  2. In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
    Figure 3 Workspace management page
  3. In the navigation pane on the left, choose Threat Operations > Intelligent Modeling, and select the Model Templates tab.
    Figure 4 Model Templates tab
  4. In the model template list, click Details in the Operation column of the target model template. The template details page is displayed on the right.
  5. On the details page, click Create Model in the lower right corner. The page for creating an alert model is displayed.
  6. On the Create Threat Model page, configure basic information about the model.
    • Pipeline Name: Select an execution pipeline for the alert model.
      Table 1 Available pipelines

      Alert Template

      Execution Pipeline

      O&M - Attaching a NIC

      sec-cts-audit

      O&M - Creating a VPC peering connection

      O&M - Binding EIPs to resources

    • Retain default values for other parameters.
  7. After the setting is complete, click Next in the lower right corner of the page. The page for setting the model logic is displayed.
  8. Set the model logic. You are advised to retain the default settings.
  9. Complete all settings and click Next in the lower right corner of the page.
  10. Review all settings and click OK in the lower right corner of the page.
  11. Repeat 4 to 10 to create alert models with other templates.
  12. In the navigation pane on the left, choose Threat Operations > Intelligent Modeling.
    Figure 5 Available Models
  13. To enable models in batches, select all models you want to enable and click Enable in the upper left corner of the list.

    If the model status changes to Enable, the model is successfully started.

Step 3: Configure and Enable the Playbook

In SecMaster, the initial version (V1) of the Real-time notification of critical Organization and Management operations workflow is enabled by default. You do not need to manually enable it. The initial version (V1) of the Real-time notification of critical Organization and Management operations playbook is also activated by default. To use it, you only need to enable it.
  1. In the navigation pane on the left, choose Security Orchestration > Playbooks.
    Figure 6 Accessing the Playbooks tab
  2. On the Playbooks page, locate the row that contains the Real-time notification of critical Organization and Management operations playbook and click Enable in the Operation column.
  3. In the dialog box displayed, select the initial playbook version v1 and click OK.

Implementation Effect

When a key O&M operation is performed, this playbook is triggered. The playbook will send an email notification as configured. The following is an example.

Figure 7 Operation notifications