Skip to content
Notifications
Clear all

Step-by-step guide: Creating a collaborative workspace for an incident.

1 Posts
1 Users
0 Reactions
0 Views
(@ivanp)
Estimable Member
Joined: 7 days ago
Posts: 61
Topic starter   [#8106]

Having recently completed a lengthy evaluation of ThreatConnect for a security operations overhaul, I found the process of establishing a truly collaborative incident workspace to be more nuanced than the platform's marketing materials might suggest. The core capability is certainly present, but the practical implementation and, crucially, the cost implications of scaling collaboration are deeply intertwined with your licensing model and operational habits. A misstep in the initial configuration can lead to significant inefficiency or unexpected overage charges down the line.

My guide is derived from a production deployment for a 24/7 SOC, with a keen eye on how each step interacts with common pricing dimensions.

**Phase 1: Pre-Workspace Foundation and License Audit**
Before creating a single workspace, you must reconcile your operational needs with your contract.
* **Seat Licensing Scrutiny:** Determine which user roles require a full "Analyst" license versus a "Read-Only" or "Restricted" license. Every full license added to facilitate collaboration has a direct, recurring annual cost. Consider if third-party stakeholders (like legal or PR) truly need access, or if reports can be exported.
* **Community/Organization Context:** Decide if the workspace will reside within a specific Organization (typical for a single company) or in the Community level (for sharing with external partners). This decision has profound implications for data sovereignty and vendor lock-in; moving data between these contexts later is non-trivial.
* **Indicator Tagging Taxonomy:** Establish a consistent tag taxonomy for threats, campaigns, and TTPs *before* incident chaos ensues. Inconsistent tagging, a common pitfall, destroys the collaborative value of the platform's data aggregation features.

**Phase 2: Workspace Creation and Access Cost Controls**
The workspace itself is a container, but its settings dictate financial and operational flexibility.
* **Creation and Visibility:** Navigate to the Intelligence tab, select "Workspaces," and create a new one. The critical choice here is between "Private" and "Public (Organization)." A Private workspace offers control but may necessitate manual user addition for each new collaborator, creating overhead. A Public workspace within your Org reduces overhead but requires discipline to avoid information sprawl.
* **User Group Assignment:** Instead of assigning users individually, leverage Groups. This aligns with seat licensing management and simplifies access reviews. Assign groups to the workspace with appropriate roles (Admin, Member, Read-Only). Remember that any user added to a group who did not previously have a license may trigger a new license requirement.
* **Template Consideration:** If your pricing tier includes Playbooks, consider creating or using a template that pre-loads key analytic nodes (like VirusTotal, PassiveTotal, or internal enrichment). This standardizes response and prevents "overage fee" scenarios from uncontrolled, ad-hoc API calls to integrated services.

**Phase 3: Structuring for Collaborative Workflow**
This is where the theoretical becomes practical, and where usage-based billing elements can emerge.
* **Utilizing the Timeline:** Mandate that all actions, from initial observables to containment steps, are logged as entries on the workspace Timeline. This creates an audit trail and is more efficient than email threads. However, note that extensive logging of large data blobs (like full PCAPs) may impact storage costs depending on your contract's stipulations.
* **Task Management with Assignments:** Create formal Tasks for specific action items, assigning them to individuals or groups. This integrates with user dashboards. The pitfall here is allowing tasks to be created without clear deadlines or owners, leading to collaborative drift and extended incident lifecycle, which indirectly increases cost by consuming more analyst hours within the platform.
* **Indicator Management and Bulk Scoring:** As observables are added, use the bulk scoring and tagging functions collaboratively. Consensus on indicator severity (e.g., via rating votes) should be documented. Be aware that automated indicator enrichment (if configured) consumes API calls to external services; monitor these against any contractual API call limits to avoid overages.

**Phase 4: Sustaining the Model and Measuring TCO**
The workspace is not a set-and-forget construct; its ongoing use defines its return on investment.
* **Post-Incident Archive Policy:** Establish a policy for archiving or closing workspaces after a defined period. Retaining thousands of active workspaces impacts system performance and can complicate data retention compliance, potentially incurring additional storage or management fees.
* **Regular Review of Integration Usage:** Periodically audit the usage logs for integrated services (like sandbox submissions or threat intel feeds) that are triggered from within workspaces. Compare this against your contracted allowances. Unchecked automation can lead to significant cost overruns.
* **Cross-Workspace Search and Knowledge Re-use:** The ultimate collaborative value is realized when teams use the global search function to pivot across historical workspaces. This reduces duplicate work and leverages past investments. However, this requires the disciplined use of tags and descriptions mentioned in Phase 1; otherwise, the search function yields poor results, undermining the platform's value proposition.


null


   
Quote