Having examined the topic of governance in depth in the previous instalment of this series – and business continuity management (BCM) in particular – today we turn our attention to another key element: the handling of security incidents – and how monitoring and ITSM can work together most effectively in this context. The main focus here is on how OpenText Service Management can be used to identify, assess, control and mitigate risks.
Security incidents in OpenText – from alert to automated response
Security incidents cannot simply be generalised. Risks must be weighted differently depending on the organisational context. Let’s consider a simple example: a locked door poses a completely different risk for a jeweller than it does for a nursery. Whilst the jeweller wants to protect against burglary, the nursery’s priority is to prevent children from leaving the premises. Although both scenarios require a protective measure, the assessment and implementation are fundamentally different. It is precisely this way of thinking that can be applied directly to IT risks.
That is why a thorough analysis is required:
- What exactly needs to be protected?
- Where is protection required?
- Which technical measures – from firewalls and intrusion detection systems (IDS) to anti-virus software – are appropriate and necessary?
- And: How can we detect an impending incident at an early stage?
The role of IT service management
This is where the interplay between monitoring and IT service management with OpenText comes into play. After all, a security incident often begins with a simple event in the monitoring system. If this is detected at an early stage and automatically passed on to service management, a predefined playbook can be triggered: clear response steps, ideally already tested and established. In practice, this means that alerts from the monitoring system directly generate a ticket in the service management system – including all relevant information for the teams responsible.
An interesting feature: our middleware, developed in-house at Materna, checks for every event whether a corresponding ticket has already been created automatically. If one exists, it is simply updated. This provides a consolidated view of clusters of events – for example, just one ticket for 100 similar events. Unlike many standard solutions, where each event generates a separate ticket, this significantly reduces the administrative workload.
Key success factors: communication, awareness and automation
A major problem for many organisations is that security incidents are handled manually, i.e. via email. If the person responsible is unavailable, the entire process grinds to a halt. The situation is even more serious when there are several unconnected data sources – such as a shadow CMDB in Excel format – that are not linked to the central IT Service Management system. In such cases, incidents remain unprocessed or the process is cumbersome and slow.
Our survey, which we carried out as part of a workshop, revealed that there is often a lack of process automation, a lack of central integration of security processes into ITSM – and a lack of security awareness within the organisation. Yet the latter can be practised very effectively in day-to-day work: training sessions, simulated phishing emails or web portals with targeted communication are effective ways of raising awareness of the issue. This, too, can be implemented in a modern service portal.
From event to decision – with data analysis and risk reporting
Finally, there is still a need for integrated analysis of security events. As soon as an event occurs repeatedly in the same location, the system can detect it, analyse it and evaluate it as a pattern or cluster. This makes it possible to identify causes – such as a particular service that keeps attracting attention – and take targeted action.
Risk management does not stop at security incidents: risks can also arise from other areas such as contracts, services, assets, service providers, suppliers or employee data. These are reported – regardless of their source – in the integrated ITSM system and subsequently analysed and assessed by a specialist team using dedicated tools. This provides a centralised overview of all risk factors within the organisation. The key advantage is that the risks under consideration are directly linked to the relevant data records (e.g. configuration items or contracts), thereby ensuring maximum transparency and traceability.
Conclusion: Security as an integrated ITSM process
This article has made it clear that risks can only be actively managed – from detection and assessment through to a structured response – if security processes are fully integrated into IT and Enterprise Service Management, for example using OpenText. Playbooks, reports, automated workflows and clear reporting channels ensure that a security incident does not turn into an emergency. And if it does, the BCM module within the same system has already laid the groundwork for the next step.
In the next instalment of our series, we’ll be looking at compliance: how can regulatory requirements, contracts and internal policies be systematically monitored and managed?
Further articles in this series:
Part 1: Governance, Risk and Compliance in Service Management – Materna Blog
Part 2: Business Continuity Management (BCM) and OpenText Service Management: A strong partnership for greater security and efficiency – Materna Blog
Are you interested in further security solutions? Click here to view our cyber security offering.