For a given incident type, it describes a series of actions that can be a mixture of automated and manual steps. When you start, the steps are often manual. As the playbook and confidence in the steps improve, you can start automating
For example a playbook for a…
Large IBM Qradar deployment and SOC Build out. Deployed 160+ QRadar appliances over multiple countries. The Qradar components deployed were
Qradar Console, QRIF, QVM, QRIF, AppNodes, Flow Collectors (Cu & Fi), Log Collectors and Processors
IBM Resilient (SOAR).
At the end…