{"id":111033,"date":"2020-05-12T06:00:10","date_gmt":"2020-05-12T13:00:10","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=111033"},"modified":"2020-08-03T07:18:15","modified_gmt":"2020-08-03T14:18:15","slug":"cortex-micro-surveys","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2020\/05\/cortex-micro-surveys\/","title":{"rendered":"Manage a Remote SOC: Micro-Surveys for Crisis Management"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">How many weeks has it been since lockdown? I have lost count as the weekdays blur into the weekends. But one thing is constant regardless of where you are: the work of a SOC must go on. While some may imagine that security analysts spend all their time investigating incidents for signs of malicious activity, communication tasks also play a vital role in protecting organizations and performing crisis management. The change from working in person to working remotely brings changes in the ways security analysts communicate with end users and share information with each other.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Considering how important communication can be, we know it\u2019s important to include ways to make your communication easier in our series of <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/tag\/remote-soc\/\"><span style=\"font-weight: 400;\">tips for managing a remote SOC<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A part of the work of incident response is collecting data from end users. This can be part of addressing a phishing campaign \u2013 you might want to poll end users to see if they clicked on a link or an attachment. Having accurate data on how successful the phishing campaign has been in your organization can help you devote an appropriate level of resources to mitigating it. You may need to communicate with end users as part of a crisis management effort during this time of transition. You may want to know if users have experienced difficulty with connecting to the corporate network so you can address those issues and prevent users from turning to unauthorized devices or networks. The information you gather from users often needs to be shared with others in the SOC.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Did you know that communication tasks can be built into Cortex XSOAR playbooks to send quick micro-surveys to your users for data collection and enrichment?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Here are a few examples of communication tasks in <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/xsoar\"><span style=\"font-weight: 400;\">Cortex XSOAR<\/span><\/a><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>Ask Tasks<\/b><\/h4>\n<p><b> <\/b><span style=\"font-weight: 400;\">These are conditional one-question surveys, the answers to which will determine how the playbook will proceed.<\/span><\/p>\n<p><div style=\"max-width:100%\" data-width=\"459\"><span class=\"ar-custom\" style=\"padding-bottom:117.21%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"size-full wp-image-111034 alignnone lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/05\/Newtask.png\" alt=\"This screenshot shows how you can create Ask Tasks in Cortex XSOAR. These micro-surveys can be used as a crisis management tool when managing a remote SOC.\" width=\"459\" height=\"538\" \/><\/span><\/div><\/p>\n<p>&nbsp;<\/p>\n<h4><b>Data Collection Task<\/b><\/h4>\n<p><b> <\/b><span style=\"font-weight: 400;\">These are more detailed surveys that relevant users can access through a link sent to their email. All responses to the survey are stored in incident context, for example, as part of a phishing incident, enabling you to use the data as inputs for playbook tasks or for analysis in dashboards. <\/span><span style=\"font-weight: 400;\">These data collection tasks are fully customizable, allowing you to set question formats (short-text, single-select, etc), task type and frequency of sending out the questionnaire. All responses to the survey are stored in incident context, enabling you to reuse the data as inputs for future playbook tasks or track the data in dashboards.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Want to see these tools in action? Watch Rishi Bhargava, vice president, product strategy, explain how we used micro-surveys to monitor employee health status.<\/span><\/p>\n<p><div class=\"styleIt\" style=\"width:560px;height:315px;\"><lite-youtube videoid=\"J6DcD5y5B_U\" ><\/lite-youtube><\/div><\/p>\n<p><span style=\"font-weight: 400;\">If you are new to Cortex XSOAR, we encourage you to take it for a test drive, and feel free to kick the tires while you are at it.\u00a0 Stay safe, stay healthy \u2013 until the next post.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Sign up for the free <\/span><a href=\"https:\/\/start.paloaltonetworks.com\/sign-up-for-community-edition.html\"><span style=\"font-weight: 400;\">Community Edition of Cortex XSOAR<\/span><\/a><span style=\"font-weight: 400;\"> today.<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">We hope you enjoyed learning about using micro-surveys for crisis management in Cortex XSOAR. Watch for more useful tips and hints in the next post in our series on the <\/span><\/i><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/tag\/remote-soc\/\"><i><span style=\"font-weight: 400;\">remote SOC<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p><div style=\"max-width:100%\" data-width=\"900\"><span class=\"ar-custom\" style=\"padding-bottom:30.33%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"wp-image-111016 aligncenter lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/04\/XSOARoffer.png\" alt=\"The free Cortex XSOAR Community Edition is helping more than 4,000 users accelerate incident response.\" width=\"900\" height=\"273\" \/><\/span><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Micro-surveys in Cortex XSOAR can help security analysts manage communication in a remote SOC.<\/p>\n","protected":false},"author":663,"featured_media":109650,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6770],"tags":[7025,7223,7073],"coauthors":[7026],"class_list":["post-111033","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-future","tag-cortex-xsoar","tag-playbooks","tag-remote-soc","sec_ops_category-product-features"],"jetpack_featured_media_url":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/04\/pan_generic-gtm-social_cortex-350x300-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/111033","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=111033"}],"version-history":[{"count":2,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/111033\/revisions"}],"predecessor-version":[{"id":111065,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/111033\/revisions\/111065"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/109650"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=111033"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=111033"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=111033"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=111033"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}