Security Operations SIEM: Step 1 - OnBoarding

Table of Contents

Below you'll find a table of contents for the Onboarding journey.

siem-onboarding.png

SecOps Onboarding will provide administrative access to the platform. This is the first requirement in product adoption, and includes integration with your chosen Identity and Access Management (IAM) software to ensure user and role consistency across your portfolio.

Prerequisites

  • Entitlement for SecOps SIEM on the account and project

Actions

siem-onboarding-gcp-project-setup.png

 GCS Project Setup

A Google Cloud project is required to use Google Workspace APIs. It is the overarching entity to group services, APIs, billing, collaborators, and managing permissions within your Google Cloud environment.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Access to manage Projects inside of your company's Google Workspace. (Presumably the user wouldn't see this step without access to begin with)
Steps
  1. In the Google Cloud console, go to Menu > IAM & Admin > Create a Project.

  2. In the Project Name field, enter a descriptive name for your project.

    1. To edit the Project ID, click Edit. The project ID can't be changed after the project is created, so choose an ID that meets your needs for the lifetime of the project.

  3. In the Location field, click Browse to display potential locations for your project. Then, click Select.

  4. Click Create. The Google Cloud console navigates to the Dashboard page and your project is created within a few minutes.

Relevant Links
siem-onboarding-config-idp-integration.png
Configure IDP Integration

Identity Platform is a CIAM system that can help you add identity and access management functionality to your Google Cloud projects. Identity Platform is a Google Cloud native IdP.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Google Cloud project set up for Chronicle
  • Billing Enabled for Google Cloud Project
Steps
  1. Select your project from the dropdown at the top of the console.

  2. Navigate to the Identity Platform page. | Docs

  3. Click Enable Identity Platform.

  4. Navigate to the Identity Providers Page > Click Add Provider.

  5. In the Select a provider list, select Email/Password.

  6. Click the Enabled toggle to on, click Save.

  7. Navigate to the Users page. | Docs

  8. Click Add User.

  9. In the Email field, enter an email and password. Make a note of both of these values because you will need them in a later step.

  10. To add the user, click Add. The new user is listed on the Users page.

Relevant Links

siem-onboarding-config-external-idp.png

 Configure External IDP

If your organization uses an external identity provider (IdP), you will need to configure federation to allow your users, contractors, and partners to authenticate to IAM and Google Console.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to the Google Cloud Project in which you intend to enable 3rd party IdP.
  • Understanding of Google Cloud Workforce Identity Federation.
  • Familiarity with Google Cloud Shell.
Steps
  1. Define workforce identity pool and provider details. | Docs

  2. Define User Attributes and Groups in the IdP. | Docs

  3. Create a SAML Application in the IdP and configure it. | Docs

  4. Configure workforce identity federation in the Google Cloud. | Docs

  5. Create and Configure a workforce identity pool. | Docs

  6. Create a workforce identity provider. | Docs

  7. Grant roles for SecOps access | Docs

  8. Verify or Configure SecOps feature access control. | Docs

  9. Modify workforce identity federation configuration. | Docs

Relevant Links

siem-onboarding-provision-chronicle-instance.png

 Provision SecOps Instance

In this step we'll provision your SecOps instance using all the pre-work from the previous steps. In order to utilize SecOps, you'll need to have an instance provisioned inside of your Google Cloud Project.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Create Google Cloud Project and Enable Chronicle API
  • Configure SSO Provider for Chronicle instance
  • Confirm User has required permissions
Steps
  1. Provide your Customer (CE) with the Project ID you plan to bind to the SecOps Instance. Wait for confirmation email.

  2. Select your Google Cloud Project, then navigate to Security > Chronicle SecOps.

  3. If you have not enabled the Chronicle API, you will see a Getting Started button, click it.

  4. Fill out the Company Information section, click Next.

  5. Review the service account information and then click Next.

  6. Select the workforce provider created in the previous step of the Chronicle Journey, click Next.

  7. Expand the Terms of Service. if you agree to the terms, click Start Setup.

    1. Note: It could take up to 15 minutes for the Chronicle instance to be provisioned. You will receive a notification once provisioned successfully.

Relevant Links
Contributors
Version history
Last update:
2 weeks ago
Updated by: