Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Automated Case Management and Assignment in FortiSIEM 7.2

Fortinet
05/08/2026
29
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • FortiSIEM 7.2 introduces automated case management that assigns incidents to analyst groups based on configurable policies matching case categories to team expertise levels.
  • Administrators can define SLAs, escalation procedures, and assignment methods (random, team lead, or manual) through case management policies with customizable notifications.
  • Automation policies route incidents by category—availability and performance to Level 1, security and changes to Level 2—ensuring appropriate skill matching.
  • The Case Management Overview provides KPIs tracking incident response efficiency, while investigation tools include MITRE ATT&CK mappings and chronological attack timelines.

Automated Case Assignment and Policy Configuration

This demonstration walks through FortiSIEM 7.2's automated case management capabilities, showing how security operations teams can streamline incident handling through policy-based assignment. The workflow begins with creating analyst groups organized by expertise level—Escalations, Level 1, and Level 2—each designed to handle cases matching their technical capabilities. Administrators can configure case management policies that define service level agreements, escalation procedures, and assignment methods including random distribution among team members or direct assignment to team leads. The automation policies tie incident categories to specific analyst groups, ensuring availability and performance issues route to Level 1 analysts while security and change-related incidents requiring advanced skills automatically escalate to Level 2 teams.

Case Investigation and MITRE ATT&CK Integration

Beyond assignment automation, FortiSIEM provides analysts with comprehensive investigation tools once cases are created. The Case Management Overview page surfaces key performance indicators tracking incident response efficiency from event detection through case creation. When analysts drill into individual cases, they gain visibility into related incidents, affected hosts, observables, and the tactics and techniques employed by attackers. MITRE ATT&CK mappings help identify attack patterns and techniques used to gain access, while a chronological timeline in the Investigate tab reveals the attack's progression. This end-to-end workflow—from automated triage to deep investigation—demonstrates how FortiSIEM aims to reduce manual overhead while maintaining thorough incident analysis capabilities.

Chapters

0:00 - Introduction to Automated Case Management
0:15 - Creating Analyst Groups
0:31 - Configuring Case Management Policies
1:34 - Building Automation Policies
3:01 - Case Overview and KPIs
3:38 - Case Investigation and MITRE Mappings

Key Quotes

0:00 "In this demo, we introduce a new feature in Fortisim 7.2, where you can automate case management and assign cases in the automated fashion."
2:37 "This automation policy will handle change and security incidents, which require advanced skills. Therefore, I will assign it to the Level 2 Analyst group."
3:05 "Fortisim's Case Management Overview page provides analysts with a comprehensive understanding of case trends."

Categories:
  • » Webinar Library » Fortinet
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Demo
  • Technical Deep Dive
  • SIEM case management
  • incident response automation
  • security operations workflows
  • analyst tiering
  • MITRE ATT&CK integration
  • SLA management
  • incident escalation
  • security analytics
  • SOC efficiency
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Automated Case Management and Assignment in FortiSIEM 7.2

              Upcoming Webinar Calendar

              • 06/10/2026
                11:00 AM
                06/10/2026
                Action1: Vulnerability Digest--Patch Tuesday & Other Updates
                https://www.truthinit.com/index.php/channel/1997/action1-vulnerability-digest-patch-tuesday-other-updates/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Stay Informed on the Latest Keepit Partner Developments – June 23
                https://www.truthinit.com/index.php/channel/1990/stay-informed-on-the-latest-keepit-partner-developments-–-june-23/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/

              Upcoming Events

              • Jun
                10

                Action1: Vulnerability Digest--Patch Tuesday & Other Updates

                06/10/202611:00 AM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Stay Informed on the Latest Keepit Partner Developments – June 23

                    06/23/202610:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version