Create Playbook Tags
A Playbook tag is an identifier that can be used to define role-based access control (RBAC) for Playbooks. To define RBAC for Playbooks, analysts must create Playbook tags and assign them to Playbooks and user groups in CFTR. The members of a user group in CFTR can execute the Playbooks whose tags match the tags assigned to the user group. For more information on assigning tags to a Playbook, see Create Playbook.
For example, if you are a SOC (Security Operations Center) manager, then you can define RBAC for Playbooks using tags and you can limit permission such as executing a Playbook for junior security analysts.
Before you start
Ensure that the following prerequisites are met:
You have permission to View Tags and Create/Update Tags.
CFTR is integrated with an Orchestrate instance.
In CFTR, role-based access control of Playbooks is enabled under Admin Panel > Configurations > Integration > Orchestrate.
Steps
To create a Playbook tag, do the following:
Go to Admin Panel > Playbook Tags.
Click New Tag.
Enter a name and description for the tag.
Select a Color for the tag and click Save.
Manage Playbook Tags
You can perform the following activities to manage Playbook tags:
Edit tags to update tag name, tag description, and tag color.
Search for a tag.
Filter tags based on recent updates such as last week, last month, and more.
Delete a tag that is not linked to any Playbook.
View linked Playbooks of a tag from the Playbook tags listing page.
Sort tags based on the tag name and creation time.