ISMS & Risk

Rule Chains

The technical finding lands as an action, not as an email

Most security-operations automation ends in a notification. Someone has to read it, understand it and translate it before an action results. Rule chains skip that step: a new device on the network, a changed DNS answer, a different open port, a failed service, a certificate about to expire, a correlated SIEM alert or a behavioural anomaly can directly create an action or task, with an owner and a deadline. That is the point where technical detection and the management system genuinely connect.

ISO 27001NIS2
Features

Your benefits

1

Triggers from across the platform

Classic ISMS triggers via answered question, overdue measure, high risk score and new record. Plus technical ones: correlated SIEM incident, new device, DNS change, port difference, outage, recovery, expiring certificate and two behaviour-analytics triggers.

2

Ten object areas as targets

A chain acts on checklists, audits, risk analyses, assets, data protection, tasks, notifications, incidents, licences or processing records instead of merely sending mail.

3

Four action types and real escalation

Create a measure, create a task, escalate or notify. Escalation policies work in stages, so a stalled case moves onward instead of quietly dying.

4

Traceable in an audit

An execution log records which rule fired when and why, and what came of it. Action templates keep the results consistent.

Capabilities

Capabilities in detail

  • ISMS triggers: answered question, overdue measure, high risk score, new record
  • SIEM trigger on correlated incidents
  • Attack surface triggers: new device, DNS change, port difference
  • Uptime triggers: outage, recovery, expiring certificate
  • Behaviour analytics triggers: anomaly and score threshold
  • Ten object areas from checklist to processing record
  • Action types: create measure, create task, escalate, notify
  • Condition checks via a logic builder
  • Action templates and the action instances derived from them
  • Escalation policies in stages
  • Notification internally or by email through global channels
  • Event queue for asynchronous processing
  • Execution log per rule for audit evidence
Result

A management system in which a technical finding arrives as an action with an owner, not as a notification someone has to translate.

Experience Rule Chains live

Schedule a no-obligation demo – we will show you the module with your own use cases.