跳到内容

情报与治理

安全运营

Incident console for ERPStack security events, Wazuh evidence, Grafana trace/log references, triage, notes, and SLA lanes.

本地已验证 证据第一模块页面
主要用户
Platform admin Security operator Service operations Release owner
/app/security-operations
应用程序衍生的视觉效果
SIEM Incident Console
打开应用程序路径
活动
租户范围
分诊
Persistent
严重性
SLA tracked
区域 状态 证据
调查 Incident table Wazuh drilldown
库存作业 Queue health MTTA/MTTR
证据 Trace/log refs Grafana links

核心流程

该模块帮助操作员完成哪些工作。

每个工作流程都被编写为操作路径,而不是营销主张,因此买家可以了解日常模块的配合情况。

步1
Review suspicious and high-severity events
步2
Filter by tenant, module, severity, rule, and status
步3
Triage incidents with notes and ownership
步4
Drill into Wazuh, logs, traces, and evidence references

功能清单

功能按照操作员寻找功能的方式进行分组。

3 能力组

Incident triage

  • Severity lanes
  • Status workflow
  • 作业
  • Operator notes

Security evidence

  • Wazuh proof refs
  • Grafana trace links
  • Loki log refs
  • Raw event detail

Service operations

  • Source health
  • SLA breach alerts
  • MTTA/MTTR
  • Operator workload

连接模块图

该模块如何与 ERPStack 的其余部分交换业务上下文。

Module 关系
所有模块 Receives suspicious, privileged, compliance, and boundary events
Wazuh Security alert ingestion, rule groups, and threat-hunting evidence
Grafana Trace and log drilldowns for operational investigation
Platform Settings Security-sensitive setting changes and provider controls

治理和报告

严格的 ERP 模块所期望的控制和管理可见性。

治理
  • Durable incident workflow
  • Operator notes
  • Wazuh proof refs
  • SLA breach alerts
报表
  • Incident workload
  • MTTA/MTTR
  • Source health
  • Operator queue

AI 覆盖范围政策

ERPStack 今天可以诚实地声称该模块。

AI 声明与官方代理工具注册表、评估证据、安全模式控制和预定代理监控准备情况相关。在实施模块本机工具之前,路线图模块仅显示计划的覆盖范围。

AI L2/L4 gap
承保索赔 Current AI coverage: Security and Compliance Hardening L2/L4 below target level through the official Agent Tool Registry.
治理证据 Governance evidence: 2 registered tools, 1 evaluation cases, tenant/RBAC/safe-mode registry controls, and AI log evidence.
定时监控 Scheduled monitor readiness: 1/1 ready (Security Incident Triage Monitor).
L4/L5边界 Raise Security and Compliance Hardening AI coverage from L2 to L4.

证据第一的标准

模块页面在一处解释价值、工作流程、控制和证明。

此页面结构支持当前的公共模块目录,其中包含应用程序派生的视觉效果、连接模块证据、治理证明和报告上下文,可以与真实产品路线进行比较。

特征清晰度

买家可以看到具体的功能组,而不是模糊的功能声明。

操作适合

工作流程、用户和连接的模块显示模块所属的位置。

治理证明

RBAC、审计、SIEM、批准和报告作为首要问题出现。

审核路径

公共页面链接回应用程序路线,以便审阅者可以将页面声明与产品表面进行比较。