To simplify the process of creating roles and assigning permissions, there are preconfigured roles in NetWitness Platform.
|Administrators||Full system access. The System Administrators persona is granted all permissions by default.|
|Respond_Administrator||Access to all Respond permissions. The Respond Administrator persona is focused on system configuration of Respond.|
|Data_Privacy_Officers||The Data Privacy Officer (DPO) persona is similar to Administrators with additional focus on configuration options that manage obfuscation and viewing of sensitive data within the system (see the Data Privacy Management Guide). Users with the DPO role can see which meta keys are flagged for obfuscation, and they also see obfuscated meta keys and values created for the flagged meta keys.|
|SOC_Managers||Same access as Analysts plus additional permission to handle incidents. The SOC Managers persona is identical to Analysts, but with permissions necessary to configure Respond.|
|Operators||Access to configurations but not to meta and session content. The System Operators persona is focused on system configuration, but not investigation, ESA, Alerting, Reporting, and Respond.|
|Malware_Analysts||Access to investigations and malware events. The only access granted to the Malware Analysts persona is the Malware Analysis module.|
|Analysts||Access to meta and session content but not to configurations. The Security Operation Center (SOC) Analysts persona is centered around investigation, ESA Alerting, Reporting, and Respond, but not system configuration.|
Access to the RSA NetWitness UEBA service in the Investigate > Users view. NetWitness UEBA is an advanced analytics solution for discovering, investigating, and monitoring risky behaviors across all entities in your network environment.
Note: You do not need to set up specific permissions for this role. You only need to assign this role to a user, and that user will have access to NetWitness UEBA.
The administrator can also add custom roles.