We want to use Manage Engine to be a Security Incident reporting tool. We would document any security incidents that occur in our organization like a virus getting in or a password being cracked, etc.. Ideally we'd like the Security Analyst to be the only one able to generate these Security Incident tickets and for the security analyst to be the only one that can view the Security Incident tickets.
What is the best way to secure this type of configuration? I've thought of using a site and securing that site. Or to create a new roll and then use that secure the security incident tickets.
Does anyone have any feedback on how I might accomplish this? Currently, everyone in the organization can see every ticket. We do not have different remote sites so there was no need to secure based on location.
I have looked on the forum and can't seem to find anything like this so if there is forward me the link.
Thanks
Tom H