Add closure information to a security incident
When a security incident is in the Review or Closed state, you can enter closure information.
Before you begin
Role required: sn_si.basic
Procedure
If it isn’t already open, open the security incident you want to update.
Select the Related Records tab.
Fill in the fields, as needed.
Field Description Create knowledge article The option to generate a knowledge article using the contents of the post incident report. Close code The close code that best describes the reason for closing the security incident. Closed by [Read only] Displays the user who closed the security incident. Closed [Read only] Displays the date and time the security incident was closed. Close notes How the security incident has been closed, including lessons learned, resolution, and so on. Select any of the following tabs to further update the security incident:
- Incident Details
- Post Incident Review
- Select Submit.