Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Other additional Security Incident Response setup tasks

If you are an administrator in the global domain, you configure how Security Incident Response handles day-to-day operations.

Before you begin

Role required: sn_si.admin

Note:

These options are standard to many service management applications, and as such, they use service management terminology. For example, Request is used for the main task (that is, the security incident) and Task is used for subtasks or Response Tasks.

If you are an administrator in a domain lower than the global domain, you can view the Configurations screen, but cannot modify the settings.

Procedure

  1. Navigate to All > Security Incident > Administration > Configuration.

    The options for configuring the applications are organized under these tabs:

    • The Business Process tab contains options for setting up the request life cycle, creating catalogs and requests, and configuring notifications.
    • The Assignment tab contains options for setting up manual and auto-assignment.
    • The Add-ons tab contains options for enabling the knowledge base, managed documents, and task activities.
    • Fill in the fields on the Business process tab.
FieldDescription
Lifecycle
Work notes are required to close or cancel a request or taskEnable this option to require the user to enter work notes before a security incident or response task can be closed or canceled.
Copy task work notes to requestEnable this option to synchronize response task work notes with the work notes on the security incident. So when work notes in the task are added, the same work notes appear in the parent security incident.
Catalog and Request Creation
Create or update requests by inbound emailEnable this option to create or update security incidents from inbound emails.
Requests are created usingSelect catalog or regular form to activate the catalog and enable automatic publishing of security incident templates to the catalog.Select regular form only to deactivate the catalog and disable automatic publishing of security incident templates to the catalog.
Templates create a dedicated catalog itemEnable this option to activate automatic publishing of catalog items for the application.
Notifications
For a request or task, when the selected field changes, send notification to recipientsYou can configure notifications to be sent to specific recipients when selected fields in security incidents and response tasks change. 1. From Table, select Request (security incident or Task (response task). 2. From Field, select the field to use for generating notifications. When a change is made to the selected field, a notification is sent to the identified recipients. 3. From Recipients, select one or more recipients. 4. If you select a specific user or a specific group, you are prompted to select a user or group. 5. To define more notifications using other fields or recipients, repeat the preceding steps for the next set of notification settings. 6. To remove a notification, select the
Image omitted: DeleteNotification.png
delete notification symbol icon to the right of the notification.</td></tr></tbody>
  1. Click the Assignment tab and fill in the fields.
FieldDescription
Assignment method for requestsSelect the method for assigning security incidents:- using auto-assignment: Security incidents are automatically assigned. - using a workflow: Security incidents are assigned by the selected workflow. - manually: Security incidents are manually assigned.
Use this workflow to assign requestsSelect the workflow for dispatching security incidents. This field appears when using a workflow is selected from the Assignment method for requests list.
Assignment method for tasksSelect the method for assigning response tasks:- using auto-assignment: Response tasks are automatically assigned. - using a workflow: Response tasks are assigned by the selected workflow. - manually: Response tasks are manually assigned.
Use this workflow to assign tasksSelect the workflow for assigning response tasks. This field appears when using a workflow is selected from the Assignment method for tasks list.
Assign requests or tasks based on assignment group coverage areasEnable this option to limit the assignment of security incidents and response tasks to groups that cover the location of the task.
Scheduling
Auto-selection of agents consider time zone for tasksEnable this option to consider the time zone of the agent when assigning a task. This field appears when auto-assignment is selected for security incidents or response tasks.
Additional Factors
Auto-selection of agents consider location of agentsEnable this option to give preference to agents who are closer to the task location, when assigning any tasks. This field appears when auto-assignment is selected for security incidents or response tasks.
Auto-selection of agents for tasks requires them to have skillsSelect the degree to which agent skills must be matched to a task when determining auto-assignment. - Select all to require that an assigned agent must have all the skills to perform the task. An agent who lacks even one skill is eliminated. - Select some if you want agents who have most of the skills required to perform the task. - Select none if you want to auto-assign agents without taking skills into account. This field appears when auto-assignment is selected for security incidents or response tasks.
Auto-selection attempt to assign the same agent to all tasks in a requestEnable this option to auto-assign all response tasks for a security incident to the same agent.
  1. Click the Add-ons tab and fill in the fields.

    FieldDescription
    Documentation
    Enable a dedicated knowledge baseEnable this option to activate the knowledge base for Security Incident Response.
    Enable managed documentsEnable this option to add a related list to managed documents.
    Enable task activitiesEnable this option to log task interactions and communications, such as phone calls and email messages.
  2. Click Save.

Lock down security administration

To protect investigations and keep security incidents private, you can restrict Security Incident Response access to security-specific roles and ACLs. Non-security administrators can be restricted from access, unless you expressly allow them entry.

Before you begin

When the Security Incident Response application is activated, the System Administrator user is granted the sn_si.admin role by default. The System Administrator is the only administrator who can set up security groups and users.

A security role is required to have access to Security Incident Response features and records.

Role required: sn_si.admin

Procedure

  1. After the Security Incident Response plugin has been activated, a user with the admin role assigns the Scoped Admin (sn_si.admin) role to at least one user.

  2. The user with the admin role changes to the Security Incident scope.

  3. Navigate to All > sys_store_app.list.

  4. Type sn_si in the Scope field.

Image omitted: system-applications.png
System applications.
  1. Click Security Incident Response.

  2. Scroll down to the Related Links and click Remove from the role contained by admin.

  3. Log out and log back in.

    The admin user cannot access the Security Incident Response application.

Related topics

Application administration

Manage Restricted Caller Access

The Restricted Caller Access (RCA) feature enables an administrator to define cross-scope access to an application or application resource and allow or deny access requests. This feature is enabled in Security Incident Response by default so security analysts can protect sensitive security-related information.

A field called Caller access has been added to all tables and script includes in Security Incident Response, and the field defaults to Caller Tracking. This setting means that application scopes are allowed access to Security Incident Response tables and script includes. However, a tracking record is created for each record and stored in the Restricted Caller Access Privilege [sys_restricted_caller_access] table.

Note: Take care when changing records from Caller Tracking to Caller Restricted. Records with this status cannot be accessed until an administrator manually allows access to it. The administrator must navigate to System Applications > Application Restricted Caller Access, locate the table or script include for which access has been requested, and change the Status field from Requested to Allowed.

Related topics

Restricted caller access privilege settings

Set the application scope, application resource, and event access

Run quick start tests for Security Incident Response

Validate that Security Incident Response still works after you make any configuration changes, such as applying an upgrade or developing an application. Copy and customize these quick start tests to pass when using your instance-specific data.

Security Incident Response quick start tests require activating Security Incident Response plugin (com.snc.security_incident) and loading the demo data.

TestDescriptionRelease version
SIR: Create Security IncidentDetermine whether a user can successfully create a security incident from the security incident form.Madrid
SIR: Create Security Incident via Security Incident CatalogDetermine whether a user can successfully create a security incident from the catalog.Madrid
SIR: PIR Assessments OOTB configuration testUse this test to validate PIR assessments and base system configurations.Tokyo
SIR: PIR Assessments conditional Configuration testsVerify that security incidents matching the mandatory conditional rule are not closed without completing the post incident assessment. Verify that the security incidents matching the optional conditional rule can be closed without completing the post incident assessment. Verify that assessments are not generated for the security incidents that do not match any rule.Tokyo
SIR: PIR Run Time ExperienceVerify that PIR reports are configured and attached to the security incidents as per the new design.Tokyo
SIR: PIR Design Time ExperienceVerify that the security incident is mapped with the report template based on the administrator configuration.Tokyo
SIR: Link Security Incident to a existing Major Security IncidentLink a Security Incident to an existing Major Security Incident and validate data from Security Incident rolled up to Major Security Incident.Tokyo
SIR: Promote Security Incident as Major Security IncidentPromote a Security Incident as Major Security Incident and validate data from Security Incident rolled up to Major Security Incident.Tokyo
SIR: Propose Security Incident as Major Security IncidentPropose a Security Incident as Major Security Incident and validate data from Security Incident rolled up to Major Security Incident.Tokyo
SIR: Security Incident life cycleValidate a Security Incident life cycle with the policy violation response tasks workflow.Yokohama
SIR: Create Security CaseCreate a Security Case from the Security Incident form.Yokohama
Verify that only Allowed Members can access the security incident once Enforce Restriction is ONVerify that only the allowed members can access the security incident once the Enforce Restriction is enabled.Yokohama
Verify that security incident enabled with "Enforce Restriction" is not visible for any userVerify that security incident enabled with "Enforce Restriction" is not visible for any user.Yokohama
Validate Read AccessValidate the view access.Yokohama
Validate Write AccessValidate the edit access.Yokohama
SIR Workspace: Read AccessVerify that Read Access user can view the security incident without having security roles even on workspace.Yokohama
SIR Workspace: Write AccessVerify that Write Access user can update the security incident without having security roles.Yokohama
SIR Workspace: Create new Security IncidentCreate new security incident from workspace.Yokohama
SIR Workspace: Create Response TaskCreate new response task from an existing security incident.Yokohama
Now Assist for Security: Active Security Incident SummarizationSummarize an active security incident and validate the displayed sections.Zurich
Now Assist for Security: Security Incident Summarization\_Share to worknotesShare the generated summary to worknotes.Zurich
Now Assist for Security: Closed Security Incident SummarizationSummarize a closed security incident and validate the displayed sections.Zurich

Related topics

Quick start tests

sndocs is an independent community mirror and is not affiliated with or endorsed by ServiceNow.

ServiceNow, the ServiceNow logo, Now, and other ServiceNow marks are trademarks and/or registered trademarks of ServiceNow, Inc., in the United States and/or other countries. Other company and product names may be trademarks of the respective companies with which they are associated.

© 2026 ServiceNow, Inc. All rights reserved.

Documentation content is redistributed under the Apache License 2.0 from the ServiceNowDocs repository.