Skip to content
Release: Australia · Updated: 2026-07-09 · Official documentation · View source

Create security tag rules

Security tag rules provide filtering for security tag access.

Before you begin

  • Security tags added by rules are removed automatically when rule conditions no longer match.
  • Manual security tags are preserved when automatic tags are applied.
  • When multi-selection is disabled for a security tag group, only one tag from that group can be applied to a security incident. If a security analyst manually applies a tag and an automatic tagging rule subsequently triggers for a different tag within the same group, the automatic tag overrides the manual tag.
  • Role required: sn_si.admin

Procedure

  1. Navigate to Workspaces > Security Exposure Management Workspace.

  2. Select Administration in the navigation pane.

  3. Select Review on the Security tags tile.

  4. Security tags are displayed in a list grouped by Security tag groups.

  5. Choose or create a security tag.

  6. In the Security Tag Rules related tab, select New.

  7. Fill in the fields on the form, as appropriate.

    FieldDescription
    NameThe name of the security tag rule.
    Security TagThe security tag to attach to the rule.
    ActiveOption to turn the security tag on or off.
    DescriptionA description of this rule.
  8. Determine Record Filtering.

  9. Fill in the fields on the form, as appropriate.

    FieldDescription
    Use filter groupOption to associate the filter group to the rule.
    TableThe table to contain the rule.
    ConditionOption to add one or more filter conditions.
  10. Select Submit

Parent Topic:Set up security tag groups and tags