---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# ServiceNow Otto for Security Incident Response (SIR)

# ServiceNow Otto for Security Incident Response (SIR) {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of ServiceNow Otto for Security Incident Response (SIR)

ServiceNow Otto for Security Incident Response (SIR) leverages intelligent workflows and generative AI capabilities to assist security analysts in efficiently resolving security incidents.
Security managers benefit from concise incident context, closure notes, post-incident analysis data, and recommended remediation steps, all presented in an easy-to-read format.
Otto is ServiceNow's conversational AI platform integrated directly into workflows, offering multimodal interactions and autonomous orchestration across systems.
Show full answer Show less  

## Key Features

* **AI-Powered Incident Management:** Uses generative AI skills to support security analysts in managing and resolving incidents effectively.
* **Concise Incident Summaries:** Provides security managers with quick access to incident context, closure notes, and actionable post-incident insights.
* **Multimodal Interaction:** Supports web, mobile, and messaging channels for flexible user engagement.
* **Licensing Tiers:** Three tiers---Foundation (AI insights), Advanced (productivity enhancements), and Prime (autonomous actions and custom AI asset creation)---cater to varying organizational AI needs.
* **Configuration and Management:** Guidance available to configure and activate Otto SIR skills and manage security incidents effectively.

## Important Considerations

* AI model availability varies by customer location, data center compliance (e.g., FedRAMP, NSC DOD IL5), and market regulations; ServiceNow regularly updates availability status.
* ServiceNow's AI features require data transfer to centralized environments, potentially involving third-party cloud providers like Microsoft Azure, with data handled under strict internal policies.
* Customers' input and output data from the application are collected to improve ServiceNow AI products; however, customers can opt out of future data collection.
* AI-generated outputs may not always be fully accurate or appropriate; customers must apply human oversight and not rely solely on AI for critical decision-making, especially in sensitive domains.
* Users must comply with ServiceNow's AI Acceptable Use Policy and remain aware of evolving AI limitations and responsibilities.

## Support and Resources

ServiceNow provides resources including the Security Operations Resource Library, community support, the Known Error Portal, and Customer Service and Support to assist with troubleshooting and effective use of Otto for SIR.  
With ServiceNow Otto for Security Incident Response (SIR), security analysts can use intelligent workflows and ServiceNow generative AI skills to help them resolve security incidents. Security managers can review the context of security incidents and closure notes quickly in a concise, easy-to-read format, view post-incident analysis data, and see recommended remediation steps.

## Now Assist \> ServiceNow Otto announcement {#now-assist-security-incident-landing__id_a54_1kw_zjc}

ServiceNow Otto introduced AI on the platform. As that experience has evolved, there's a new name for the experience. ServiceNow Otto® is the conversational AI platform integrated into ServiceNow workflows. It provides agentic capabilities, supports multimodal interactions across web, mobile, and messaging channels, and enables autonomous orchestration for cross-system workflows.{#now-assist-security-incident-landing__servicenow-otto-name-change}

## Get started {#now-assist-security-incident-landing__cf-app-landing-get-started}

The ServiceNow AI Platform now brings you a new AI experience with three licensing tiers available:

* Foundation: AI basics to deliver insights
* Advanced: AI to boost productivity across relevant use cases
* Prime: Act autonomously with all AI assets, and create your own

{#now-assist-security-incident-landing__ul_szz_vjt_43c}For more information, see [ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US).

|-|-|-|
| [Explore Learn about ServiceNow Otto for Security Incident Response (SIR)](https://www.servicenow.com/docs/231IG9T52eRx3UFbwlkQnw "Security analysts can use intelligent workflows and ServiceNow generative AI skills to triage, investigate, and close security incidents with ServiceNow Otto for Security Incident Response (SIR).") | [Configure Learn how to configure and activate the skills for ServiceNow Otto for Security Incident Response (SIR)](https://www.servicenow.com/docs/uI~W0N2S2hkraUvWti_byw "The ServiceNow Otto for Security Incident Response (SIR) application is supported in the Security Incident Response Workspace and in the legacy Core UI (UI16). Use the guided setup in the AI Admin Hub console to configure ServiceNow Otto for Security Incident Response (SIR).") | [Use Learn how to manage security incidents using ServiceNow Otto for Security Incident Response (SIR)](https://www.servicenow.com/docs/VWtZcKp6_grKikL5QKbjXA "Security analysts can close security incidents quickly from within their flow of work with the generative AI skills supported by ServiceNow Otto for Security Incident Response (SIR).") |
[ ]

{#now-assist-security-incident-landing__table_jlh_dgk_1cc} Important:  
* Not all model providers are available for customers with in-country SKUs, and some AI products/features are currently unavailable for in-country customers. For more information, see the [KB1584492](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1584492) article in the Now Support Knowledge Base. Be sure to check for model provider availability updates in future releases.{#now-assist-security-incident-landing__na-in-country-notice}
* Some AI products/features are currently unavailable for customers in the FedRAMP, NSC DOD IL5, or Australia IRAP-Protected data centers, self-hosted customers, or in other restricted environments. For more information, see the [KB0743854](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0743854) article in the Now Support Knowledge Base. Be sure to check for availability updates in future releases.{#now-assist-security-incident-landing__na-restricted-envs-notice}
* Some AI products/features are currently available only for customers in some regions. Be sure to check for availability updates in future releases.{#now-assist-security-incident-landing__na-standalone-language-notice}
* Some AI products and skills are not available in Regulated Markets. For more information, see [KB2593939: Regulated Markets AI Products/Skills Not Available](https://support.servicenow.com/kb?id=kb_article_view&sys_kb_id=e8d7cc82475aba90b7832920326d4362). Be sure to check for availability updates in future releases.
{#now-assist-security-incident-landing__ul_j3b_4vd_wcc}

## Troubleshoot and get help {#now-assist-security-incident-landing__cf-app-landing-get-help}

* [Security Operations Resource Library](https://www.servicenow.com/community/secops-articles/security-operations-resource-library/ta-p/3120885)
* [Security Operations community](https://www.servicenow.com/community/secops/ct-p/security-operations)
* [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477)
* [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case)
{#now-assist-security-incident-landing__ul_olh_dgk_1cc}

## AI limitations

This application uses artificial intelligence (AI) and machine learning, which are rapidly evolving fields of study that generate predictions based on patterns in data. As a result, this application may not
always produce accurate, complete, or appropriate information. Furthermore, there is no guarantee that this application has been fully trained or tested for your use case. To mitigate these issues, it is your responsibility
to test and evaluate your use of this application for accuracy, harm, and appropriateness for your use case, employ human oversight of output, and refrain from relying solely on AI-generated outputs for decision-making
purposes. This is especially important if you choose to deploy this application in areas with consequential impacts such as healthcare, finance, legal, employment, security, or infrastructure. You agree to abide by [ServiceNow's AI Acceptable Use Policy](https://www.servicenow.com/ai-acceptable-use-policy.html), which may be updated by ServiceNow.{#now-assist-security-incident-landing__p_kv2_nfg_h1c}

## Data processing

This application requires data to be transferred from ServiceNow customers' individual instances to a centralized ServiceNow environment, which may be located in a different data center region from the one where your instance is, and potentially to a third-party cloud provider, such as Microsoft Azure. This data is handled per ServiceNow's internal policies and procedures, including our policies available through our [CORE Compliance Portal](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0564067).{#now-assist-security-incident-landing__p_lv2_nfg_h1c}

## Data collection

ServiceNow collects and uses the inputs, outputs, and edits to outputs of this application to develop and improve ServiceNow technologies including ServiceNow models and AI products. In addition, this application will collect data from security incidents, incidents, change requests, problems, and vulnerable items. Customers can opt out of future data collection at any time, as described in the [Now Assist Opt-Out page](https://www.servicenow.com/docs/access?context=opt-out-of-data-sharing-for-now-assist&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US).

For more information, see [AI Admin Hub](https://www.servicenow.com/docs/access?context=platform-now-assist-landing&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US).

