---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Other additional Security Incident Response setup tasks

# Other additional Security Incident Response setup tasks {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 9 minutes to read

If you are an administrator in the global domain, you configure how Security Incident Response handles
day-to-day operations.

## Before you begin

Role required: sn_si.admin  
Note:  
These options are standard to many service management applications, and as
such, they use service management terminology. For example, Request is used
for the main task (that is, the security incident) and Task is used for
subtasks or Response Tasks.

If you are an administrator in a domain lower than the global domain, you can
view the Configurations screen, but cannot modify the settings.

## Procedure

1. Navigate to AllSecurity IncidentAdministrationConfiguration.  
   The options for configuring the applications are organized under these tabs:
   * The Business Process tab contains options for setting up the request life cycle, creating catalogs and requests, and configuring notifications.{#t_ConfigureSIM__li_SMConfigBusinessProcessTabDesc}
   {#t_ConfigureSIM__li_SMConfigBusinessProcessTabDesc}
   * The Assignment tab contains options for setting up manual and auto-assignment.{#t_ConfigureSIM__li_SMConfigAssignmentTabDesc}
   {#t_ConfigureSIM__li_SMConfigAssignmentTabDesc}
   * The Add-ons tab contains options for enabling the knowledge base, managed documents, and task activities.{#t_ConfigureSIM__li_SMConfigAddonsTabDesc}
   {#t_ConfigureSIM__li_SMConfigAddonsTabDesc} {#t_ConfigureSIM__ul_otd_nwc_pt}
2. Fill in the fields on the Business process tab.  
   {#t_ConfigureSIM__table_kpf_lrk_ls__entry__2}

   | Field | Description |
   |-|-|
   | Lifecycle ||
   | Work notes are required to close or cancel a request or task | Enable this option to require the user to enter work notes before a security incident or response task can be closed or canceled. |
   | Copy task work notes to request | Enable this option to synchronize response task work notes with the work notes on the security incident. So when work notes in the task are added, the same work notes appear in the parent security incident. |
   | Catalog and Request Creation ||
   | Create or update requests by inbound email | Enable this option to create or update security incidents from inbound emails. |
   | Requests are created using | Select catalog or regular form to activate the catalog and enable automatic publishing of security incident templates to the catalog. Select regular form only to deactivate the catalog and disable automatic publishing of security incident templates to the catalog. |
   | Templates create a dedicated catalog item | Enable this option to activate automatic publishing of catalog items for the application. |
   | Notifications ||
   | For a request or task, when the selected field changes, send notification to recipients | You can configure notifications to be sent to specific recipients when selected fields in security incidents and response tasks change. 1. From Table, select Request (security incident or Task (response task). 2. From Field, select the field to use for generating notifications. When a change is made to the selected field, a notification is sent to the identified recipients. 3. From Recipients, select one or more recipients. 4. If you select a specific user or a specific group, you are prompted to select a user or group. 5. To define more notifications using other fields or recipients, repeat the preceding steps for the next set of notification settings. 6. To remove a notification, select the ![delete notification symbol]() icon to the right of the notification. {#t_ConfigureSIM__ol_uv4_tnx_5r} |
   [Table 1. Configuration screen --- Business Process tab]

   {#t_ConfigureSIM__table_kpf_lrk_ls}
3. Click the Assignment tab and fill in the fields.  
   {#t_ConfigureSIM__table_gjj_3vk_ls__entry__2}

   | Field | Description |
   |-|-|
   | Assignment method for requests | Select the method for assigning security incidents: * using auto-assignment: Security incidents are automatically assigned. * using a workflow: Security incidents are assigned by the selected workflow. * manually: Security incidents are manually assigned. {#t_ConfigureSIM__ul_zs4_tnx_5r} |
   | Use this workflow to assign requests | Select the workflow for dispatching security incidents. This field appears when using a workflow is selected from the Assignment method for requests list. |
   | Assignment method for tasks | Select the method for assigning response tasks: * using auto-assignment: Response tasks are automatically assigned. * using a workflow: Response tasks are assigned by the selected workflow. * manually: Response tasks are manually assigned. {#t_ConfigureSIM__ul_cv4_tnx_5r} |
   | Use this workflow to assign tasks | Select the workflow for assigning response tasks. This field appears when using a workflow is selected from the Assignment method for tasks list. |
   | Assign requests or tasks based on assignment group coverage areas | Enable this option to limit the assignment of security incidents and response tasks to groups that cover the location of the task. |
   | Scheduling ||
   | Auto-selection of agents consider time zone for tasks | Enable this option to consider the time zone of the agent when assigning a task. This field appears when auto-assignment is selected for security incidents or response tasks. |
   | Additional Factors ||
   | Auto-selection of agents consider location of agents | Enable this option to give preference to agents who are closer to the task location, when assigning any tasks. This field appears when auto-assignment is selected for security incidents or response tasks. |
   | Auto-selection of agents for tasks requires them to have skills | Select the degree to which agent skills must be matched to a task when determining auto-assignment. * Select all to require that an assigned agent must have all the skills to perform the task. An agent who lacks even one skill is eliminated. * Select some if you want agents who have most of the skills required to perform the task. * Select none if you want to auto-assign agents without taking skills into account. This field appears when auto-assignment is selected for security incidents or response tasks. {#t_ConfigureSIM__ul_jrs_t4z_5r} |
   | Auto-selection attempt to assign the same agent to all tasks in a request | Enable this option to auto-assign all response tasks for a security incident to the same agent. |
   [Table 2. Configuration screen --- Assignment tab]

   {#t_ConfigureSIM__table_gjj_3vk_ls}
4. Click the Add-ons tab and fill in the fields.  
   {#t_ConfigureSIM__table_vmk_nwk_ls__entry__2}

   | Field | Description |
   |-|-|
   | Documentation ||
   | Enable a dedicated knowledge base | Enable this option to activate the knowledge base for Security Incident Response. |
   | Enable managed documents | Enable this option to add a related list to managed documents. |
   | Enable task activities | Enable this option to log task interactions and communications, such as phone calls and email messages. |
   [Table 3. Configuration screen --- Add-ons tab]

   {#t_ConfigureSIM__table_vmk_nwk_ls}
5. Click Save.
{#t_ConfigureSIM__steps_osh_qb1_hr}

## Lock down security administration {#ariaid-title2}

To protect investigations and keep security incidents private, you can restrict Security Incident Response access to
security-specific roles and ACLs. Non-security administrators can be restricted from access,
unless you expressly allow them entry.

### Before you begin

When the Security Incident Response
application is activated, the System Administrator user is granted the sn_si.admin
role by default. The System Administrator is the only administrator who can set up
security groups and users.

A security role is required to have access to Security Incident Response
features and records.
Role required: sn_si.admin

### Procedure

1. After the Security Incident Response plugin has been activated, a user with the admin role assigns the Scoped Admin (sn_si.admin) role to at least one user.
2. The user with the admin role changes to the Security Incident scope.
3. Navigate to Allsys_store_app.list.
4. Type sn_si in the Scope field.  
5. Click Security Incident Response.
6. Scroll down to the Related Links and click Remove from the role contained by admin.
7. Log out and log back in.  
   The admin user cannot access the Security Incident Response application.
{#lock-down-security-admin__steps_cvl_2qb_1x}
**Related topics**   

* [Application administration](https://www.servicenow.com/docs/access?context=application-administration&version=australia&pubname=australia-application-development&ft:locale=en-US)

## Manage Restricted Caller Access {#ariaid-title3}

The Restricted Caller Access (RCA) feature enables an administrator to define cross-scope access to an application or application resource and allow or deny access requests. This feature is enabled in Security Incident Response by default so security analysts can protect sensitive security-related information.  
A field called Caller access has been added to all tables and script includes in Security Incident Response, and the field defaults to Caller Tracking. This setting means that application scopes are allowed access to Security Incident Response tables and script includes. However, a tracking record is created for each record and stored in the Restricted Caller Access Privilege \[sys_restricted_caller_access\] table.  
Note:  
Take care when changing records from Caller Tracking to Caller Restricted. Records with this status cannot be accessed until an administrator manually allows access to it. The administrator must navigate to System ApplicationsApplication Restricted Caller Access, locate the table or script include for which access has been requested, and change the Status field from Requested to Allowed.
**Related topics**   

* [Restricted caller access privilege settings](https://www.servicenow.com/docs/access?context=restricted-caller-access-privilege&version=australia&pubname=australia-application-development&ft:locale=en-US)
* [Set the application scope, application resource, and event access](https://www.servicenow.com/docs/access?context=scope-resource-access&version=australia&pubname=australia-application-development&ft:locale=en-US)

## Run quick start tests for Security Incident Response {#ariaid-title4}

Validate that Security Incident Response still works after you make any
configuration changes, such as applying an upgrade or developing an application. Copy and
customize these quick start tests to pass when using your instance-specific data.
Security Incident Response quick start
tests require activating Security Incident Response plugin
(com.snc.security_incident) and loading the demo data.  
{#quick-start-tests-sir__table_fkf_nfg_h1c__entry__3}{#quick-start-tests-sir__p_ikf_nfg_h1c}

| Test | Description | Release version |
|-|-|-|
| SIR: Create Security Incident | Determine whether a user can successfully create a security incident from the security incident form. | Madrid |
| SIR: Create Security Incident via Security Incident Catalog | Determine whether a user can successfully create a security incident from the catalog. | Madrid |
| SIR: PIR Assessments OOTB configuration test | Use this test to validate PIR assessments and base system configurations. | Tokyo |
| SIR: PIR Assessments conditional Configuration tests | Verify that security incidents matching the mandatory conditional rule are not closed without completing the post incident assessment.{#quick-start-tests-sir__p_gkf_nfg_h1c} Verify that the security incidents matching the optional conditional rule can be closed without completing the post incident assessment.{#quick-start-tests-sir__p_hkf_nfg_h1c} Verify that assessments are not generated for the security incidents that do not match any rule. | Tokyo |
| SIR: PIR Run Time Experience | Verify that PIR reports are configured and attached to the security incidents as per the new design. | Tokyo |
| SIR: PIR Design Time Experience | Verify that the security incident is mapped with the report template based on the administrator configuration. | Tokyo |
| SIR: Link Security Incident to a existing Major Security Incident | Link a Security Incident to an existing Major Security Incident and validate data from Security Incident rolled up to Major Security Incident. | Tokyo |
| SIR: Promote Security Incident as Major Security Incident | Promote a Security Incident as Major Security Incident and validate data from Security Incident rolled up to Major Security Incident. | Tokyo |
| SIR: Propose Security Incident as Major Security Incident | Propose a Security Incident as Major Security Incident and validate data from Security Incident rolled up to Major Security Incident. | Tokyo |
| SIR: Security Incident life cycle | Validate a Security Incident life cycle with the policy violation response tasks workflow. | Yokohama |
| SIR: Create Security Case | Create a Security Case from the Security Incident form. | Yokohama |
| Verify that only Allowed Members can access the security incident once Enforce Restriction is ON | Verify that only the allowed members can access the security incident once the Enforce Restriction is enabled. | Yokohama |
| Verify that security incident enabled with "Enforce Restriction" is not visible for any user | Verify that security incident enabled with "Enforce Restriction" is not visible for any user. | Yokohama |
| Validate Read Access | Validate the view access. | Yokohama |
| Validate Write Access | Validate the edit access. | Yokohama |
| SIR Workspace: Read Access | Verify that Read Access user can view the security incident without having security roles even on workspace. | Yokohama |
| SIR Workspace: Write Access | Verify that Write Access user can update the security incident without having security roles. | Yokohama |
| SIR Workspace: Create new Security Incident | Create new security incident from workspace. | Yokohama |
| SIR Workspace: Create Response Task | Create new response task from an existing security incident. | Yokohama |
| Now Assist for Security: Active Security Incident Summarization | Summarize an active security incident and validate the displayed sections. | Zurich |
| Now Assist for Security: Security Incident Summarization_Share to worknotes | Share the generated summary to worknotes. | Zurich |
| Now Assist for Security: Closed Security Incident Summarization | Summarize a closed security incident and validate the displayed sections. | Zurich |
[Table 4. Security Incident Response tests]

{#quick-start-tests-sir__table_fkf_nfg_h1c}
**Related topics**   

* [Quick start tests](https://www.servicenow.com/docs/access?context=quick-start-tests&version=australia&pubname=australia-application-development&ft:locale=en-US)

*[\>]: and then


