---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create response tasks

# Create response tasks {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

After a security incident has been created, you can create response tasks to track
separate actions to be performed to respond to the security issue.

## Before you begin

Important:  
If you are unable to create a response task, verify that no custom ACLs on the task table are blocking access.

Role required: sn_si.basic

## Procedure

1. Navigate to the appropriate location to open the security incident for which you want to create tasks.  
   For example:
   * To create a response task based on a security incident assigned to you, select Security IncidentIncidentsAssigned to Me.
   * To create a response task based on a security incident assigned to your team, select Security IncidentIncidentsAssigned to TeamIncidents.
   * To create a response task based on an unassigned security incident, select Security IncidentIncidentsUnassigned Incidents.
   {#t_CreateResponseTask__ul_om4_zwr_ps}
2. Open the security incident for which you want to add response tasks.
3. Select the Add Response Task button in the form header.  
   Note:  
   To create any other task, select the Tasks tab in the incident Related List.
4. Fill in the fields on the form, as appropriate.  
   {#t_CreateResponseTask__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | Select security tag | If you set up and activated [security tags](https://www.servicenow.com/docs/bus9vK7pliypx82WYkj9OQ "You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them."), you can select one or more tags to add metadata to the record or specify the degree of sensitivity of the response task. If you did not set up or activate security tags, this drop-down list is not displayed. |
   | Number | \[Read only\] The automatically generated Security Incident Response number. |
   | Parent | \[Read only\] The number of the related security incident. |
   | Configuration Item | The configuration item (resource) affected by the security issue. |
   | Affected User | The person affected by the security issue. |
   | Priority | The priority used to determine when this task is performed. |
   | State | The current state of the security response task. Upon task creation, this field defaults to Draft. |
   | Skills | The skill required to perform this task. Select the lock icon and select the skill required. After you have completed your selections, select the lock icon again. |
   | Assignment group | The assignment group from which the assigned worker is selected. Note: Select an external group if you want to provide the read-only access of the parent security incident of this response task. |
   | Assigned to | The individual assigned to perform the task. |
   | Access to security incident | Option to provide the read-access to the parent security incident of this response task. |
   | Short description | A description of the Security Incident Response task. |
   | Description | A description for the selected task. |
   | Secure notes | The work notes that are encrypted and not visible to the customer. |
   | Work notes | The work notes that aren't visible to the customer. |
   | Comments | Comments that you want to be visible to the customer. |
   | Email | Option to send email to the stakeholders. |
   [Table 1. Security incident]

   {#t_CreateResponseTask__table_vks_thr_ns}
5. When you have completed your entries, select Submit.  
   Note:  
   After you have created Security Incident Response tasks, you can view them using any of the following applications under the Response Tasks module:
   * Assigned to Me.
   * Assigned to Team.
   * Show Open Tasks
   * Show All Tasks
   * Unassigned Tasks.
   {#t_CreateResponseTask__ul_xks_thr_ns}
{#t_CreateResponseTask__steps_lsq_ywr_ps}

*[\>]: and then


