---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Understanding Security Incident Response

# Understanding Security Incident Response {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Understanding Security Incident Response

Security Incident Response (SIR) in ServiceNow helps you manage the full life cycle of security incidents---from detection and analysis to containment, eradication, recovery, and post-incident review.
It provides analytic-driven dashboards and reporting to identify trends and bottlenecks in your incident response processes, enabling your security team to respond efficiently and effectively.
Show full answer Show less  
SIR supports integration with third-party cybersecurity tools and partner apps from the ServiceNow Store, enabling automation and orchestration for faster incident handling. Access control features ensure sensitive security incidents and investigations remain restricted to authorized security roles, enhancing data privacy and protection.

## Key Capabilities

* **Incident Discovery:** Security incidents can be logged manually, generated from internal events, or created via external monitoring and vulnerability tracking systems. Incidents can also be submitted through the service catalog.
* **Incident Analysis:** The Security Incident form offers customizable views showing vulnerabilities, related incidents, changes, problems, and tasks linked to affected configuration items (CIs). It leverages external databases like NIST and third-party detection tools to identify malware and vulnerabilities. Business service maps help locate other potentially impacted services for comprehensive analysis.
* **Containment, Eradication, and Recovery:** You can assign tasks across departments and use business service maps to coordinate responses, including creating problems, changes, and communication activities like SMS or bridge calls.
* **Post-Incident Review:** After resolution, SIR facilitates conducting post-incident reviews through meetings, surveys, and automated reports that document the incident timeline, actions taken, related records, and lessons learned. Knowledge base articles created from these reviews support faster resolution of future incidents.

## Access Control and Security

Access to Security Incident Response is restricted to security-related roles and ACLs to ensure confidentiality. Non-security administrators are blocked unless explicitly allowed. Even administrators impersonating security admins have limited access to sensitive information and cannot change passwords for security admin users.

## Terminology Highlights

* **Active Incident:** Any incident not closed or cancelled.
* **Administrator Lockdown:** Restriction of system access to authorized security personnel only.
* **Response Tasks:** Assigned actions to respond to security threats.
* **Threat Lookup and Vulnerability Scan:** Requests initiated from the system to scan files, URLs, IPs, or affected resources for malware and vulnerabilities.
* **Security Incident Treemaps:** Visual charts showing hierarchical incident data.

## Practical Benefits for ServiceNow Customers

By leveraging Security Incident Response, your security team can:

* Streamline and document the entire incident handling process with role-based access control for security data protection.
* Gain actionable insights from integrated analytics and reporting to improve response efficiency.
* Automate and orchestrate response activities through integrations with third-party cybersecurity tools.
* Ensure continuous improvement via structured post-incident reviews and knowledge sharing.  
With Security Incident Response (SIR), manage the life cycle of your security
incidents from initial analysis to containment, eradication, and recovery. Security Incident
Response enables you to get a comprehensive understanding of incident response procedures
performed by your analysts, and understand trends and bottlenecks in those procedures with
analytic-driven dashboards and reporting.

Watch this video to learn about the SIR process, using Security Incident Response to thwart attacks and viewing security activity in the Security Incident Response Explorer.
Built in integrations with third-party cyber security solutions and partner-developed integrations from the ServiceNow Store enable security automation and orchestration for efficient and accurate incident response.  
To protect your investigations and keep security incidents private, Security Incident Response provides the means to restrict access to the system to specific security-related roles and ACLs. Non-security administrators can be restricted from access, unless you expressly allow them entry.  
Note:  
IT System Administrators \[admin\] can impersonate ServiceNow users. However, when impersonating a user with an application admin role for Security Incident Response, an admin cannot access features granted by that role, including security incidents and profile information. Access to modules and applications in the navigation bar is also restricted. Also, admin cannot change the password of any user with an application admin role for Security Incident Response.

## Discovery {#what-is-sir__section_qrm_cpv_gbb}

Security incidents can be logged or created in the following ways.

* From the Security Incident form
* From events that are spawned internally, or created by external monitoring or vulnerability tracking systems via alert rules, or manually
* From external monitoring or tracking systems
* From the service catalog
{#what-is-sir__ul_h14_dpv_gbb}

## Analysis

Depending on the selected view, you are using (default, Non-IT Security, Security ITIL, and so
on), the Security Incident form can show any combination of vulnerabilities, incidents,
changes, problems, tasks on the affected CI and affected CI groups. The system can identify
malware, viruses, and other areas of vulnerability by cross-referencing the National
Institute of Standards and Technology (NIST) database, or other third-party detection
software. As security incidents are resolved, you can use any incident to create a security
knowledge base article for future reference.

Perform further analysis using a business service map to locate other affected systems or
business services that can be infected.

## Containment, Eradication, and Recovery

As you monitor and analyze vulnerabilities, you can create and assign tasks to other
departments. You can use a business service map to create tasks, problems, or changes for
all affected systems, documents, activities, SMS messages, bridge calls, and so forth.

## Review

After the incident is resolved, other steps can take place before closure. You can perform a post incident review. Creating knowledge base articles can help with future similar incidents. Significant incidents may require a post-incident resolution review. This review can take several forms. For example:

* Conduct a meeting to discuss the incident and gather responses.
* Write and distribute to those teams who worked on an incident a list of resolution review questions designed for each category or priority of incident.
* Incident managers can write the report and gather information on their own.

{#what-is-sir__ul_xhs_tsn_js}An incident resolution review report can be automatically generated that includes:

1. a summary of what was done
2. the time line
3. the type of security incident encountered
4. all related incidents, changes, problems, tasks, CI groups
5. the details of the resolution
{#what-is-sir__ol_dyd_3sj_bwb}In addition, an automated security incident resolution review survey system is available. It gathers the names of all users assigned to a security incident, and sends out a customized survey to gather data about the handling of the incident. This data can then be made available in a generated security incident review report, which you can edit into a final draft. Similar data can be added to a knowledge base article to contain lessons learned and the steps to take to resolve similar issues in the future.

## Request apps on the Store {#what-is-sir__section_ep3_152_ygb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#what-is-sir__inline-send-to-store}

## Security Incident Response Terminology

The following terms are used in Security Incident Response.{#what-is-sir__table_vks_thr_ns__entry__2}

| Term | Definition |
|-|-|
| Active | Any security incident not in the closed or cancelled state. |
| [Administrator lockdown](https://www.servicenow.com/docs/gqmIYzSxVmc1BRC0QrIihw#lock-down-security-admin "To protect investigations and keep security incidents private, you can restrict Security Incident Response access to security-specific roles and ACLs. Non-security administrators can be restricted from access, unless you expressly allow them entry.") | The ability to restrict Security Incident Response access to personnel with security-related roles and ACLs. |
| [Inbound security requests](https://www.servicenow.com/docs/pySIpv7nCxL73lJ3mJ38ag "After a security incident has been created, there are numerous types of information that can be added and viewed as your analysis of the issue progresses toward resolution.") | Requests submitted for low-impact security demands, such as requesting a new electronic badge. |
| [Manage post incident activities](https://www.servicenow.com/docs/oqrtXBycQIK~wMQ90skcig "Based on the requirements of your business, a review of the origins and handling of security incidents is often needed.") | A review of the origins and handling of a security incident. The final product is a post incident report, which documents all actions performed and the reasons for doing them. |
| [Response tasks](https://www.servicenow.com/docs/DkulBUxdF_PGJ3kaSScQ4g "After a security incident has been created, you can create response tasks to track separate actions to be performed to respond to the security issue.") | Tasks assigned to a security incident for tracking actions in response to the threat. |
| [Understanding security incident calculators](https://www.servicenow.com/docs/N6z~BYotFzbRRD52y344Xw#c_SecIncCalculators "Security incident calculators are used to update record values when pre-defined conditions are met. The calculators are grouped based on the criteria used to determine how the records are updated.") | Calculators used to update record values when pre-configured conditions are met. |
| [Security incident treemaps](https://www.servicenow.com/docs/VjBrTcgLsXEMFFKRtbmsPQ "Treemaps display hierarchical (tree-structured) data as a set of nested rectangles. Each branch of the tree is given a rectangle, which is then tiled with smaller rectangles representing subbranches. Treemaps allow you to display security incident information in a dynamic, engaging way.") | Chart type that hierarchically shows security incident data in the form of nested rectangles. |
| [Threat lookup](https://www.servicenow.com/docs/_h_zmtwW9jmT1yKUBmmySQ "If the Security Incident Response plugin is activated, you can submit threat lookups for files, hash values, URLs, and IP addresses from the Security Incident Catalog. The requests are submitted and you can view the results in the My Requests module.") | A request submitted from the security incident catalog for scanning files, URLs, and IP addresses for malware. |
| [Vulnerability scan](https://www.servicenow.com/docs/Ln~zPADaTR0MCqUSbwgEKw "If your security incident has one or more configuration items (servers, computers, and so on), they can be scanned for vulnerabilities from the Security Incident Response form.") | A request initiated from the Security Incident form for scanning affected resources (servers, computers, and other configuration items) for vulnerabilities. |
[ ]

{#what-is-sir__table_vks_thr_ns}

