Configuring ServiceNow Otto for Security Incident Response (SIR)
Summarize
Summary of Configuring ServiceNow Otto for Security Incident Response (SIR)
The ServiceNow Otto for Security Incident Response (SIR) application integrates generative AI capabilities into the Security Incident Response Workspace and the legacy Core UI (UI16). It enhances your security incident management by providing AI-driven skills such as incident summarization, resolution notes generation, and recommended actions. Configuration is performed through the AI Admin Hub console, which centralizes installation and skill management.
Show less
Key Features
- AI Access Control: AI agents use role masking to control user access. If you select access based on specific user roles, you must configure corresponding security controls to include those roles.
- Generative AI Skills: Includes security incident summarization (for incidents in any state except Draft), resolution notes generation, metrics analysis, recommended actions (excluding Closed and Cancelled states), correlation insights, post-incident analysis, shift handover content generation, resolution planning, and quality assessment.
- AI Search Dependency: The Recommended Actions skill requires the AI Search application to be enabled in your instance.
- Data Sharing: Sharing data with the ServiceNow AI development program improves prediction accuracy and user experience but can be opted out per instance via the AI Admin Hub console.
- Automatic Updates: Updating the ServiceNow Otto for SIR application automatically updates its dependency applications, ensuring compatibility and feature continuity.
- Guided Setup: Use the AI Admin Hub console to install required plugins, configure generative AI skills, and manage agentic workflows. Skills can be deactivated, configured, and reactivated as needed.
Practical Considerations for ServiceNow Customers
- Ensure you install both the ServiceNow Otto for Security Incident Response (snsecgenai) and Security Incident Response Core (snsi) applications.
- Verify that AI Search is enabled to fully utilize recommended action features.
- Manage user access carefully by configuring role-based security controls to match your organizational requirements.
- Be aware of which AI skills and workflows are enabled by default, and adjust settings based on your operational preferences.
- Regularly review and update your configurations via the AI Admin Hub console for optimal performance and security incident response efficiency.
The ServiceNow Otto for Security Incident Response (SIR) application is supported in the Security Incident Response Workspace and in the legacy Core UI (UI16). Use the guided setup in the AI Admin Hub console to configure ServiceNow Otto for Security Incident Response (SIR).
Configuration overview
AI agents use role masking to determine which users can access them. Ones installed with your applications have specific roles that come included with the application. If you select Users with specific roles for user access, you must configure the security controls to include these roles. For the instructions to change the security controls, see Define security controls for an AI agent.
By sharing data with the ServiceNow® AI development program, you provide relevant data to help improve prediction accuracy, user experience, tailor products to your business needs, and reduce hallucinations for your activated ServiceNow Otto skills.
You can opt out of a ServiceNow instance from sharing data from the AI Admin Hub console. See Opt out of data sharing for Now Assist. Repeat the opt-out process for all instances that use the ServiceNow Otto functionality.
The following table lists the features and skills that you can access from the AI Admin Hub console.
| ServiceNow Otto product | Security incident skills |
|---|---|
| ServiceNow Otto for Security Incident Response (SIR) | Security incident summarization Note: The incident summarization supports security incidents in any state other than Draft. |
| Resolution notes generation. | |
| Security operations metrics analysis | |
| Security incident recommended actions The security incident recommended actions skill supports security incidents in any state other than Closed and Cancelled. Note: The AI Search application must be enabled so that the Recommended Actions skill works for security incidents. To verify AI Search is enabled on your instance, navigate to . Contact support if the page indicates that AI Search is not enabled. Correlation insights support security incidents in all states. |
|
| Post-incident analysis | |
| Generate content for shift handover | |
| Security incident resolution plan | |
|
Security incident quality assessment |
- Install plugins for ServiceNow Otto.
Install the ServiceNow Otto for Security Incident Response (SIR) application (sn_sec_gen_ai) and Security Incident Response Core [sn_si] applications.
Note:When you update the ServiceNow Otto for Security Incident Response (SIR) application, its dependency applications are automatically updated.
- Configure a skill for ServiceNow Otto for Security Incident Response (SIR)
You can deactivate, configure, and reactivate generative AI skills and agentic workflows in the Guided Setup.