---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create Security Incident from a Vulnerability Record

# Create Security Incident from a Vulnerability Record {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 26, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create a security incident to track and manage remediation efforts for identified vulnerabilities. This process helps prioritize security responses and maintain audit trails.

## Before you begin

Role required:

* sn_sec_tisc.analyst
* sn_si.analyst
{#tisc-create-security-incident__ul_mb5_bkj_s3c}

## About this task

Before you begin, ensure that Security Incident Response (SIR) application is installed.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select the Threat Intel Library icon on the workspace.
3. Go to Vulnerability ArtifactsAll Vulnerabilities.
4. Open a vulnerability record.
5. Select Create Security Incident.
6. On the form, Short description is automatically populated (required) and optionally update category, priority, assignment group, and description as necessary.  
7. Select Submit.  
   A confirmation message appears indicating that Security incident {\*\*\*\*\*\*\*\*} created successfully, and a link to the Security Incident record is provided.  
   Note:  
   * When you click the link from the confirmation message, the Security Incident opens in read-only mode. The record includes a reference to the originating vulnerability, and relevant fields are automatically populated to maintain consistency.
   * A corresponding work note is also added to the vulnerability record. To access it, go to the Details section of the vulnerability record.
   * Additionally, the system records a work note on the activity stream of the Security Incident Response Workspace indicating that the incident record is originated from a TISC vulnerability and providing a link to the related vulnerability record.
   {#tisc-create-security-incident__ul_jg2_gmj_s3c}

   The TISC Context feature in the Security Incident Response Workspace provides analysts direct access to threat intelligence linked to vulnerabilities associated with incidents. For more information, see [Working with TISC Context](https://www.servicenow.com/docs/XJLrjsZMHTbiB3FEVLygIA "TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.").

   This capability allows analysts to view and investigate related threat objects without leaving the Security Incident Response Workspace, streamlining analysis and enhancing incident response efficiency.
**Related concepts**   

* [TISC integration within SIR Workspace](https://www.servicenow.com/docs/R8vQjkmxUTHpPF0xDNBnnA "The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.")

*[\>]: and then


