Configuring Now Assist for Security Incident Response
Summarize
Summary of Configuring Now Assist for Security Incident Response
The Now Assist for Security Incident Response application integrates generative AI capabilities into the Security Incident Response Workspace and the legacy Core UI (UI16) within ServiceNow. It helps automate and enhance security incident management through AI-driven skills and workflows.
Show less
Configuration is managed via the Now Assist Admin console, which centralizes installation, setup, and control of AI skills related to security incident response.
Key Features
- Role Masking: Limits AI agent access by assigning predefined roles and privileges. When selecting user access by roles, ensure these roles are included in security controls and data access settings.
- Data Sharing: Sharing data with the ServiceNow AI development program improves prediction accuracy and reduces AI hallucinations. Customers can opt out of data sharing per instance via the Now Assist Admin console.
- Now Assist Skills for Security Incidents:
- Incident Summarization (supports all states except Draft)
- Resolution Notes Generation
- Security Operations Metrics Analysis
- Recommended Actions (supports all states except Closed and Cancelled; requires AI Search enabled)
- Correlation Insights (supports all incident states)
- Post-Incident Analysis
- Content Generation for Shift Handover
- Security Incident Resolution Plan
- Security Incident Quality Assessment
- Automatic Updates: Updating the Now Assist for Security Incident Response application automatically updates its dependencies.
- Skill Management: Generative AI skills and agentic workflows can be activated, deactivated, and configured through Guided Setup.
Practical Considerations for ServiceNow Customers
- Ensure AI Search is enabled to use the Recommended Actions skill effectively; verify via AI Search Status.
- Configure security controls carefully to align AI agent roles with your organization's access policies.
- Install necessary plugins: Now Assist for Security Incident Response (snsecgenai) and Security Incident Response Core (snsi).
- Manage data sharing preferences proactively to balance AI capability improvements with organizational data governance requirements.
The Now Assist for Security Incident Response application is supported in the Security Incident Response Workspace and in the legacy Core UI (UI16). Use the guided setup in the Now Assist Admin console to configure Now Assist for Security Incident Response.
Configuration overview
Role masking enables users to limit the roles and privileges of AI agents during tool execution. AI agents that get installed with Now Assist applications are assigned pre-defined roles. If you select Users with specific roles for user access, you must configure the security controls to include these roles. Data access settings must also include these roles. For the instructions to change the security controls, see Define security controls for an AI agent.
By sharing data with the ServiceNow® AI development program, you provide relevant data to help improve prediction accuracy, user experience, tailor products to your business needs, and reduce hallucinations for your activated Now Assist skills.
You can opt out of a ServiceNow instance from sharing data from the Now Assist Admin console. See Opt out of data sharing for Now Assist. Repeat the opt-out process for all instances that use the Now Assist functionality.
The following table lists the features and skills that you can access from the Now Assist Admin console.
| Now Assist Technology product | Security incident skills |
|---|---|
| Now Assist for Security Incident Response | Security incident summarization Note: The incident summarization supports security incidents in any state other than Draft. |
| Resolution notes generation. | |
| Security operations metrics analysis | |
| Security incident recommended actions The security incident recommended actions skill supports security incidents in any state other than Closed and Cancelled. Note: The AI Search application must be enabled so that the Recommended Actions skill works for security incidents. To verify AI Search is enabled on your instance, navigate to . Contact support if the page indicates that AI Search is not enabled. Correlation insights support security incidents in all states. |
|
| Post-incident analysis | |
| Generate content for shift handover | |
| Security incident resolution plan | |
|
Security incident quality assessment |
- Install Now Assist plugins.
Install the Now Assist for Security Incident Response application (sn_sec_gen_ai) and Security Incident Response Core [sn_si] applications.
Note:When you update the Now Assist for Security Incident Response application, its dependency applications are automatically updated.
- Configure a skill for Now Assist for Security Incident Response
You can deactivate, configure, and reactivate generative AI skills and agentic workflows in the Guided Setup.