---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Reporting incidents from SOW and SIR Workspace in DRIR

# Reporting incidents from SOW and SIR Workspace in DRIR {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Reporting incidents from SOW and SIR Workspace in DRIR

High-impact, high-urgency incidents created or marked as high priority in the Service Operations Workspace (SOW) of Incident Management or the Security Incident Response (SIR) Workspace are classified as major incidents.
These major incidents are logged and reported through the Digital Resilience Incident Reporting (DRIR) application.
This process ensures timely and structured reporting for critical ICT-related incidents, security breaches, or operational payment issues.
Show full answer Show less  

## Incident Reporting Workflow

* **Incident Verification:** Determine if the incident qualifies as major by assessing if it affects critical services, involves a security breach, or operational payment issues.
* **Incident Classification:** Automatically classify incidents involving malicious unauthorized access as major. Otherwise, incidents not impacting critical services are not classified as major.
* **Incident Record Creation:** Create an incident record capturing key details such as case number, source, state, subtype, priority, and requester. Related actions are documented in the Activities panel.
* **Notification:** Send email updates to the DORA analyst to keep them informed about case progress.
* **Initial Report:** Automatically generate an initial report within 24 hours of major classification.
* **Response Activation:** Initiate response steps for the incident.
* **Intermediate Report:** For incidents open more than three days, review and update the report every 72 hours until closure or termination conditions are met.
* **Response Review:** Ongoing review of response actions if the incident remains open.
* **Final Report:** Upon incident closure, verify and enrich case notes and generate a final report one month after classification.

## Incident Reporting Timelines

Timely reporting is critical to effective incident management. The following table summarizes key report deadlines from the time an incident is classified as major:

* **Initial report:** Within 24 hours
* **Intermediate report:** Every 72 hours (3 days), recurring until incident closure or termination
* **Final report:** One month after classification

## Case Generation and Status Tracking

When an incident is marked as critical in the SOW or SIR Workspace, a corresponding case is automatically generated in the Digital Resilience Incident Reporting application. The DRIR application supports tracking and managing these cases with status indicators.

The regulatory reporting status of each DRIR case---categorized as Potentially Reportable, Reportable, or Not Reportable---is displayed in the Details panel and within the Regulation Mappings related list. The previous dedicated 'Reporting Status' form section has been removed and consolidated into the Details panel for streamlined access.

## Practical Benefits for ServiceNow Customers

* Standardized and automated major incident classification and reporting improve compliance and response efficiency.
* Clear timelines and structured reporting stages help ensure timely communication with regulatory analysts and stakeholders.
* Integrated status tracking within the DRIR application enables real-time visibility into incident progress and regulatory reporting requirements.
* Consistent workflows across Incident Management and Security Incident Response Workspaces simplify incident handling for critical events.  
High-impact, high-urgency incidents created or marked as high priority in the SOW of Incident Management or SIR Workspace of Security Incident Response are classified as major incidents. These major incidents are logged and reported in the Digital resilience incident reporting application.

## Incident reporting workflow {#integration-with-incident-management__section_ayx_1qk_sdc}

The following example shows a sample workflow for reporting an incident in Incident Management.  
1. Incident verification: Determine if the reported incident is a major ICT-related incident, a security breach, or an operational payment issue. Assess whether any critical services are impacted.
2. Incident classification: If the critical services affected criterion is not met, the incident is not classified as major. If there is any report of malicious unauthorized access to the network and information systems, the incident is automatically classified as major.
3. Incident record creation: Create an incident record. The Details tab includes information such as the case number, source, state, subtype, priority, requester, and other relevant details. Review actions related to the case which are documented in the Activities panel on the Details tab.
4. Notification: Send an email notification to the DORA analyst to update them on the progress of the case.
5. Initial report: Automatically collect initial report data. Generate an initial report no later than 24 hours once the incident is classified as major.
6. Response activation: Activate the response steps for the incident.
7. Intermediate report: Review the incident report, if the incident has been open for more than three days. Update the incident data in the intermediate report, which is generated no later than 72 hours after the incident is classified as major.
8. Response review: If the incident is still open, review the response steps.
9. Final report: Verify if the incident is closed and enrich the notes in the record. Update the final report with the revised notes, which is generated one month after the incident is classified as major.
{#integration-with-incident-management__ol_izy_dqk_sdc}

## Incident reporting timelines {#integration-with-incident-management__section_tyd_t5k_sdc}

To report an incident, the following timelines are considered.{#integration-with-incident-management__table_t3p_w5k_sdc__entry__2}

| Report type | Timeline (From the time the incident is classified as major) |
|-|-|
| Initial report | 24 hours |
| Intermediate report | 72 hours Note: The intermediate report is cyclical. A new intermediate assessment is generated every 72 hours (3 days) from the time the incident is classified as major until the source incident is closed or the termination conditions configured on the DRI Intermediate report template are met. |
| Final report | 1 month |
[Table 1. Reporting timelines]

{#integration-with-incident-management__table_t3p_w5k_sdc}

## Case generation in Digital resilience incident reporting {#integration-with-incident-management__section_gvv_c2n_ydc}

When an incident is marked as critical in the Service Operations Workspace of the Incident Management application as shown in the example, a case is generated in Digital resilience incident reporting.
The SIR Workspace deploys a similar workflow for reporting high-impact incidents which are then logged in Digital resilience incident reporting.

## Where to find the case status {#integration-with-incident-management__section_hxk_gy1_gjc}

The Regulatory reporting status of a DRI case (Potentially reportable/Reportable/Not reportable) is displayed in the Details panel and per regulation in the Regulation Mappings related list. The dedicated 'Reporting status' form
section that existed in earlier releases has been removed; the same information is now in the Details panel.

