---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Case creation from security artifacts

# Case creation from security artifacts {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In addition to creating cases manually from Security Case Management, you can also create cases from
security artifacts, such as security incidents, indicators of compromise, affected users, and
configuration items.
* **[IoCs and observables in cases](https://servicenow-prod.fluidtopics.net/qyAKXsQrLeCMszdo9WHwsw)**   
  In Threat Intelligence, you can create cases from IoCs and observables, as well as add IoCs and observables to existing cases. You can also create observables directly from a case.
* **[Security incidents in cases](https://servicenow-prod.fluidtopics.net/XBtNos2KOnm8izozfspq6A)**   
  In Security Incident Response, you can create cases from security incidents, CIs, and affected users, as well as add those artifacts to existing cases.
* **[Configuration items in cases](https://servicenow-prod.fluidtopics.net/UbIFNlTe7tYZHzdZ701NIA)**   
  You can create a new case from one or more configuration items (CI) in the Configuration Item \[cmdb_ci\] table. You can also add CIs to existing cases.
* **[Affected users in cases](https://servicenow-prod.fluidtopics.net/h53gCYmkyckEDUd9uuMb3A)**   
  You can create a new case from one or more affected users in the User \[sys_user\] table. You can also add users to existing cases.

