---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create cases in Security Case Management

# Create cases in Security Case Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Cases are used to track information about a campaign or state actor threatening your
organization. After a case is created, you can add artifacts that allow you to review and
analyze all related information within a single case record.

## Before you begin

Role required: sn_ti.case_use
r

## Procedure

1. Navigate to AllThreat IntelligenceCase ManagementAll Cases.  
   The Security Cases list opens.
2. Click New.  
   The Security Cases screen opens.
3. Fill in the fields as appropriate.  
   {#create-cases-in-case-mgmt__table_t4d_4bd_5s__entry__2}

   | Field | Description |
   |-|-|
   | Case Number | \[Read only\] The case number. |
   | Case Name | Enter a descriptive name for the case. |
   | Case Type | Select the type of case being investigated. |
   | Rating | Select the importance of this case (from Critical to Low). |
   | Last Updated | \[Read only\] The date and time the case was last updated. |
   | Short Description | A brief description of the case. |
   [ ]

   {#create-cases-in-case-mgmt__table_t4d_4bd_5s}
4. Click the Additional Case Details tab.  
5. Fill in the fields as appropriate.  
   {#create-cases-in-case-mgmt__table_ecw_znv_xy__entry__2}

   | Field | Description |
   |-|-|
   | Created by | \[Read only\] The name of the user who created this case. |
   | State | The current state of the case. At case creation, the State defaults to Draft. |
   | Assigned to | Click the lookup icon and assign the case to an analyst. |
   | Work notes list | Click the lock icon and add internal users who can view work notes. |
   | Additional comments | As needed, enter notes on the case that will be visible to the customer. |
   | Work Notes | If needed, type a work note for the case. |
   [ ]

   {#create-cases-in-case-mgmt__table_ecw_znv_xy}
6. Click Submit.  
   After the record has been saved, you can click the Case Artifacts tab and [add
   artifacts to the case](https://servicenow-prod.fluidtopics.net/pRIpTBzc8pYtBEji6ua~zg "After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.").
* **[Add artifacts to a case](https://servicenow-prod.fluidtopics.net/pRIpTBzc8pYtBEji6ua~zg)**   
  After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.
* **[Associate MITRE-ATT\&CK information with security case](https://servicenow-prod.fluidtopics.net/vR0MxG6Hmr3ZC~hcuvahbg)**   
  Associate MITRE-ATT\&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.

*[\>]: and then


