---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure the Security incident resolution plan skill

# Configure the Security incident resolution plan skill {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Add your existing runbooks to the resolution plan generation skill. The runbooks provide additional context to the resolution plan generation skill.

## Before you begin

Role required: sn_si.admin

## About this task

Important:  
This generative AI skill is turned on by default. The skill will be automatically available to appropriate role users for the application. For more information, see [AI agents, skills, and agentic workflows on by default](https://www.servicenow.com/docs/access?context=now-assist-skills-on-by-default&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

## Procedure

1. Navigate to AdminAI Admin HubAI Skills.
2. In Technology, select Security Operations.
3. In the Security Incident resolution plan tile, select ![More actions icon.]().
4. Select Edit.
5. Select Add AI Runbooks.
6. In the Additional Runbook Context page, select Add.
7. In Condition, enter a condition when the skill must reference the runbook.  
   For example, set the condition as <kbd class="ph userinput">If category is Phishing and affected user VIP status is true</kbd>.
8. In Choose KB Reference, select a knowledge base article runbook.
9. In Order, set an order of importance.  
   You can set Order to any positive integer, a lower value indicating a higher priority.
10. Select Save and continue.

*[\>]: and then


