---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations common functionality

# Security Operations common
functionality {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Security Operations Common Functionality

The Security Support Common plugin is automatically activated with any main Security Operations applications such as Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance.
It provides foundational modules and shared functionalities across all Security Operations applications, enhancing integration, data processing, and workflow capabilities.
Access to Security Operations modules requires thesnseccmn.adminrole, which is inherited from administrative roles within any Security Operations app.
Show full answer Show less  

## Key Features

* **Integration Reference:** Includes pre-built integrations for Security Incident Response, Threat Intelligence, and Vulnerability Response with instructions to activate plugins, configure integrations, and guidelines for creating custom integrations.
* **Email Processing:** Enables inbound information integration from external detection systems, handles unmatched emails, prevents duplicate records, and provides granular control of data processing.
* **Filter Groups:** Allows creation of groups to filter and locate records across any table, such as grouping computers by manufacturer or filtering configuration items by vulnerabilities or subnet IP ranges.
* **Escalations:** Supports creation of escalation paths for security incidents, allowing issues requiring higher attention to be routed to specialized groups, with escalation options appearing on relevant incident records.
* **Security Tags and Tag Groups:** Tags can be assigned to incidents, response tasks, vulnerable items, indicators of compromise, and cases to create metadata and define access control for security content.
* **Enrichment Data Mapping:** Transforms data from XML, JSON, or Properties files into ServiceNow records, supporting workflows that enrich security incident data.
* **Field Value Transforms:** Converts customer-specific field values into standardized values recognized by Security Operations for consistent data parsing, enrichment, and mapping.
* **Field Mapping:** Links Security Operations tables with other ServiceNow tables, enabling relationships between security incidents and customer service cases, problems, or other security tasks.
* **On-Demand Orchestration:** Allows security analysts to trigger specific tasks (e.g., process dumps on configuration items) directly from incident workflows to aid investigation and response.
* **CMDB CI Identifier Rules:** Defines rules to identify configuration items in the CMDB by matching data from third-party integrations, ordered by evaluation precedence.
* **Operating System Groups:** Maps operating systems to process types and scripts used in Security Incident Response workflows, enabling customized process retrieval logic.
* **Security Annotations:** Provides the ability to add explanatory notes or comments to configuration items, observables, or security incidents for contextual information.
* **Search Functionality:** Uses the Zing text indexing engine to enable fast, comprehensive searching across all Security Operations applications.
* **Legacy Workflow Triggers:** Supports workflows triggered by specific table conditions to automate processes when conditions are met.
* **Security Operations Orchestration:** Facilitates interaction with Windows and UNIX systems through activity packs and workflows, enabling data retrieval and task automation.

## Practical Benefits for ServiceNow Customers

* Streamlines integration and data ingestion from multiple security tools and external systems to maintain a unified, enriched security operations environment.
* Enables granular management of security incidents through escalation paths, tagging, and annotations to improve incident handling and collaboration.
* Provides flexible filtering and grouping capabilities to efficiently organize and analyze assets, vulnerabilities, and security-related data.
* Facilitates automation and orchestration of investigative tasks directly within security incident workflows, enhancing analyst productivity.
* Ensures consistent and standardized data formats via enrichment and field value transformation, improving accuracy and interoperability across security modules.
* Supports domain separation with customizable property overrides to adapt Security Operations functionality across different business units or domains.  
Whenever any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated, the Security Support Common plugin is activated. This plugin loads various modules that provide functionality that is common across all Security Operations applications.  
Note:  
Only users with the \[sn_sec_cmn.admin\] can view and use the Security Operations module. This role is inherited when you are assigned an administrative role in any of the Security Operations applications.

## Security Operations Modules {#sec-ops-common-functionality__section_htx_lg1_21b}

{#sec-ops-common-functionality__table_td5_g1s_3z__entry__2}

| Feature | Description |
|-|-|
| [Security Operations Integration Reference](https://servicenow-prod.fluidtopics.net/pLM1~qwCDCY6CHnJkE4~wg "Developers and ServiceNow partners can use the information in this section to gain understanding of the under-the-hood functionality of third-party integrations, including development guidelines, integration capabilities, and workflows."), [Threat Intelligence integrations](https://servicenow-prod.fluidtopics.net/9sJ8C7LcH1yxYckRbWLCuw "The Threat Intelligence base system includes integrations to third-party malware-detection software packages. This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system."), [Vulnerability Response integrations](https://servicenow-prod.fluidtopics.net/5tRtjEBZLs~2Uym3WljEBw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") | Several integrations are included with the Security Operations applications (Security Incident Response, Threat Intelligence, and Vulnerability Response). This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system. |
| [Security Operations email processing](https://servicenow-prod.fluidtopics.net/0MR_cKqhArGhCnE5mGTnRg "You can set up the integration of information from external detection systems, provide granularity in processing security operations records, handle unmatched emails, and prevent duplication of records using Email Processing.") | You can set up the integration of information from external detection systems, provide granularity in processing security operations records, handle unmatched emails, and prevent duplication of records using Email Processing. |
| Groups | * Filter Groups Create and use filter groups to locate records from any table on your instance. For example, you can create a group of all computers by the same manufacturer. You can also filter configuration items (CIs) that have similar vulnerabilities or that fall within a particular subnet IP address range. * Escalations You can create an escalation path for security incidents for issues requiring more attention or expertise. Once an escalation group exists, a button appears on any security incident in that group. {#sec-ops-common-functionality__ul_zlv_wdk_nsb} |
| Security Tags | Tags: Security tag rules provide filtering for security tag access. |
| Utilities | * Enrichment Data Mapping Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents. * Field Value Transforms Transforms unique customer field values into field values recognized by Security Operations email parsing, data enrichment or tables using field maps. Supports choice fields, references, and aligns external data into the standard terminology and format for your new record. * Field Mapping Security Operations tables can be mapped to and from other tables, linking a security incident to a customer service case or a problem to other parts of the Security Operations system. For example, you can integrate a plugin to a Security Incident Response task. * On-Demand Orchestration During Security Incident Response analysis, a security analyst may want to perform a task that is driven by a security incident workflow. For example, run a process dump on a particular CI. This can be accomplished with on-demand orchestration. * Operating Systems Groups NA. * SecOps Application Registry NA. {#sec-ops-common-functionality__ul_g13_5dk_nsb} |
| CMDB | CI Identifier Rules: CI identifiers are rules used to lookup a configuration item (CI) in the CMDB that contains matching information from a third-party integration. These rules define the fields that contain matching data and the order of precedence by which they are evaluated. The lowest Order value is evaluated first. |
[ ]

{#sec-ops-common-functionality__table_td5_g1s_3z}
* **[Create and define filter groups in Security Operations](https://servicenow-prod.fluidtopics.net/r5uDdmM_UX_B_rwi8GTPsA)**   
  Create and use filter groups to locate records from any table on your instance. For example, you can create a group of all computers by the same manufacturer. You can also filter configuration items (CIs) that have similar vulnerabilities or that fall within a particular subnet IP address range.
* **[Shared data transformation](https://servicenow-prod.fluidtopics.net/2wtrNh_Zly~iao80hSkGKg)**   
  The Security Incident Response, Vulnerability Response, and Threat Intelligence plugins share common features, for relationship data and duplication rules, used to import external and internal information into Security Operations.
* **[Security Operations email processing](https://servicenow-prod.fluidtopics.net/0MR_cKqhArGhCnE5mGTnRg)**   
  You can set up the integration of information from external detection systems, provide granularity in processing security operations records, handle unmatched emails, and prevent duplication of records using Email Processing.
* **[Security Operations field mapping](https://servicenow-prod.fluidtopics.net/qfRRG5cyfQD69AQhEBAdfg)**   
  Security Operations tables can be mapped to and from other tables, linking a security incident to a customer service case or a problem to other parts of the Security Operations system.
* **[Security Operations field value transforms](https://servicenow-prod.fluidtopics.net/zEpq302K0bw6UHv3IKC0OA)**   
  Transforms unique customer field values into field values recognized by Security Operations email parsing, data enrichment or tables using field maps. Supports choice fields, references, and aligns external data into the standard terminology and format for your new record.
* **[Security Operations enrichment data mapping](https://servicenow-prod.fluidtopics.net/tQ0eKbOQeuPSLf~YhSyydw)**   
  Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents.
* **[Security Operations user-defined escalation](https://servicenow-prod.fluidtopics.net/N~Kc_n5pPsXEX_8OeFGdGg)**   
  You can create an escalation path for security incidents for issues requiring more attention or expertise. Once an escalation group exists, a button appears on any security incident in that group.
* **[Create domain-separated property overrides](https://servicenow-prod.fluidtopics.net/p067Z557yRrJ6KouMMzHKQ)**   
  When you use domain separation, you can create overrides to existing Security Operations properties that allow you to customize the functions of the applications in each of your domains.
* **[Create an operating system group](https://servicenow-prod.fluidtopics.net/xmA3mWT4EAiuu5gI_wvDUg)**   
  Operating system groups are used to map an operating system to specific process types and scripts in Security Incident Response workflows. The scripts define how running processes for the defined operating system groups are retrieved. New operating systems can be added as needed.
* **[Set up security tag groups and tags](https://servicenow-prod.fluidtopics.net/bus9vK7pliypx82WYkj9OQ)**   
  You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.
* **[Security annotations](https://servicenow-prod.fluidtopics.net/~x4wZh7A4MDcNKxMO3aa8w)**   
  A security annotation is a note of explanation or comments added to a configuration item, observable, or use on a security incident.
* **[Components installed with Security Support Common](https://servicenow-prod.fluidtopics.net/XBgS_uQa3aw~uAihjpcQLw)**   
  Several types of components are installed with Security Support Common. They provide common functionality for use across the various security applications, such as Security Incident Response.
* **[Search Security Operations](https://servicenow-prod.fluidtopics.net/aMC3~JVtKE_xgcOOkR95gQ)**   
  You can find information quickly in any Security Operations application using the search icon in the screen header. Zing is the text indexing and search engine that performs all text searches in your instance.
* **[Security Operations Integration Reference](https://servicenow-prod.fluidtopics.net/pLM1~qwCDCY6CHnJkE4~wg)**   
  Developers and ServiceNow partners can use the information in this section to gain understanding of the under-the-hood functionality of third-party integrations, including development guidelines, integration capabilities, and workflows.
* **[Legacy: Security Operations workflow triggers](https://servicenow-prod.fluidtopics.net/dPvKY~tiNpo9I_MNnZqG~A)**   
  Security Operations workflow triggers contain a condition on a table. All workflows attached to the workflow trigger record run when the condition is met.
* **[Security Operations Orchestration](https://servicenow-prod.fluidtopics.net/gW6D3FvyJthtOz5imG07OQ)**   
  Users can interact with and retrieve data from Windows or UNIX-based systems and environments using activity packs and workflows in Security Operations Orchestration.

