---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add closure information to a security incident

# Add closure information to a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

When a security incident is in the Review or Closed state, you can enter closure
information.

## Before you begin

Role required: sn_si.basic

## Procedure

1. If it isn't already open, open the security incident you want to update.
2. Select the Related Records tab.
3. Fill in the fields, as needed.  
   {#add-closure-info-to-si__table_l2p_dcs_ns__entry__2}

   | Field | Description |
   |-|-|
   | Create knowledge article | The option to generate a knowledge article using the contents of the post incident report. |
   | Close code | The close code that best describes the reason for closing the security incident. |
   | Closed by | \[Read only\] Displays the user who closed the security incident. |
   | Closed | \[Read only\] Displays the date and time the security incident was closed. |
   | Close notes | How the security incident has been closed, including lessons learned, resolution, and so on. |
   [ ]

   {#add-closure-info-to-si__table_l2p_dcs_ns}
4. Select any of the following tabs to further update the security incident:  
   * [Incident Details](https://servicenow-prod.fluidtopics.net/1ruNBlbRJ~qCshm8kaDbhA "After a security incident is created, you can add more details to aid in analysis, such as access roles and different kinds of notes.")
   * [Post Incident Review](https://servicenow-prod.fluidtopics.net/TPH1MQIwd1a_MXVvpiIOdA "Based on the requirements of your business, a review of the origins and handling of security incidents is often needed.")
   {#add-closure-info-to-si__ul_rxz_h1q_vz}
5. Select Submit.
{#add-closure-info-to-si__steps_qmj_hxw_vz}

