---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add security incident to TISC case

# Add security incident to TISC case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Add security incidents to TISC case records.

## Before you begin

Role required: sn_si.analyst, sn_sec_tisc.case_write

## Procedure

1. Navigate to WorkspacesSecurity Incident Response WorkspaceSecurity IncidentsAll.
2. Locate and open any specific security incident that you're investigating.  
   This can also be done by searching for the incident ID or browsing from Quick Filters section or filtering through incident state.
3. Click on More actions icon.
4. Click Add to TISC Case action.  
   Add to TISC Case dialog box displays and this only shows those TISC cases where the incident is not already associated.
5. Select the case(s) from the Add to Case dialog box.  
   Note:  
   Create a new TISC case if there no case records. For more information on how to create case(s), see [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.").
6. Click Add.
7. Click the Case record to view the case in TISC from the information message displayed or from the Activity stream.  
   Note:  
   To view the linked security incidents, click on the particular case record from the security incident Activity stream. By clicking on this will take you to the case record in TISC workspace and the security incidents will get added under Artifacts tab of the Case Management module.
**Related tasks**   

* [Add observables to TISC Case](https://servicenow-prod.fluidtopics.net/6hTKrR7dtiA2DUf~bV0JXQ "Add observables to TISC case records.")
* [Send Observables to TISC](https://servicenow-prod.fluidtopics.net/VJNWnxlhS9MGhvva17pqgw "Using this feature the security analyst can push the observables data from SIR to TISC. Using the TISC Context, you can check if the observables are present in TISC, if not security analyst can push the data whenever required.")
* [Send Threat Lookup to TISC](https://servicenow-prod.fluidtopics.net/QQdzzepm419PH_VxjzMw9w "Using this feature the security analyst can push the threat lookup data from SIR to TISC. Using the TISC Context, you can check if the threat lookup results are present in TISC, if not security analyst can push the data whenever required.")
* [Send Sighting Search to TISC](https://servicenow-prod.fluidtopics.net/lrH4qlEmdq1zowWEOb~Cbw "Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.")
* [Send Observable Enrichment to TISC](https://servicenow-prod.fluidtopics.net/d_zRa7QF_uxPqTH8ByInUg "Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.")  
**Related reference**   

* [System properties to send data](https://servicenow-prod.fluidtopics.net/xQZzhDOp9JP7rBFciK40Ow "Review the system properties for TISC integrations to combine with SIRW. You can configure these properties to control how both applications manages the integrations.")

*[\>]: and then


