---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add a security incident to a security case

# Add a security incident to a security case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If you determine that a security incident requires a higher level of analysis, add it
to a new or existing case.

## Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_si.admin, sn_ti.case_user_write

## Procedure

1. Navigate to the security incident that requires escalation by clicking Security IncidentIncidentsAssigned to Me, and open the security incident.
2. Select the more actions icon (![]() and select Add to Security Case.  
   The Add Security Incident(s) to Security Case dialog box opens.
3. If you have a case assigned to you that you want to add this security incident to, fill in the fields as appropriate, then select Submit.  
   {#add-sec-inc-to-case__table_y52_34c_yy__entry__2}

   | Field | Description |
   |-|-|
   | Security Case | Select the security case. |
   | Optional notes | As needed, enter additional notes that would be of value to the case analyst. |
   [ ]

   {#add-sec-inc-to-case__table_y52_34c_yy}
4. If you have one or more cases assigned to you, but want to create a case and assign the security incident to it, select Create New Case to show additional fields.
5. Fill in the fields as appropriate.  
   {#add-sec-inc-to-case__table_t4d_4bd_5s__entry__2}

   | Field | Description |
   |-|-|
   | Security Case Name | Enter the name of the new security case. |
   | Description | Enter a description for the case. |
   | Case Type | Select the type of case being investigated. |
   | Optional notes | As needed, enter additional notes that would be of value to the case analyst. |
   [ ]

   {#add-sec-inc-to-case__table_t4d_4bd_5s}
6. Select Create.  
   A message appears at the top of the security incident, along with a link to the new case.
**Related concepts**   

* [Security Case Management](https://servicenow-prod.fluidtopics.net/Y2pnftV6QRdUlHoNUrOfNA "Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.")

*[\>]: and then


