---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Assign Security Incidents

# Assign Security Incidents {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Assign security incidents.

## Before you begin

Role required: sn_si.basic

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Click the list (![list icon]()) icon.
3. Click Lists.
4. For example, go to Security IncidentsAll Open.
5. Select one or more security incidents.
6. Click Assign.
7. Fill the details such as Assignment group, Assigned to, and add Work notes if required.  
   The incident will then be assigned to the user.
8. Click Save.  
   Figure 1. Assign one or more Security Incidents
**Related tasks**   

* [Personalize a list](https://servicenow-prod.fluidtopics.net/_RxhTpnln1PmOuwEqp9R1g "Security analysts or managers can personalize the security incidents or response tasks or phishing emails custom list view based on their individual preferences.")
* [Apply quick filters on Security Incidents and Response Tasks lists](https://servicenow-prod.fluidtopics.net/35Z73~2baAzbxtNGCt72ew "Apply the predefined quick filters on Security Incidents and Response Tasks lists to get the desired work items.")
* [Close multiple security incidents](https://servicenow-prod.fluidtopics.net/Dvg2PBwYt_q~KLReXA~5sg "Close multiple security incidents at the same time to avoid having to close related incidents individually, such as incidents created with a common root cause or false positive incidents.")
* [Assign Response Tasks](https://servicenow-prod.fluidtopics.net/W_pvOPoYfE6SM60RAY0HNg "Assign Response tasks for a security issue.")
* [Report Phish Email](https://servicenow-prod.fluidtopics.net/Xa19dE_pFpmbf9OFlZFXxg "Report phishing emails from the lists view.")
* [Working with quick filters](https://servicenow-prod.fluidtopics.net/Dm_XloOH7st7z7LSR6BbAA "Quick filters are easily accessible filters that are available on, security incidents and response tasks lists.")
* [Export Security Incidents or Response Tasks](https://servicenow-prod.fluidtopics.net/JHtI68igM~InPCAaJ594~w "Export the security incidents or response tasks from the list view.")
* [Manage Shift Handover records](https://servicenow-prod.fluidtopics.net/cnHScVK7WGH36Kp9gnPgZw "Use the Shift Handover records list view to create, edit, copy, or delete Shift Handover records. Each Shift Handover record is associated with a Shift Handover Report Template.")

*[\>]: and then


