---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Close multiple security incidents

# Close multiple security incidents {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Close multiple security incidents at the same time to avoid having to close related incidents individually, such as incidents created with a common root cause or false positive incidents.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Select the Security Incidents icon ![]().
3. In the Lists tab, select Security IncidentsAll Open.
4. Select one or more security incidents to close and select Close.  
   The Bulk Close the security incidents window displays links to access lists of the security incidents selected to be closed.
   * If at least one selected security incident has pending activities such as active tasks, playbooks, child SIs, assessments, or active flows, the Security incidents with active tasks, playbooks, child SIs, assessments and active flows link is displayed.
   * If at least one security incident selected for closing has no pending closing activities, the Security incidents ready to be closed link is displayed.

   {#close-multiple-incidents-sir__ul_fcr_z44_vfc}

   Any active pending active tasks, playbooks, child SIs, assessments, and active flows will automatically be closed when you proceed with the bulk closure.
5. **Optional:** If you're not sure whether active items for incidents should be closed, review the security incidents with active items.
   1. Select the Security incidents with active tasks, playbooks, child SIs, assessments and active flows link.
   2. Open the security incident you want to review.
   3. If any changes are necessary, make them and select Save.
   4. Close the incident tab.
   5. Select Take me back.
   {#close-multiple-incidents-sir__substeps_h3p_mbs_zgc}
6. Select next.
7. In the Close Code field, select the applicable close code.  
   The available close codes are:
   * Investigation completed
   * Threat mitigated
   * Patched vulnerability
   * Invalid vulnerability
   * Not resolved
   * False positive
   {#close-multiple-incidents-sir__ul_gvk_215_xgc}
8. In the Close notes field, enter any notes.
9. Select Bulk Close.

## Result

The incident closing activity runs in the background.
**Related tasks**   

* [Personalize a list](https://servicenow-prod.fluidtopics.net/_RxhTpnln1PmOuwEqp9R1g "Security analysts or managers can personalize the security incidents or response tasks or phishing emails custom list view based on their individual preferences.")
* [Apply quick filters on Security Incidents and Response Tasks lists](https://servicenow-prod.fluidtopics.net/35Z73~2baAzbxtNGCt72ew "Apply the predefined quick filters on Security Incidents and Response Tasks lists to get the desired work items.")
* [Assign Security Incidents](https://servicenow-prod.fluidtopics.net/aP2FfEOHr0CacFo6ua40IQ "Assign security incidents.")
* [Assign Response Tasks](https://servicenow-prod.fluidtopics.net/W_pvOPoYfE6SM60RAY0HNg "Assign Response tasks for a security issue.")
* [Report Phish Email](https://servicenow-prod.fluidtopics.net/Xa19dE_pFpmbf9OFlZFXxg "Report phishing emails from the lists view.")
* [Working with quick filters](https://servicenow-prod.fluidtopics.net/Dm_XloOH7st7z7LSR6BbAA "Quick filters are easily accessible filters that are available on, security incidents and response tasks lists.")
* [Export Security Incidents or Response Tasks](https://servicenow-prod.fluidtopics.net/JHtI68igM~InPCAaJ594~w "Export the security incidents or response tasks from the list view.")
* [Manage Shift Handover records](https://servicenow-prod.fluidtopics.net/cnHScVK7WGH36Kp9gnPgZw "Use the Shift Handover records list view to create, edit, copy, or delete Shift Handover records. Each Shift Handover record is associated with a Shift Handover Report Template.")

*[\>]: and then


