---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Handle security incidents using AWA

# Handle security incidents using Advanced Work Assignment {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.

## Before you begin

Role required: sn_si.analyst and awa_agent

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Select the Inbox button.
3. Indicate your availability status by selecting your presence state in the Status field.  
   The available presence states are:
   * Available: You're available and can accept security incidents. Whether you'll be assigned incoming incidents is based on the configured service channel, queues and assignment rules.  
     Note:  
     If auto-assignment has been enabled, security incidents are directly assigned to you.
   * Away: You aren't available to accept assignments of incoming incidents.
   * Offline (the default): You're offline and aren't available to accept assignments of incoming incidents.
   {#handle-incidents-using-awa__ul_zh3_kh2_lhc}
4. Accept or reject a security incident assignment.  
   Note:  
   If rejection handling hasn't been enabled in AWA, the Reject option isn't available.
   * Accept the incident by selecting Accept.

     The incident is assigned to you.
   * Reject the incident by selecting Reject and select a reason for the rejection.
   {#handle-incidents-using-awa__choices_l2b_syv_mhc}
{#handle-incidents-using-awa__steps_lzh_xyy_khc}
**Related concepts**   

* [Working with Security Incident Records](https://servicenow-prod.fluidtopics.net/TFUzgIYau3h8zmc3_FkDEA "The Security Incident Record consists of the following.")
* [Security Incident Playbook](https://servicenow-prod.fluidtopics.net/Or37s267AkF~R9MUgzRYiQ#security-incident-playbook "Invoke the security incident playbook flow automatically or manually.")
* [Prerequisites for the Playbooks](https://servicenow-prod.fluidtopics.net/POSOIYPbrf55BhB5oZj_Tw "You need the following roles and plugins to build the Playbooks.")
* [Rebuilding existing playbooks in Workflow Studio](https://servicenow-prod.fluidtopics.net/Gxrs6Kmn6bmfB680yQYz3A "You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.")
* [Activity Definitions](https://servicenow-prod.fluidtopics.net/IMGNwpKoJREVXgsdWM6BEg "The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.")
* [Sample Playbooks for SIR Workspace](https://servicenow-prod.fluidtopics.net/LJZS56n6O87_ZQicnhxpTw "You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.")
* [Working with MSI Records](https://servicenow-prod.fluidtopics.net/EzBRz3gfWLnRuxl~O9DXuA "Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.")
* [Working with Form UI actions](https://servicenow-prod.fluidtopics.net/BiVNOVqIU5VY5t0VA35xHg "Following are the UI actions that are displayed on the security incident form.")  
**Related tasks**   

* [Security Incident Closure workflow](https://servicenow-prod.fluidtopics.net/eUcWbP2pHl3bZk_3cBQ5EA "Close the security incident by updating the incident state.")

*[\>]: and then


