---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure Security Incident Response

# Install and configure Security Incident Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Before you run Security Incident Response in your
instance, you must download it from the ServiceNow Store and complete configuration
steps.

## Before you begin

Role required: sn_secops_setup.admin  
Important:  
* Installing the Security Incident Response 13.4.5 version or later from the ServiceNow Store will automatically install the Security Incident Response Workspace (sn_si_aw) 1.5.1 version or later by default. For more information on the dependent applications, refer to the [SIR Workspace plugins](https://servicenow-prod.fluidtopics.net/DT9niT7CHKbBFZbGrlMamw "The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.") section.
* Please note that the Security Incident Response Workspace versions 1.5.1 and above can only be installed/upgraded through an installation/upgradation of Security Incident Response and cannot be installed independently.
* The latest features in Security Incident Response are exclusively available in the Security Incident Response Workspace. Please install or upgrade to the latest Security Incident Response or Security Incident Response Workspace version to access and leverage features such as Shift-Handover, Risk Score Calculator, etc.
{#install-and-configure-sir__ul_ipb_3mz_dcc}  
Note:  
The Setup Assistant requires the sn_secops_setup.admin role. Users with the sn_si.admin role automatically inherit this role. The Setup Status (sn_secops_setup_status) table fields are enforced as strict read-only to prevent unauthorized modifications.

## Procedure

1. Follow the instructions for [downloading an application
   from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. After you have downloaded the Security Incident Response application and all of its dependency applications, navigate to Security IncidentAnalyst Workspace SetupSetup Assistant.  
3. Follow the instructions on the forms to configure the Security Incident Response base system.  
   For additional information on some of the more complicated setup tasks, see [Setup Assistant reference](https://servicenow-prod.fluidtopics.net/EjEx2i4_BJB~IAh6cy32sQ#setup-assistant-reference "The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation."), as needed.
{#install-and-configure-sir__steps_yh2_3yh_jfb}

*[\>]: and then


