---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Managing security incidents and inbound requests

# Managing security incidents and inbound requests {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After a security incident has been created, there are numerous types of information that
can be added and viewed as your analysis of the issue progresses toward resolution.  
Important:  
The latest features in Security Incident Response are exclusively available in the Security Incident Response Workspace. Install or upgrade to the latest Security Incident Response \[com.snc.security_incident\] or Security Incident Response Workspace \[com.snc.security_incident.workspace\] version from the ServiceNow Store to access features such as Shift-Handover, Risk Score Calculator, etc.  
This section describes the following:

* [Create an inbound request](https://servicenow-prod.fluidtopics.net/whCjmC2RyNgA7qFwIy9R_Q "Unlike security incidents, inbound requests are generally of a lower priority. Requests for a lookup, scan, or a new badge are examples of inbound requests.")
* [Manage observables](https://servicenow-prod.fluidtopics.net/3Q1b9S7o60NJHSvquz2k0A "Observables are artifacts found on a network or operating system that are likely to indicate an intrusion. Typical observables are IP addresses, MD5 hashes of malware files or URLs, or domain names. Threat Intelligence observable table data is available from within a security incident.")
* [Manage lookups and scans](https://servicenow-prod.fluidtopics.net/aEJKMRJ_hWCiFGAg50SCUA "You can perform lookups and vulnerability scans from security incidents and from the security incident catalog to identify potential threats and vulnerabilities.")
* [Calculate the severity of a security incident](https://servicenow-prod.fluidtopics.net/hbhRJ6~sEdDRUuYA3rH6ag "You can calculate the severity of a security incident using predefined calculators.")
* [Manage post incident activities](https://servicenow-prod.fluidtopics.net/TPH1MQIwd1a_MXVvpiIOdA "Based on the requirements of your business, a review of the origins and handling of security incidents is often needed.")
* [Close security incidents](https://servicenow-prod.fluidtopics.net/6pw5rxRzHHnTI5qQnv1x7w "When a security incident has transitioned to the Review state, it’s possible to close it and enter an appropriate closure code. Closure codes can be searched on later for ease of location.")
{#manage-si-details__ul_ad2_vsf_1xb}

