---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Secureworks CTP Master Ticket Closure Notice

# Secureworks CTP Master Ticket Closure Notice {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Before you close a security incident created by a Secureworks CTP master ticket, you must verify that all child tickets associated with the master ticket
are
closed.

## Before you begin

Role required: sn_si.admin

## Procedure

1. Navigate to AllSecureworks Ticket IngestionSecureworks Ticket to Task.  
   The Secureworks CTP tickets with their corresponding security incidents are displayed.
2. Select on the security incident with the isGlobalParent field set to true.
3. Change the security incident State to Closed, specify the close codes and select Save.
4. Add a note requesting closure of the Master Ticket in Secureworks and select Submit Request.  
   The Master Ticket is now reassigned to the Secureworks SOC team.
5. Once the request has been submitted, you can close the security incident.
6. Navigate to ApplicationModule.
{#secureworks-ctp-master-ticket-closure__steps_rms_4wj_ymb}

*[\>]: and then


