---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Closure workflow

# Security Incident Closure workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Close the security incident by updating the incident state.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. For example, go to ListsSecurity IncidentsOpen incidents.
3. Open an incident that you want to close.
4. Go to the Details tab.
5. Drill down to the incident state and select Close.
6. Perform the closing activities.  
   * This is a mandatory step to review any task before closing a security incident. Any response tasks must be reviewed by the analyst and closed or canceled before closing as security incident. When the Analyst selects on Review active tasks, it takes the user to the Response Tasks tab. A session message is displayed prompting that you're in the process of closing a security incident. Select
     continue.

   * Select Continue. The first step -- review active tasks in closing the security incident is complete.Figure 1. Reviewing closure tasks
   * Move to the next step to review the active playbooks for the analyst to review, which is an optional step. You can select the link to review the active playbook task and close them as required.  
     Note:  
     Any active workflow(s), playbook activities, and flows will be automatically cancelled on closure of the security incident.
     Figure 2. Review playbook tasks
   * Post-incident review report: You will now be moved to review the post-incident activities to proceed further with the closure. If the assessment is optional then skip the step or if the assessment is mandatory then take the assessment and complete it.Figure 3. Review/Take assessment
   * Configure/preview report: This is again an optional step, select the link to review report and proceed to Next step.
   * Provide Resolution details: The analyst can select the check box to create knowledge articles automatically.
   * Provide the Closure code, Closure notes and select Close incident.

   {#security-incident-closure-workflow_0__ul_ucd_llx_x5b}  
   Note:  
   By any chance if the analyst cancels the Close the security incident dialogue box, then the analyst can navigate to the Details tab and change the incident state to close to continue with the closure.
**Related concepts**   

* [Working with Security Incident Records](https://servicenow-prod.fluidtopics.net/TFUzgIYau3h8zmc3_FkDEA "The Security Incident Record consists of the following.")
* [Security Incident Playbook](https://servicenow-prod.fluidtopics.net/Or37s267AkF~R9MUgzRYiQ#security-incident-playbook "Invoke the security incident playbook flow automatically or manually.")
* [Prerequisites for the Playbooks](https://servicenow-prod.fluidtopics.net/POSOIYPbrf55BhB5oZj_Tw "You need the following roles and plugins to build the Playbooks.")
* [Rebuilding existing playbooks in Workflow Studio](https://servicenow-prod.fluidtopics.net/Gxrs6Kmn6bmfB680yQYz3A "You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.")
* [Activity Definitions](https://servicenow-prod.fluidtopics.net/IMGNwpKoJREVXgsdWM6BEg "The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.")
* [Sample Playbooks for SIR Workspace](https://servicenow-prod.fluidtopics.net/LJZS56n6O87_ZQicnhxpTw "You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.")
* [Working with MSI Records](https://servicenow-prod.fluidtopics.net/EzBRz3gfWLnRuxl~O9DXuA "Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.")
* [Working with Form UI actions](https://servicenow-prod.fluidtopics.net/BiVNOVqIU5VY5t0VA35xHg "Following are the UI actions that are displayed on the security incident form.")  
**Related tasks**   

* [Handle security incidents using Advanced Work Assignment](https://servicenow-prod.fluidtopics.net/T3UyVFGugN7M9V4Ol1CCLg "Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.")

*[\>]: and then


