---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response setup

# Security Incident Response setup {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Setup for Security Incident Response involves some mandatory steps and several
optional steps, depending on your specific requirements. After you have downloaded Security Incident Response from the ServiceNow Store and installed it, you are ready
to run the Setup Assistant to perform basic configuration for Security Incident Response
and third-party integrations.

## The Security Incident Response setup process {#setup-sir__section_j2h_rgf_p3b}

The following diagram illustrates the setup process. It is separated into two sub-processes, downloading and configuring the Security Incident Response application.

The first setup step is to [download the Security Incident Response application from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/CgQgbA4wdpGBHx~mjN1ZOA "Before you run Security Incident Response in your instance, you must download it from the ServiceNow Store and complete configuration steps."). When the download is complete, several dependent applications, including the Setup Assistant, are loaded and ready for use to configure Security Incident Response.

## Setup Assistant {#setup-sir__section_h25_4gf_p3b}

The Security Incident Response Setup Assistant is a wizard-like application that guides you, step-by-step, through the setup of your base Security Incident Response instance.

The Setup Assistant requires the sn_secops_setup.admin role. Users with the sn_si.admin role automatically inherit this role.

The setup steps are fairly self-explanatory; however, if you require additional explanation, you can find additional assistance in the [Setup Assistant reference](https://servicenow-prod.fluidtopics.net/EjEx2i4_BJB~IAh6cy32sQ#setup-assistant-reference "The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation."). After you have completed the setup using the Setup Assistant, you can perform [other optional setup procedures](https://servicenow-prod.fluidtopics.net/WIHieeqPOG0rFktGpenkPw#t_ConfigureSIM "If you are an administrator in the global domain, you configure how Security Incident Response handles day-to-day operations."), as needed. These procedures include options for:

* Setting up the request life cycle
* Creating catalogs and requests
* Configuring notifications
* Setting up manual and auto-assignment
* Enabling the knowledge base, managed documents, and task activities
{#setup-sir__ul_ayn_sdf_p3b}

A new and improved Security Incident Response Workspace is available. For more information, see [Security Incident Response Workspace](https://servicenow-prod.fluidtopics.net/EmZFs2~PIit1DPFbKL384A "The ServiceNow Security Incident Response Workspace is a reimagined interface that provides a next-gen user experience for the security analysts and SOC managers. The security analysts can use this to manage the life cycle of security incidents from an initial analysis to containment, eradication, and recovery.").

