---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Denial of Service workflow template

# Security Incident Denial of Service workflow template {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

The Security Incident - Denial of Service - Template allows you to perform a series
of tasks designed to handle Denial of Service (DOS) attacks.

## Before you begin

Role required: sn_si.write

## About this task

The workflow is triggered when the Category in a security
incident is set to Denial of Service. This action causes a
response task to be created for the first activity in the workflow.
Figure 1. Denial of Service (DOS)

## Procedure

1. Open the security incident for this denial of service occurrence, or [create a new security incident](https://servicenow-prod.fluidtopics.net/hRLl9dw7~RuP3HDYtHJlEg "In addition to automatic methods for creating security incidents, you can create them manually, as needed.").
2. In Category, select Denial of Service.
3. Save the record.
4. Scroll down and open the Response Tasks related list.  
   The first of a series of response tasks appears. Each time the record is saved, your response to the previous task either causes the next response task to be created or the flow to end.{#si-denial-of-service-template__table_ihp_5ds_kbb__entry__3}

   | Response task | Action | Results |
   |-|-|-|
   | Is target business critical? | Determine if the target of this DOS attack is business critical. In the task, select Yes or No in Outcome. | If you select Yes, the Set priority to critical task is executed. If you select No, the Is a vulnerability being exploited? task is executed. |
   | Set priority to critical | No action required. | The Priority of the security incident is changed automatically to Critical, and the Is a vulnerability being exploited? task is executed. |
   | Is a vulnerability being exploited? | Determine whether this DOS attack exploits a software vulnerability. In the task, select Yes or No in Outcome. | If you select Yes, the Emergency patch request task is executed. If you select No, the Internal attacker? task is executed. |
   | Emergency patch request | Issue an emergency patch request for the system(s) being attacked. Update the State field in the task as appropriate. | If you changed the state of the task to Closed Complete or Cancelled, the next response task is executed. |
   | Internal attacker? | Determine if the source of this DOS attack is internal to your organization. In the task, select Yes or No in Outcome. | If you select Yes, the Isolate attacking host(s) task is executed. If you select No, the Notify DOS protection provider and/or ISP task is executed. |
   | Isolate the attacking host(s) | Perform the steps necessary to isolate the internal host(s) responsible for the attack. Update the State field in the task as appropriate. | After you complete this step, the Validate system integrity of attacked systems task is executed. |
   | Notify DOS protection provider and/or ISP | Perform the steps necessary to contact your Denial of Service protection provider and/or your Internet Service Provider to notify them of the attack. Update the State field in the task as appropriate. | If you changed the state of the task to Closed Complete or Cancelled, the next response task is executed. |
   | Validate system integrity of attacked systems | Perform the steps necessary to assess and validate the integrity of the attacked computers. Update the State field in the task as appropriate. | If you changed the state of the task to Closed Complete or Cancelled, the next response task is executed. |
   | Review DOS protections | Conduct a review of your existing DOS protections and procedures. Make any necessary changes. Update the State field in the task as appropriate. | If you changed the state of the task to Closed Complete or Cancelled, the next response task is executed. |
   | Set state to review | No action required. | The State of the security incident is changed automatically to Review. The Lessons learned meeting task is executed. |
   | Lessons learned meeting | Conduct a lessons learned meeting to triage the work performed for this Denial of Service incident. Update the State field in the task as appropriate. | If you change the state of the task to Closed Complete or Cancelled, the flow ends. |
   [Table 1. Response tasks in Denial of Service Template]

   {#si-denial-of-service-template__table_ihp_5ds_kbb}
**Related tasks**   

* [Security Incident Confidential Data Exposure workflow template](https://servicenow-prod.fluidtopics.net/nFKIzAO87NmEaSmbOlfnBg "The Security Incident - Confidential Data Exposure - Template allows you to perform a series of tasks designed to handle the exposure of sensitive data.")
* [Security Incident Lost Equipment workflow template](https://servicenow-prod.fluidtopics.net/jTlE4VrajMjH9hJI99LUtg "The Security Incident - Lost Equipment - Template allows you to perform a series of tasks designed to handle lost equipment.")
* [Security Incident Malicious Software workflow template](https://servicenow-prod.fluidtopics.net/_VPjlhZMzho3MBg~FSE80g "The Security Incident - Malicious Software - Template allows you to perform a series of tasks designed to handle malicious software on your network.")
* [Security Incident Phishing workflow template](https://servicenow-prod.fluidtopics.net/e_fMyDIGgjuYycuEtZKEoQ "The Security Incident - Phishing - Template allows you to perform a series of tasks designed to handle spear phishing emails on your network.")
* [Security Incident Policy Violation workflow template](https://servicenow-prod.fluidtopics.net/jj5HhCQ9g6WokjWDIbe7KA "The Security Incident - Policy Violation - Template allows you to perform a series of tasks designed to handle security policy violations.")
* [Security Incident Reconnaissance workflow template](https://servicenow-prod.fluidtopics.net/p70N3CfQJ5HFRTywU7oo5w "Reconnaissance is usually a preliminary step toward a further attack seeking to exploit a device or system. The Security Incident - Reconnaissance - Template allows you to perform a series of tasks designed to handle reconnaissance on your network.")
* [Security Incident Rogue Server or Service workflow template](https://servicenow-prod.fluidtopics.net/hM7_g1Qwyg8kNe8Np56Yqw "The Security Incident - Rogue Server or Service - Template allows you to perform a series of tasks designed to handle activity from rogue servers or services affecting your network.")
* [Security Incident Spam workflow template](https://servicenow-prod.fluidtopics.net/DxsjNHaxoerxIv4_~sTNyg "The Security Incident - Spam - Template allows you to perform a series of tasks designed to handle email spam on your network.")
* [Security Incident Unauthorized Access workflow template](https://servicenow-prod.fluidtopics.net/NFoUZQBaMzTmVEgwQDQ14w "The Security Incident - Unauthorized Access - Template allows you to perform a series of tasks designed to handle unauthorized access to your network.")
* [Security Incident Web/BBS Defacement workflow template](https://servicenow-prod.fluidtopics.net/UoGVdQA3r7wkoF40RpZgBw "The Security Incident - Web/BBS Defacement - Template allows you to perform a series of tasks designed to handle vandalism directed against one of your organization's BBS or web sites.")

