---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Spam workflow template

# Security Incident Spam workflow template {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The Security Incident - Spam - Template allows you to perform a series of tasks
designed to handle email spam on your network.

## Before you begin

Role required: sn_si.write

## About this task

The workflow is triggered when the Category in a security
incident is set or changed to Spam source. This action causes
a response task to be created for the first activity in the workflow.
Figure 1. Spam source

## Procedure

1. Open the security incident for which you want to handle email spam, or [create a new security incident](https://servicenow-prod.fluidtopics.net/hRLl9dw7~RuP3HDYtHJlEg "In addition to automatic methods for creating security incidents, you can create them manually, as needed.").
2. In Category, select Spam source.
3. Save the record.
4. Scroll down and open the Response Tasks related list.  
   The first of a series of response tasks appears. Each time the record is saved, your response to the previous task either causes the next response task to be created or the workflow to end.{#si-spam-template__table_oxh_wvs_kbb__entry__3}

   | Response task | Action | Results |
   |-|-|-|
   | Spam contains malicious content? | Determine whether the spam contains malicious software. In the task, select Yes or No in Outcome. | If you selected Yes, the following response tasks are executed: * Quarantine email message * Create malicious software incident {#si-spam-template__ul_gcv_ctq_1y} If you selected No, the Update email software is executed. |
   | Create malicious software incident | Perform the steps to create a security incident, updating the State field in the task as appropriate. | If you change the state of the task to Closed Complete or Cancelled, this response task waits until the next three response tasks have been completed. The state of the security incident then transitions to Review. |
   | Quarantine email message | Perform the steps to quarantine the spam, updating the State field in the task as appropriate. | If you change the state of the task to Closed Complete or Cancelled, the next response task is executed. |
   | Block source on firewall | Perform the steps to block the email address on the firewall, updating the State field in the task as appropriate. | If you change the state of the task to Closed Complete or Cancelled, the next response task is executed. |
   | Update email software | Add the email address to your block list, updating the State field in the task as appropriate. | If you change the state of the task to Closed Complete or Cancelled, the next response task is executed. Note: This response task is also executed if you answered No to the Spam contains malicious content? response task. |
   | Set state to review | No action required. | The State of the security incident is automatically changed to Review. |
   [Table 1. Response tasks in Spam Template]

   {#si-spam-template__table_oxh_wvs_kbb}
{#si-spam-template__steps_m44_snq_1y}
**Related tasks**   

* [Security Incident Confidential Data Exposure workflow template](https://servicenow-prod.fluidtopics.net/nFKIzAO87NmEaSmbOlfnBg "The Security Incident - Confidential Data Exposure - Template allows you to perform a series of tasks designed to handle the exposure of sensitive data.")
* [Security Incident Denial of Service workflow template](https://servicenow-prod.fluidtopics.net/sSSFVstKld_nT4PbN6Uzjg "The Security Incident - Denial of Service - Template allows you to perform a series of tasks designed to handle Denial of Service (DOS) attacks.")
* [Security Incident Lost Equipment workflow template](https://servicenow-prod.fluidtopics.net/jTlE4VrajMjH9hJI99LUtg "The Security Incident - Lost Equipment - Template allows you to perform a series of tasks designed to handle lost equipment.")
* [Security Incident Malicious Software workflow template](https://servicenow-prod.fluidtopics.net/_VPjlhZMzho3MBg~FSE80g "The Security Incident - Malicious Software - Template allows you to perform a series of tasks designed to handle malicious software on your network.")
* [Security Incident Phishing workflow template](https://servicenow-prod.fluidtopics.net/e_fMyDIGgjuYycuEtZKEoQ "The Security Incident - Phishing - Template allows you to perform a series of tasks designed to handle spear phishing emails on your network.")
* [Security Incident Policy Violation workflow template](https://servicenow-prod.fluidtopics.net/jj5HhCQ9g6WokjWDIbe7KA "The Security Incident - Policy Violation - Template allows you to perform a series of tasks designed to handle security policy violations.")
* [Security Incident Reconnaissance workflow template](https://servicenow-prod.fluidtopics.net/p70N3CfQJ5HFRTywU7oo5w "Reconnaissance is usually a preliminary step toward a further attack seeking to exploit a device or system. The Security Incident - Reconnaissance - Template allows you to perform a series of tasks designed to handle reconnaissance on your network.")
* [Security Incident Rogue Server or Service workflow template](https://servicenow-prod.fluidtopics.net/hM7_g1Qwyg8kNe8Np56Yqw "The Security Incident - Rogue Server or Service - Template allows you to perform a series of tasks designed to handle activity from rogue servers or services affecting your network.")
* [Security Incident Unauthorized Access workflow template](https://servicenow-prod.fluidtopics.net/NFoUZQBaMzTmVEgwQDQ14w "The Security Incident - Unauthorized Access - Template allows you to perform a series of tasks designed to handle unauthorized access to your network.")
* [Security Incident Web/BBS Defacement workflow template](https://servicenow-prod.fluidtopics.net/UoGVdQA3r7wkoF40RpZgBw "The Security Incident - Web/BBS Defacement - Template allows you to perform a series of tasks designed to handle vandalism directed against one of your organization's BBS or web sites.")

