---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create from Security Incident list

# Create a security incident from the Security Incident list {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

In addition to automatic methods for creating security incidents, you can create them
manually, as needed.
This video shows a visual overview of how you could create a security incident from the Security Incident list.

## Before you begin

Role required: sn_si.basic

## Procedure

1. Navigate to any security incident list (for example, AllSecurity IncidentIncidentsShow All Incidents).
2. Select New.
3. On the form, fill in the fields.  
   {#t_ManuallyCreateSecurityIncident__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | Select security tag | If needed, select a [Security tag](https://servicenow-prod.fluidtopics.net/bus9vK7pliypx82WYkj9OQ "You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.") to add metadata to the record or identify who should have access to this security incident record. This field appears only after the security incident has been saved. Note: Manual tags are preserved when automatic tags are applied. |
   | Number | \[Read only\] The security incident number. |
   | Requested by | The person requesting the work to be performed. |
   | Configuration Item | The server, computer, router, or other configuration item affected by the security issue. |
   | Affected user | The person affected by the security issue. |
   | Location | The location of the requester or resource. If a Configuration Item is not selected, this field is pre-filled with the location of the requester. |
   | Category | The category that identifies the type of security issue. If a category is selected, a workflow for analyzing this issue is executed when the record is saved. For example, if you select Denial of Service, the Security Incident - Denial of Service - Template workflow is executed. For more information, see [Security Incident Response workflow templates](https://servicenow-prod.fluidtopics.net/daWGLDG7to~ex1MImXeNTw "Workflow templates are provided with Security Incident Response Orchestration to allow you to perform basic security operation-related analysis procedures. The templates can be used as is or you can customize them to create workflows to better suit your specific needs. The workflow templates are deactivated by default."). |
   | Subcategory | The subcategory that further defines the issue. |
   | Opened | \[Read only\] Displays the date and time the incident was opened. |
   | State | The current state of the security incident. Upon security incident creation, this field defaults to Draft. |
   | Substate | Identifies whether the security incident includes a pending problem or change. |
   | Source | Identifies the source of the security incident, such as email, a phone call, or network monitoring. |
   | Alert Sensor | Security integration through which you ingest the alert or event data such as CarbonBlack, CrowdStrike, McAfee, and so on. |
   | Alert Rule | The rule in the security product which triggered the creation of this security incident. |
   | Risk score | Displays the risk score calculated for this security incident. The value is based on the priority of the security incident, the type of security incident (Denial of Service, Spear Phishing, or Malicious code activity), and the number of sources that triggered a failed reputation score on an indicator. The risk score aids in prioritizing security incident work for analysts. Three security incident properties enable you to further designate a color-coded dot to appear next to the risk score in list view to make them more easily identifiable. If you change certain fields in the security incident, such as the Business impact or Priority, and save the record, the Risk score is automatically recalculated and displayed. The change is also reflected in the work notes and on the Risk Score Audits related list. Note: The risk score is also recalculated when affected users are associated with a security incident, affected services, or vulnerable items. You can also manually enter a new Risk score. This can be useful if you want to keep a particular security incident at the top of the list of security incidents you are analyzing. If you enter a new Risk score, the Risk score override check box is automatically selected. Regardless of the changes made in the security incident, a manually-entered risk score is not automatically recalculated. Note: If you have upgraded your instance from a prior release, risk scores were calculated for all of your open security incidents. For more information, see [Understanding security incident calculators](https://servicenow-prod.fluidtopics.net/EjEx2i4_BJB~IAh6cy32sQ#c_SecIncCalculators "Security incident calculators are used to update record values when pre-defined conditions are met. The calculators are grouped based on the criteria used to determine how the records are updated."). |
   | Risk score override | Select this check box to override the automatic update of the risk score. The override is reflected in the work notes. |
   | Business impact | Select the importance of this security incident to your business. The default value is Non-critical. If, after the security incident record has been saved, you change the value in the Priority fand/or Risk fields, the Business impact is recalculated. |
   | Priority | Select the order in which to address this security incident, based on the urgency. If this value is changed after the record is saved, it can affect the Business impact calculation. |
   | Assignment group | The group to which this security incident is assigned. |
   | Assigned to | The individual assigned to analyze this security incident. Assignments can be performed manually or automatically. For more information, see [Assigning security analysts](https://servicenow-prod.fluidtopics.net/TwtDZB289oUSK~R1AFOwhQ#r_AgentAssignment "Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment."). |
   | Short description | A brief description of the security incident. |
   | Knowledge results | As you type the short description, links to related articles from the knowledge base appear. Scanning the information could solve your issue. |
   [ ]

   {#t_ManuallyCreateSecurityIncident__table_vks_thr_ns}
4. Select and hold (or right-click) in the record header and select Save.  
   If you added a new CI to the security incident, the following integration workflows are automatically executed:
   * [Security Operations - Get Running Processes Flow](https://servicenow-prod.fluidtopics.net/7PKofxKKNYMks5dGSVT6Xw "The Security Operations - Get Running Processes flow is a high-level flow independent of integrations. It retrieves a list of running processes on a configuration item (CI) from a host. Use it to fulfill an integration, such as Carbon Black, or for a Windows-based security incident."). This workflow retrieves a list of running processes on a configuration item (CI) from a host or endpoint.
   * [Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/G5KU_I510ZVVJJ4QZN_pQQ "The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations."). This workflow retrieves a list of running services from Windows-based CIs.
   * [Security Operations Integrations - Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/53Vtuib1JX5dIXwcI88zUw "The Security Operations Integrations - Get Network Statistics flow retrieves a list of active network connections from a host or endpoint."). This workflow retrieves a list of active network connections from a host or endpoint.
   {#t_ManuallyCreateSecurityIncident__ul_cht_wvw_t1b}
5. To view the information retrieved by these workflows, click the Show Enrichment Data related link, and then click any of the indicated tabs.  
   Note:  
   Additional workflows are executed based on the third-party integrations you have activated as follows [Security Operations Carbon Black Integration - Get Running Processes Flow](https://servicenow-prod.fluidtopics.net/L7ELcO~mGe0v3whXcy1jgg "The Security Operations Carbon Black Integration - Get Running Processes is the implementation for the Carbon Black integration launched by the Security Operations Integration - Get Running Process flow.")
**Related concepts**   

* [Security Incident Response setup](https://servicenow-prod.fluidtopics.net/9yCE9ERQGkiGdzL7CsYSEA "Setup for Security Incident Response involves some mandatory steps and several optional steps, depending on your specific requirements. After you have downloaded Security Incident Response from the ServiceNow Store and installed it, you are ready to run the Setup Assistant to perform basic configuration for Security Incident Response and third-party integrations.")

*[\>]: and then


