---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Working with TISC Context

# Working with TISC Context {#ariaid-title1}

* Release version: Australia
* 
* Updated April 16, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.

Security analysts can detect, investigate, and respond to security incidents more effectively from the workspace.

TISC Context in Security Incident Response Workspace allows security analysts to add security incidents or observables to TISC cases directly from the workspace. You can also view enrichment results and observables related information such as threat actors, attack patterns, and campaigns.  
Using this section, you can do the following:

1. Associate observables to a TISC case.
2. View associated observables information.
3. View observables enrichment results.

{#working-with-tisc-context__ol_wzf_zss_dcc}For more detailed information and procedures, see the following sections. For more information on how the integration works between TISC and Security Incident Response Workspace, see [TISC integration with SIR Workspace](https://servicenow-prod.fluidtopics.net/8ejNJMWpYZ5wSnsLuZ9KQQ "TISC integration with SIR Workspace automatically provides context for observables in the security incident workspace for security analysts.") in [Threat Intelligence Security Center](https://servicenow-prod.fluidtopics.net/v_eC3uWaEeyQ8wunrolOMA "The Threat Intelligence Security Center (TISC) platform provides technology solution for aggregation, management and operationalization of threat intelligence.").
* **[Add observables to TISC Case](https://servicenow-prod.fluidtopics.net/GzOmnjok6h2GgA75Y1qOow)**   
  Use this section to add security incidents or observables to a TISC case.
* **[View related info from TISC](https://servicenow-prod.fluidtopics.net/ODfv5ASqBPNQTABccuf07w)**   
  Use this section to view the related info such as related threat actors, attack patterns, campaigns, and cases from TISC in Security Incident Response Workspace.
* **[View Enrichment Results](https://servicenow-prod.fluidtopics.net/LCKORi4I2Jl6H5S05Nvtrw)**   
  TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.

