---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up Threat Intelligence Security Center

# Set up Threat Intelligence Security Center {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Before you use the Threat Intelligence Security Center, you must download it from the ServiceNow Store.

## Roles installed {#set-up-threat-intelligence-security-center__section_omy_tlq_fyb}

Review the following information and verify that you've completed all the tasks for a smooth integration. Following is the list of different user persona defined to access and work with the application:

* Threat Intelligence analyst (sn_sec_tisc.analyst)
* Threat Intelligence administrator (sn_sec_tisc.admin)

{#set-up-threat-intelligence-security-center__ul_m2f_3rq_gyb}{#set-up-threat-intelligence-security-center__table_lfk_hkv_21c__entry__2}

| Setup | Description |
|-|-|
| Assign and verify the required ServiceNow AI Platform and Threat Intelligence Security Center roles. | The following roles are required for configuration and verification of the expected results: * As an admin, you must install the TISC application from the ServiceNow Store and assign the role as sn_sec_tisc.admin. * This sn_sec_tisc.admin role performs the following tasks: * Configures the Data Sources to ingest the data. For more information, see [Threat Intelligence Feeds](https://servicenow-prod.fluidtopics.net/nwQ3_MVh~0x46aeysuvORQ "Configure threat intelligence data sources to automatically import security indicators into your ServiceNow instance. Use feeds to keep threat data current and enhance security monitoring capabilities."). * Configured the integrations required to enrich observables in TISC. For more information, see [TISC Enrichment integrations](https://servicenow-prod.fluidtopics.net/a7mlxeTPuxLymmAcZJ8OTA "The Threat Intelligence Security Center base system does not include any pre-configured integrations. This section provides instructions for configuring both ServiceNow and third-party integrations."). * Configures data import approvals to import the intelligence data using Import Intelligence. For more information, see [Working with Data Imports](https://servicenow-prod.fluidtopics.net/PprU7XL30oUCwvYm5zw2kQ "Data imports allows you to view the all the records that are being processed for import job and also lists the import jobs that are awaiting approvals."). * Configures Threat Score Calculator using required criteria for automatic calculation of Threat Score of observables. For more information, see [Define Threat Score Calculator](https://servicenow-prod.fluidtopics.net/Q4Eq9CFEGBYL1hx3syj1uA "Define threat score for the observable(s) records that are generated based on the user defined parameters. The base system is provisioned with one threat scoring rule, which can be customized and enabled accordingly."). * Configures required Taxonomies and Taxonomy Values. For more information, see [Creating Taxonomies](https://servicenow-prod.fluidtopics.net/C~XXOsCA3_f~taPumaY1vg "Create taxonomies for the data source records."). * Configure the MITRE-ATT\&CK repository relevant to your organization. For more information, see [MITRE-ATT\&CK Repository](https://servicenow-prod.fluidtopics.net/ku1Y8HlYCrL_WVXzCVI5aw "The MITRE-ATT&CK repository is available under the Intelligence Library where the data from the MITRE sources are ingested."). {#set-up-threat-intelligence-security-center__ul_rbn_mkv_21c} Note: As a sn_sec_tisc.admin, you can also assign the sn_sec_tisc.analyst role. * The sn_sec_tisc.analyst role performs the following tasks: * Views the overview of intelligence data in the TISC Home page. For more information, see [TISC Workspace](https://servicenow-prod.fluidtopics.net/38sNgiOL5dsztWeWjTXp2Q "View a centralized dashboard of threat intelligence data including feeds overview, trending threats, and intelligence sharing metrics. Monitor your security posture with trending intelligence data."). * Import data into TISC using Import Intelligence button in Threat Library page. For more information, see [Threat Intel Library](https://servicenow-prod.fluidtopics.net/LetJ9juQn~ygGwVS7EwGug "A threat library is defined as a group of organized objects and entities that serve the organizations with structured and unstructured security threat information."). * * Search across the data present in the application using search provided in Threat Library page. * Manages the data ingested from various sources in Threat Library. * Performs various enrichment actions on Observables. * Creates and manages Cases. For more information, see [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task."). {#set-up-threat-intelligence-security-center__ul_rch_skv_21c} {#set-up-threat-intelligence-security-center__ul_qlf_rkv_21c} {#set-up-threat-intelligence-security-center__ul_ozy_jkv_21c} |
[Table 1. Entitlements applicable for TISC Roles]

{#set-up-threat-intelligence-security-center__table_lfk_hkv_21c}

## Plugins {#set-up-threat-intelligence-security-center__section_byt_blv_21c}

{#set-up-threat-intelligence-security-center__table_d51_dlv_21c__entry__2}

| Plugin | Description |
|-|-|
| This following applications are required to installTISC: * Security Case Management common workspace components \[com.snc.escm.ws_commons\]. * Threat Intelligence Support Common \[com.snc.threat\]. * Column Level Encryption (com.glide.encryption) * Large JSON and XML Payload Builder API (com.glide.streaming_builder) * Security Support Core (com.snc.security_support.core) {#set-up-threat-intelligence-security-center__ul_db1_hlv_21c} | Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you configure this integration. |
[ ]

{#set-up-threat-intelligence-security-center__table_d51_dlv_21c}

## What to do next {#set-up-threat-intelligence-security-center__section_pvt_c1x_z3c}

[Set Threat Intelligence Security Center properties](https://servicenow-prod.fluidtopics.net/C7U1wHMdUzH4kJf2ZTuYmg "Review the components installed with Threat Intelligence Security Center to understand the roles, properties, and other elements added to your instance.").

