---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuring Inbound Intel Sharing Profiles

# Configuring Inbound Intel Sharing Profiles {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

This section describes the inbound intelligence sharing profiles used to receive intelligence from external organizations into TISC.

## Before you begin

Role required: sn_sec_tisc.admin  
Note:  

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterAdministrationInbound Intel Sharing.
2. Select Inbound Intel Sharing Profiles.
3. Select New to create an Inbound Intelligence Profile.
4. On the form, fill in the fields.  
   {#tisc-config-inbound-profile__table_syl_ztc_mfc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the inbound intelligence profile. |
   | Industry | Select the industry category such as Aerospace, Agriculture for which the inbound intelligence profile is applicable to. |
   | Description | Description of the inbound intelligence profile. |
   | Inbound Intelligence Settings ||
   | Data Format | Supported data formats for inbound intelligence sharing profile. Currently, two data formats are supported for inbound intelligence sharing: * STIX 2.1 * MISP {#tisc-config-inbound-profile__ul_v12_h1d_mfc}For more information on the data formats description, see [Configuring Outbound Intel Sharing Profiles](https://servicenow-prod.fluidtopics.net/s7Ot22IjeEsnaEQo8k8U5Q "Use this section to create new Outbound Intelligence Profiles. The outbound intelligence profiles specify the endpoint details to which threat intelligence data is sent."). |
   | User for authentication (should have sn_sec_tisc.api_post_intel role) | Select the user whose credentials should be used for authentication when an external system shares intelligence with TISC for this profile. Note: Users with sn_sec_tisc.api_post_intel role only be available in the drop-down list. |
   | Default Confidence | Indicates the default confidence level applied to all intelligence records received from this profile when the source doesn't provide a confidence value. |
   | Expiry period (days) | Specifies the number of days after which the intelligence records received from sharing profile expires. Once expired, the intelligence records might no longer be visible, shared, or considered valid. |
   | Default TLP | Specifies the default TLP applied to all intelligence records received from this profile when the source doesn't provide a TLP value. |
   | Enable Notification | Select this check to send a notification to the sender on approval or rejection of the inbound intelligence record. |
   | Notify On | Use this option to choose when to notify the email recipients configured (for example, on approval or rejection or both of a record). Note: This option appears only if Enable Notification is selected. |
   | Email Recipients | Enter the email addresses of users who should be notified based on the criteria configured in the Notify On field. Note: This field is only visible when Enable Notification is checked. Multiple email addresses can be entered, separated by commas. |
   | TISC Tags | Specifies the tags to be added to all the inbound intelligence received from external system. |
   [Table 1. Create New Inbound Intelligence Profile]

   {#tisc-config-inbound-profile__table_syl_ztc_mfc}
5. Select Save.

Copy Profile ID:

The external organizations require this profile ID to share the information.

6. Select Copy Profile ID button to copy your profile ID for sharing.
7. Additionally, select Email Profile ID to email the sharing profile details.  
   When you select this option, an email composer dialog box is displayed. Fill the email details to whom you want to share the profile.
8. Select Send to send the details to the external user.
**Related tasks**   

* [Configuring Inbound Intel Sharing Groups](https://servicenow-prod.fluidtopics.net/LiUOfAcmLVTMwFDwv7oo0w "Inbound Intel Sharing Groups enable administrators to group similar inbound intelligence sharing profiles together. These groups can be used to define approval rules that apply to all profiles within the group.")
* [Defining Approval Rule for Inbound Intel](https://servicenow-prod.fluidtopics.net/dNRydxqG_6v6_wTA13kpvA "Define approval rules to control whether certain profiles or groups require approval before processing the inbound intelligence.")
* [Configuring Inbound Intel Sharing Groups](https://servicenow-prod.fluidtopics.net/LiUOfAcmLVTMwFDwv7oo0w "Inbound Intel Sharing Groups enable administrators to group similar inbound intelligence sharing profiles together. These groups can be used to define approval rules that apply to all profiles within the group.")
* [Defining Approval Rule for Inbound Intel](https://servicenow-prod.fluidtopics.net/dNRydxqG_6v6_wTA13kpvA "Define approval rules to control whether certain profiles or groups require approval before processing the inbound intelligence.")

*[\>]: and then


