---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a security incident from a TISC case

# Create a security incident from a TISC case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Create security incidents and associate observables to the security incidents from a TISC case.

## Before you begin

Role required: sn_si_basic

## Procedure

1. Navigate to AllWorkspacesThreat Intelligence Security Center.
2. Click Threat Analyst Workbench icon.
3. Go to Case ManagementAll Cases.  
   All the cases are displayed.
4. Open any case.
5. Click Create Security Incident button.  
   Note:  
   On the Case Management Workbench the Create Security Incident button is enabled only for the open case records and disabled for the closed case records.  
   The Create Security Incident dialog box is displayed.
6. Fill the form with appropriate incident details:  
   {#tisc-create-si-case__table_ixf_4mt_z2c__entry__2}

   | Field | Description |
   |-|-|
   | Short description | Enter a short description of the security incident. |
   | Description | Enter a description of the security incident. |
   | Category | Defines the classification of the security incident. |
   | Priority | Defines the priority of the security incident. |
   | Subcategory | Defines the sub classification of the security incident based on its category. |
   | Assignment group | Specifies the assignment group to which the security incident should be assigned. |
   | Parent | Indicates the parent security incident, which is a TISC case from which this action is triggered. |
   [Table 1. Add details]

   {#tisc-create-si-case__table_ixf_4mt_z2c}
7. Click Next to continue.  
   Note:  
   You must enter all the mandatory fields, the Next button will remain disabled until you enter all the required fields.
8. Select the observables associated with the TISC case to link them to a security incident, and then click Next to proceed
9. Review the security incident details and observable that will be associated with the newly created security incident then click Create to continue and create the security incident.  
   Note:  
   A confirmation message is displayed indicating that the security incident is created, with a link to the security incident, clicking the link will direct you to the security incident in the Security Incident Response Workspace.  
   After the security incident is created, you will be redirected to the TISC Artifacts tab of the case.
10. Go to Security Incidents section under the TISC Artifacts tab to view the incidents.  
    Note:  
    A work notes is also posted on the TISC case activity stream indicating that the security incident (security incident number) is created with the associated with TISC observables. This work notes includes the details such as the observable type and observable value.

    On the Security Incident Response Workspace, security incident form:
    * A work notes is posted on the activity stream indicating that the security incident was successfully created from TISC case. This work notes also includes a link to the TISC case confirming that the selected observables have been associated with the security incident.
    * In addition, you can also verify this by accessing the Related Records tab of the Security Incident Response Workspace and reviewing the observables entries under Threat IntelAssociated Observables. From there, you can also view the associated observables under the TISC Context section. You may notice that the these observables have been directly associated from TISC.
    {#tisc-create-si-case__ul_etd_ccv_z2c}
**Related concepts**   

* [Workbench Overview](https://servicenow-prod.fluidtopics.net/v09QNspsdgUKsjcssQ44nQ "The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team.")
* [Working with Investigation Canvas](https://servicenow-prod.fluidtopics.net/EprH7pyEqFs2LVQ4KGvJ5w "The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.")
* [Using playbooks](https://servicenow-prod.fluidtopics.net/S_4Mkl_RpxIBoyykp2nXbQ "Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.")  
**Related tasks**   

* [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.")
* [Summarize a Case using generative AI](https://servicenow-prod.fluidtopics.net/cR_IUVt2~1oWmLQRzSERog "Use to generate a concise summary of a case, including its key findings and recommended next steps.")
* [Creating case task using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/QIyOkhiAbQsuKQ~ncYN_TQ "Create case tasks to associate with case(s).")
* [Add artifacts to case(s) or case task(s)](https://servicenow-prod.fluidtopics.net/w7jOBRuuDQT6Qje2vs23wg "After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.")
* [Run Enrichment Actions within a case](https://servicenow-prod.fluidtopics.net/Gh87urOsiF~BhNjGZQsVqg "Use this section to understand how enrichments actions are performed on case(s).")
* [Generate a Case Report using generative AI](https://servicenow-prod.fluidtopics.net/1bdvh6WMLeuGwDMntyZLaA "Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution.")
* [Generate a Case Report using a template](https://servicenow-prod.fluidtopics.net/6Y9mhLC9aae1X07xvHOfBg "Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report.")
* [Upload Secure File Attachments](https://servicenow-prod.fluidtopics.net/~1CsuAO80SPkjnX1j_LDpQ "Use this section to understand on how to upload the secure file attachments to the case(s).")

*[\>]: and then


