---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# TISC Key terminology

# TISC
Key terminology {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Key terms and definitions used in TISC to help you understand threat intelligence concepts and navigate the interface effectively.
{#tisc-key-terminology__table_rvc_3t1_pzb__entry__2}

| Terminology | Definition |
|-|-|
| Data Processing | A Threat Intelligence Platform (TIP) collects, aggregates, and organizes threat intelligence data from various sources and patterns. Threat intelligence is data that is collected, processed, and analyzed to understand threat actor targets and attack behaviors. |
| Observables | Observables represent stateful properties or measurable events pertinent to computer and network operations. Examples include MD5 file hashes, registry key values, registry key creation, or file deletion. For more information, see [Observables](https://servicenow-prod.fluidtopics.net/TpRZ5xJslvI75bF2VSkHlw "Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks."). |
| Indicators | Indicators contain patterns used to detect suspicious or malicious cyber activity. For example, an Indicator can represent malicious domains using the STIX Patterning Language. The Indicator SDO contains a textual description, Kill Chain Phases for detected behavior, a validity time window, and a required pattern property for structured detection patterns. For more information, see [Indicators](https://servicenow-prod.fluidtopics.net/Vt9vRBU0WKDaohaALNYAZA "Indicators are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names."). |
| Objects | Defines STIX Domain Objects (SDOs), each corresponding to a unique concept in cyberthreat Intelligence (CTI). Using SDOs and STIX Relationship Objects (SROs), you can create and share comprehensive cyberthreat intelligence. For more information, see [TISC Library Repository](https://servicenow-prod.fluidtopics.net/4G3NQv0L~ouF_cvQvhfm1w "IoC repository contains STIX objects, each of these objects contain a specific piece of information."). |
| Relationships | A relationship links two observables, two SDOs, or an Observable and SDO, describing how the objects relate. Relationships can be represented using an external STIX Relationship Object (SRO) or through properties that store identifier references for embedded relationships. For more information, see [Relationships Objects](https://servicenow-prod.fluidtopics.net/J~q6TTZl8g7YV7RLAD7Iqw "Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other."). |
[Table 1. Terminology Definitions]

{#tisc-key-terminology__table_rvc_3t1_pzb}
**Related tasks**   

* [TISC Workspace](https://servicenow-prod.fluidtopics.net/38sNgiOL5dsztWeWjTXp2Q "View a centralized dashboard of threat intelligence data including feeds overview, trending threats, and intelligence sharing metrics. Monitor your security posture with trending intelligence data.")
* [TISC Workspace](https://servicenow-prod.fluidtopics.net/38sNgiOL5dsztWeWjTXp2Q "View a centralized dashboard of threat intelligence data including feeds overview, trending threats, and intelligence sharing metrics. Monitor your security posture with trending intelligence data.")

