---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuring Outbound Intel Sharing Controls

# Configuring Outbound Intel Sharing Controls {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Use this section to configure outbound sharing controls, which determine the entities enabled for intelligence sharing from TISC to external systems.

## Before you begin

Role required: sn_sec_tisc.admin

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterAdministrationOutbound Intel Sharing.
2. Select Outbound Intel Sharing Controls.  
   Outbound Intel Sharing Controls is the default sharing control provisioned in the base system. By default, this control is set to the Published state.  
   Note:  
   * These are the high-level sharing controls, which can later be used within intelligence sharing templates.
   * Every action performed on the outbound sharing controls is recorded, and a work note is posted in the activity stream for each entity that is created, modified, or deleted.
   {#tisc-outbound-sharing__ul_usj_1jc_mfc}

Editing Sharing Controls:

3. Select Edit to modify the required fields if you want to change the default sharing control record.  
   Whenever you edit the sharing control record, a validation message is displayed indicating you to disable all templates and confirm that there are no pending outbound intelligence sharing records before proceeding.
   If the above validations are successful, then another warning message is displayed indicating that any automation flows based on these settings can fail if you proceed without disabling them first.  
   Warning:  
   Editing these settings without first disabling the associated automation flows may cause errors. Do you want to proceed?If you acknowledge this risk and want to proceed, you can modify the sharing control.

Managing Entity-Level Sharing Controls:

4. Go to Sharing Controls section to view all the sharing controls available for the entities.  
   By default all threat intelligence library entities present in the application including the observables, indicator, and objects are included.
5. Select any entity to view its required and optional attributes.  
   The Edit Entity and Attributes dialogue box is displayed.

Adding or Removing Entities:

6. Select Remove Entity if you want to remove any entity.  
   This action Remove Entity removes the entity and automatically excludes it from outbound intelligence sharing. Once removed, the entity can't be used for sharing within TISC and removal automatically removes the entity from all the templates, which has this entity as part of the sharing controls.

   Additionally, select Remove all attributes (Trash icon available at the bottom of the dialog box) to remove all the optional attributes. Removing any of these attributes directly impacts the corresponding intelligence sharing templates.  
   Note:  
   * If there are any outbound sharing templates, which includes the selected entity then a warning message is displayed on the Edit Entity and Attributes dialog box indicating that removing the selected entity or any of its attributes automatically excludes them from the {#total number of templates} outbound intelligence sharing templates they're currently included in. The affected templates are listed on the Edit Entity and Attributes dialog box itself.
   * A list of affected templates, for example: IOC Sharing Template is displayed for your review.
   * If there are certain entities you don't want to share with external systems, you can remove them from the sharing controls.
   * Only the entities configured within the sharing controls will be available for selection when creating or modifying intelligence outbound sharing templates.
   {#tisc-outbound-sharing__ul_ykw_wgc_mfc}
7. Select Add all optional attributes to include all the optional attributes of the selected entity in the outbound intelligence sharing.
8. After you make the necessary changes to the sharing controls, then select Publish to publish the sharing controls.  
   Once the sharing controls are published, they are available for use within intelligence outbound sharing templates. For more information, see [Configuring Outbound Intel Sharing Templates](https://servicenow-prod.fluidtopics.net/160U6adHmYOxO_VAdpfWAA "Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).").

## What to do next

Refer to the following sections for guidance on external intelligence sharing using both the GUI and automated procedures.

* [Sharing of Outbound Intelligence Records from GUI](https://servicenow-prod.fluidtopics.net/b~DwM~dlSXMJ5pYPtajp_g "This section outlines the functionality that enables users to share intelligence records directly from the Threat Intelligence (TI) Library within the TISC application.")
* [Automated sharing of high-risk IOC's with trusted partners](https://servicenow-prod.fluidtopics.net/M5XZUkj~h_Ndyj4pfQGfPQ "Learn how to automate sharing of high-risk IOC's with trusted partners.")[Configuring Outbound Intel Sharing Templates](https://servicenow-prod.fluidtopics.net/160U6adHmYOxO_VAdpfWAA "Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).")
{#tisc-outbound-sharing__ul_wgj_ppg_qfc}
**Related tasks**   

* [Configuring Outbound Intel Data Exclusion Rule](https://servicenow-prod.fluidtopics.net/2d0fdgmQ6bqkYGvIbuuyug "Use this section to create exclusion rules, which can be configured by TISC admin to restrict sharing of records that match the defined criteria.")
* [Configuring Outbound Intel Sharing Profiles](https://servicenow-prod.fluidtopics.net/s7Ot22IjeEsnaEQo8k8U5Q "Use this section to create new Outbound Intelligence Profiles. The outbound intelligence profiles specify the endpoint details to which threat intelligence data is sent.")
* [Configuring Outbound Intel Sharing Groups](https://servicenow-prod.fluidtopics.net/991t1csl9sSEPta9MtviDg "Outbound Intel Sharing Groups allow you to combine multiple profiles and use them collectively when sharing data.")
* [Defining Approval Rule for Outbound Intel](https://servicenow-prod.fluidtopics.net/tBYkoIRyd~7SM0oHgw4MMw "Define approval rules to control whether certain users require approval before sharing the shared intelligence.")
* [Configuring Outbound Intel Sharing Templates](https://servicenow-prod.fluidtopics.net/160U6adHmYOxO_VAdpfWAA "Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).")
* [Working on the Redaction Library](https://servicenow-prod.fluidtopics.net/I2Fnhq550Id7apaHgnUDHw "Redaction is the process of replacing sensitive information from shared data to protect confidentiality during intelligence sharing.")

*[\>]: and then


