---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exploring Security Operations

# Exploring Security Operations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Protect your assets and enterprise environment with ServiceNow Security Operations applications and the power of the ServiceNow AI Platform®. Connect your security and IT teams to help you prioritize and resolve threats based on the impact they pose to your organization.

## Security Operations overview {#understanding-secops__section_hx5_tqw_lbc}

The Security Operations suite of applications helps you protect your assets by improving your overall security posture. For example, by integrating applications such as Unified Security Exposure Management (USEM) Security Incident Response, Vulnerability Response, and Security Posture Control with your existing security tools, your Security Operation Center (SOC) analysts, managers, and IT teams can:

* Respond to rapidly evolving cyber and security threats.
* Identify, prioritize, and remediate exposure findings in the [Unified Security Exposure Management (USEM)](https://servicenow-prod.fluidtopics.net/yewoUeMfeoOsrMOTtdf59Q "Unified Security Exposure Management (USEM) is a comprehensive platform designed to transform how organizations manage security exposure across their digital estate. It consolidates multiple security exposure applications including Vulnerability Response, Configuration Compliance, Application Vulnerability Response, and Container Vulnerability Response into a single, cohesive architecture.") platform that brings together infrastructure, application, container, and configuration exposures into one unified experience.
* View your complete asset inventory.
* Determine your overall security tool coverage.
* Resolve security incidents faster with intelligent workflows and ServiceNow Generative AI skills (GenAI). See [ServiceNow Otto for Security Incident Response (SIR)](https://servicenow-prod.fluidtopics.net/Y2ce_RVCYtKdTnaM3q7wZA "With ServiceNow Otto for Security Incident Response (SIR), security analysts can use intelligent workflows and ServiceNow generative AI skills to help them resolve security incidents. Security managers can review the context of security incidents and closure notes quickly in a concise, easy-to-read format, view post-incident analysis data, and see recommended remediation steps.") for more information.
{#understanding-secops__ul_t5f_j5x_jbc}

## Security Operations applications for workflows {#understanding-secops__section_ix5_tqw_lbc}

The Security Operations applications fall under two broad categories for Security Operations workflows:

* Unified Security Exposure Management (USEM) - Applications and tools that help you anticipate, understand, and close your security exposures. See [Unified Security Exposure Management (USEM)](https://servicenow-prod.fluidtopics.net/yewoUeMfeoOsrMOTtdf59Q "Unified Security Exposure Management (USEM) is a comprehensive platform designed to transform how organizations manage security exposure across their digital estate. It consolidates multiple security exposure applications including Vulnerability Response, Configuration Compliance, Application Vulnerability Response, and Container Vulnerability Response into a single, cohesive architecture.") for more information about using Security Operations applications in USEM.
* Enterprise security case management - Applications and tools that help you move quickly to respond to critical incidents.
{#understanding-secops__ul_l5j_4tq_41c}
Figure 1. Security workflows

## Benefits of the Security Operations applications {#understanding-secops__section_lx5_tqw_lbc}

View Security Operations applications and data with next-generation user interfaces (workspaces). With workspaces, the security analysts, Security Operation Center (SOC) managers, and remediation specialists in your organization can monitor and manage the following types of workflows from one location:

* The life cycle of security incidents from an initial analysis to containment, eradication, and recovery.
* The security exposures that they care the most about so they can decide strategically which vulnerabilities they send to IT teams to fix.
* Key insights and key use cases for security tool coverage and asset hygiene that report and monitor imported information about your assets.
{#understanding-secops__ul_ubg_p5x_jbc}  
The two categories of Security Operations applications and the use cases they help you address in your enterprise environment:

* USEM applications - Applications that help you anticipate threats and identify security exposures.
* Enterprise security case management applications - Applications that help you respond to critical security breaches and incidents
{#understanding-secops__ul_lsc_pq1_nhc}

## USEM applications {#understanding-secops__section_zjv_j5q_41c}

{#understanding-secops__table_pst_w5x_jbc__entry__3}

| Application | Description | Users |
|-|-|-|
| Security Posture Control | Gain insights into how well security tools are deployed and covering your assets based on an asset inventory and imported data. Service graph connectors and ServiceNow products such as Hardware Asset Management (HAM) and ITOM Discovery are supported for data imports. Audits based on policies help you prioritize the remediation of high-risk combinations such as internet exposure and known vulnerabilities. Create custom policies and insights to monitor the compliance of assets with your internal security tool configuration standards. | * CISO * Information security analyst * Security operations manager * IT Operations engineer * Service owner (remediation owner persona) {#understanding-secops__ul_rhn_dhw_4bc} |
| Unified Security Exposure Management (USEM) | View security exposure findings as well as consolidated, multiple exposure findings across all asset types in one unified platform. Monitor and manage all types of security exposures across your organization's attack surface that use imported data from the following applications: * Vulnerability Response * Application Vulnerability Management * Configuration Compliance * Container Vulnerability Response {#understanding-secops__ul_uzg_4vc_jhc} | * Vulnerability managers and analysts * Compliance managers and analysts * Remediation owners * Security champions * Service owners {#understanding-secops__ul_pvg_vvc_jhc} |
[Table 1. Applications that help you anticipate threats and identify security exposures]

{#understanding-secops__table_pst_w5x_jbc}

## Enterprise security case management applications {#understanding-secops__section_sf5_z5q_41c}

{#understanding-secops__table_vns_1wx_jbc__entry__3}

| Application | Description | Users |
|-|-|-|
| Security Incident Response | Simplify the process of identifying critical incidents by applying powerful workflow and automation tools that speed up remediation. Integrate your existing Security Information and Event Manager (SIEM) tools with Security Incident Response and Security Operations applications to import threat data from various sources and automatically create prioritized security incidents. | * CISO * Information security analyst * Security operations manager * Threat intelligence analyst {#understanding-secops__ul_elr_5hw_4bc} |
| Major Security Incident Management | The major security incident management capabilities work with the existing security incident response product capabilities. This includes an ability for a security analyst to escalate a standard security incident to a major security incident, so that the new product capabilities are available to support the remediation process. Track the progress of Major Security Incident (MSI) from discovery to analysis. Propose solutions, promote, and link security incidents, and closure. | * CISO * Information security analyst * Security operations manager * IT Operations engineer * Service owner (remediation owner persona) * General council {#understanding-secops__ul_y1c_whw_4bc} |
| Data Loss Prevention Incident Response | The Data Loss Prevention Incident Response (DLP IR) permits you to review and manage the remediation workflow of DLP incidents from multiple sources, such as endpoint, network, email, and cloud. With the DLP application, you can identify, respond, and protect your data loss channels. | * CISO * Information security analyst * Security operations manager {#understanding-secops__ul_akc_yhw_4bc} |
| Threat Intelligence | Allows incident response teams to automate threat lookups, searches, and correlation. The integration with MITRE ATT\&CK permits you to measure and understand detection and mitigation coverage and assists with threat hunting. | * CISO * Information security analyst * Security operations manager * Threat intelligence analyst {#understanding-secops__ul_odj_phw_4bc} |
| Threat Intelligence Security Center (TISC) | Aggregate, curate, and manage threat intelligence from multiple sources and conduct threat intelligence case management. Track campaigns, operationalize threat intelligence, and respond to actionable intelligence. | * CISO * Information security analyst * Security operations manager * Threat intelligence analyst {#understanding-secops__ul_rdj_phw_4bc} |
[Table 2. Applications that help you respond to critical security breaches and incidents]

{#understanding-secops__table_vns_1wx_jbc}

## What to explore next {#understanding-secops__section_kg4_x34_mbc}

Select a tile to get started with the Security Operations Workspaces.

|-|-|-|
| [Security Incident Response Workspace Learn about the Security Incident Response Workspace](https://servicenow-prod.fluidtopics.net/EmZFs2~PIit1DPFbKL384A "The ServiceNow Security Incident Response Workspace is a reimagined interface that provides a next-gen user experience for the security analysts and SOC managers. The security analysts can use this to manage the life cycle of security incidents from an initial analysis to containment, eradication, and recovery.") | [Security Exposure Management Workspace Learn about the Security Exposure Management Workspace](https://servicenow-prod.fluidtopics.net/yewoUeMfeoOsrMOTtdf59Q "Unified Security Exposure Management (USEM) is a comprehensive platform designed to transform how organizations manage security exposure across their digital estate. It consolidates multiple security exposure applications including Vulnerability Response, Configuration Compliance, Application Vulnerability Response, and Container Vulnerability Response into a single, cohesive architecture.") | [Security Posture Control Workspace Learn about the Security Posture Control Workspace](https://servicenow-prod.fluidtopics.net/W5AAIQAtM~aFACI5JIjOgw "Gain visibility into your enterprise asset inventory and security tool coverage. Use policies provided with the product or create your own to identify assets missing key security tools, such as endpoint protection, configuration management, and vulnerability scanning. Monitor assets for security tool configurations specific to your environment and automate the remediation workflow for security gaps in the Configuration Compliance application.") |
| [Vulnerability Assessment Workspace Learn about the Vulnerability Assessment Workspace](https://servicenow-prod.fluidtopics.net/u8sK2NCOophqngLNqHw_8w "The Vulnerability Assessment Workspace is designed for the Vulnerability event manager to perform exposure assessment, and proactively manage critical vulnerability events especially during the critical vulnerability events such as a zero-day event.") | [IT Remediation Workspace Learn about the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/kl4_xDHEVmF1jpL7AeKbFw "The IT Remediation Workspace is intended for IT remediation owners and IT groups. It is composed of home and list views as well as data visualizations that you can click that let you see the remediation tasks you've been assigned and how many records assigned to you have solutions.") | [Software Bill of Materials Workspace Learn about the Software Bill of Materials Workspace](https://servicenow-prod.fluidtopics.net/NepUgpyctg_YSXnvTHCQ1A "View a list of the open source and third-party software components that you’re using in your application development. Get insights into software licenses, version information, and the known vulnerabilities in your components in the Software Bill of Materials (SBOM) files that you upload into your instance.") |
| [Threat Intelligence Security Center (TISC) Workspace Learn about the TISC Workspace](https://servicenow-prod.fluidtopics.net/v_eC3uWaEeyQ8wunrolOMA "The Threat Intelligence Security Center (TISC) platform provides technology solution for aggregation, management and operationalization of threat intelligence.") | [Data Loss Prevention (DLP) Incident Response Workspace Learn about the DLP Workspace](https://servicenow-prod.fluidtopics.net/ZFBvyGYhyy8KpOqY3dQUSg "The Data Loss Prevention Incident Response (DLP IR) application enables you to review and manage the remediation workflow of DLP incidents from multiple sources, such as endpoint, network, email, and cloud.") | [Major Security Incident Management (MSIM) Workspace Learn about the MSIM Workspace](https://servicenow-prod.fluidtopics.net/8F9bn6Du_7ExfNku3ULWiA "The ServiceNow Major Security Incident Management application tracks the progress of Major Security Incident (MSI) from discovery to analysis, propose, promote, and link security incidents, and closure.") |
[ ]

{#understanding-secops__table_zkx_2fb_h1c}

## Troubleshoot and get help {#understanding-secops__section_y1f_5hc_1cc}

ServiceNow Community
:   <https://www.servicenow.com/community/>

Customer Success Center
:   <https://www.servicenow.com/community/>

Developer
:   <https://developer.servicenow.com/dev.do>


Impact
:   <http://impact.servicenow.com>


ServiceNow University
:   <https://learning.servicenow.com/now/lxp/home>

NowCreate
:   <https://mynow.servicenow.com/now/best-practices/home>

Partner
:   <https://www.servicenow.com/partners.html>


ServiceNow
:   <http://servicenow.com>


ServiceNow Store
:   <http://servicenow.com>

Support
:
    * <https://support.servicenow.com/now>
    * <https://support.servicenow.com/kb?id=known_error_portal>
    {#understanding-secops__ul_hzv_5pq_xcc}

