Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Components installed with Security Incident Response

Several types of components are installed when you download and activate the Security Incident Response application, including user roles, tables, properties, and scheduled jobs.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

Demo data is available for this feature.

Properties installed

Users with the System Administrator [admin] role can view the properties. Users with the Security Administrator [sn_si.admin] role can modify them.

PropertyUsage
The default category nodes that are displayed in the Relationship Graph tab within the Workspace. The default values represent the table names corresponding to the related records.sn\_si\_aw.defaultCategories
  • Type: string
  • Default value: sn_ti_m2m_task_observables,sn_si_m2m_task_affected_user,sn_si_incident
Default start time for all agents when no schedule is set, formatted as 08:00sn\_si.default.start.time
  • Type: string
  • Default value: 08:00
  • Location: Security Incident > Administration > Properties
Default end time for all agents when no schedule is set, formatted as 17:00sn\_si.default.end.time
  • Type: string
  • Default value: 17:00
  • Location: Security Incident > Administration > Properties
Include Destination type observables along with other context type observables in the security incident user and CI relationshipssn\_si.link\_dest\_ipDetermines whether a security incident observable with a context type of Destination is displayed under the Configuration Items or Affected Users tabs. By default, observables with a Destination context type are excluded. To include the observables, choose Yes.
Allow customization when creating a Problem or Change Request from a Security Incidentsn\_si.popup

When a problem or change is created, this property opens a pop-up window to modify the request.

If this properties are set to false, the problem or change request has the same priority, short description, and description as the security incident without the option to add or edit those fields.

  • Type: true \| false
  • Default value: true
  • Location: Security Incident > Administration > Properties
Associate Sightings Search results with CIs in the CMDB.sn\_si.associate\_ci\_with\_sighting\_searchWhen set to true, sightings search results include associated configuration items that are in your CMDB. - Type: true \| false - Default value: true - Location: Security Incident > Administration > Properties
Risk score in the range is highlighted green, formatted as 0-49sn\_si.risk.score.greenIn the Security Incidents list, security incidents with a risk score between 0 and 49 are marked with a green dot.
Risk score in the range is highlighted orange, formatted as 50-79sn\_si.risk.score.orangeIn the Security Incidents list, security incidents with a risk score between 50 and 79 are marked with an orange dot.
Risk score in the range is highlighted red, formatted as 80-100sn\_si.risk.score.redIn the Security Incidents list, security incidents with a risk score between 80 and 100 are marked with a red dot.
This parameter enables or disables Sightings Search Configurations that have implemented this feature.sn\_si.enable\_sighting\_searchWhen set to true, sightings searches can be performed on activated integrations. - Type: true \| false - Default value: true - Location: Security Incident > Administration > Properties
The number of rows of raw data that are saved when a Sighting Search is performed. Range 0-100sn\_si.sighting\_search\_raw\_data\_rowsThis property defaults to 50 rows of raw data. Half of the result rows are reported from the beginning of the search time frame and half from the end of the search time frame. So, if you select 50 rows, 25 come from the start of the search time frame and 25 from the end of the search time frame.
Automatically advance the Incident State to Contain when a Response Task advances to Work In Progresssn\_si.rollup\_task\_stateWhile using flows or workflows, consider setting this property to false. This enables you to control the Incident State from within flows or workflows. It also helps avoid any potential conflicts while transitioning from one incident state to another.- Type: true \| false - Default value: true - Location: Security Incident > Administration > Properties
Assignment properties for Security Incident Response
Location Weightsn\_si.location.weightA rating used when calculating the criteria to use for auto-assigning a security analyst. If, for example, location is considered for a task, the location weight value is added to the security analyst rating.- Type: integer - Default value: 10 - Location: Security Incident > Administration > Properties
Skills Weightsn\_si.skills.weightA rating used when calculating the criteria to use for auto-assigning a security analyst. If, for example, skills are considered for a task, the skills weight value is added to the security analyst rating.- Type: integer - Default value: 10 - Location: Security Incident > Administration > Properties
Set the maximum number of security analysts to be processed by auto-assignment at a time sn\_si.max.agents.processedThe system has an absolute limit of 300 security analysts. If you specify more than 300, it sets the value to that level. The system cannot auto-dispatch a task for a dispatch group that contains more security analysts than the value configured.- Type: integer - Default value: 100 - Location: Security Incident > Administration > Properties
Time Zone Weightsn\_si.timezone.weightA rating used when calculating the criteria to use for auto-assigning a security analyst. If, for example, the security analyst time zone is considered for a task, the time zone weight value is added to the security analyst rating.- Type: integer - Default value: 10 - Location: Security Incident > Administration > Properties
Amount of time \(in minutes\) to add between the end of a task and the travel start of the next.sn\_si.work.spacingAn example of a valid time value is 10.- Type: integer - Default value: 0 - Location: Security Incident > Administration > Properties
Specified journal fields containing `code` tags that render content as HTML.sn\_si.journal\_field.html\_enabled
  • Type: string
  • Default value: work_notes, comments
  • Location: Security Incident > Administration > Properties
Calculate the Impacted services in background.sn\_si.refresh\_impacted.event

Affected Services/Impacted CIs related list is generated through events. When enabled the refresh gets executed in the background and security tags are added to the incident.Set the value to true to perform the operation in background.

  • Type: true \| false
  • Default value: false
  • Location: Security Incident > Administration > Properties
Retrieve the critical service from a pre-calculated data.sn\_si.critical\_service.calculator.use\_cache

Enables the critical service calculator to use a pre-calculated data of configuration items.

Set the value to true to lookup from a pre calculated data

  • Type: true \| false
  • Default value: false
  • Location: Security Incident > Administration > Properties

Roles installed

Role title \[name\]DescriptionContains roles
Security Incident Administrator\[sn\_si.admin\]Full control over all Security Incident Response data. Also administers territories and skills, as needed.Note: In the base system, the administrator also has access to sn_si.admin. Security Incident Response can be restricted from the administrator as long as at least one other user is assigned the security administrator role.- assessment\_admin - catalog\_admin - decision\_table\_admin - decision\_table\_reader - filter\_admin - flow\_designer - pd\_author - pd\_content\_author - pd\_operator - skill\_admin - skill\_model\_admin - sn\_si.analyst - sn\_si.ingestion\_profile\_admin - sn\_si.knowledge\_admin - sn\_si.manager - sn\_sec\_cmn.admin - sn\_secops\_setup.admin - sn\_si.restriction\_access\_manager - sn\_si.special\_access\_read\_manager - sn\_si.special\_access\_write\_manager - sn\_ti.malicious\_attachment\_access - sn\_ti.observable.admin - tags\_admin - template\_admin - territory\_admin - treemap\_admin - user\_admin
Profile Admin\[sn\_si.ingestion\_profile\_admin\]

Configure the plugins, create, edit, delete, and manage profiles for Splunk, Splunk ES, and Azure Sentinel Integration for Security Operations application.Note: Users with the sn_si.admin role can perform all operations available to a Profile Admin, as the sn_si.admin role inherits the required permissions by default.

The sn_si.ingestion_profile_admin role is assignable to users by the sn_si.admin.

N/A
Security Incident Analyst\[sn\_si.analyst\]Manage security incidents. Underlying role for basic Security access. Users with this role can create and update security incidents, requests, and tasks, as well as problems, changes, and outages related to their incidents.- pd\_operator - snc\_platform\_rest\_api\_access - sn\_msi.promoter - sn\_msi.proposer - sn\_si.basic - sn\_ti.malicious\_attachment\_access - awa\_agent
Security Incident Basic\[sn\_si.basic\]Underlying role for basic Security access. Users with this role can create and update security incidents, requests, and tasks, as well as problems, changes, and outages related to their incidents.- canvas\_user - document\_management\_user - email\_composer - flow\_operator - inventory\_user - pa\_viewer - service\_fullfiller - skill\_user - sn\_sec\_cmn.write - sn\_si.read - sn\_ti.observable.read - sn\_ti.observable.write - sn\_ti.read - task\_activity\_writer - task\_editor - treemap\_user
Chief Information Security Officer \(CISO\)\[sn\_si.ciso\]View and manipulate the CISO dashboard. Also, if the Vulnerability Response plugin is activated, users with this role can add vulnerability significance definition treemaps to the dashboard. You can also do the same with Security Incident Response plugin.- pa\_viewer - sn\_si.basic - sn\_si.read
Security Incident External\[sn\_si.external\]

View any security incidents that belong to their particular group.Note: The following two rules are applicable throughout ServiceNow irrespective of scoped admin or scope app.

  • When you add any user to a group, you are also assigning roles to that group. Similarly, when you remove a user from a group, the inherited roles will also get removed.
  • Every role is assignable by some higher precedence role.
service\_fulfiller
Security Incident Integration User\[sn\_si.integration\_user\]External tools can provide new security incident records and update security incident records.import\_transformer
Security Incident Knowledge Administrator\[sn\_si.knowledge\_admin\]Manage, update, and delete the information in the Security Incident knowledge base.- knowledge\_admin - sn\_si.read
Security Incident Manager\[sn\_si.manager\]Same access as security analysts.- pd\_author - pd\_operator - sn\_si.basic
Security Incident Read\[sn\_si.read\]Read security incidents.- canvas\_user - sn\_sec\_cmn.read - sn\_templated\_snip.template\_snippet\_reader - sn\_ti.observable.read - workspace\_user
Security Restriction Access Manager \[sn\_si.restriction\_access\_manager\]Allows users or groups to 'enforce restriction' on security incidents. This is applicable only for field change.N/A
Security Incident Special Accesssn\_si.special\_accessProvides access to specific security incidents to users outside of the Security Operations organization.N/A
Security Special Access Enabler \[sn\_si.special\_access\_enabler\]Provides special access role to a user outside of the Security Operations organization to specific security incidents.N/A
Security Incident Special Access Read Manager \[sn\_si.special\_access\_read\_manager\]Manage the Security Incident Special Access [sn_si.special_access] role. Use this role to modify the Read access field in the security incident form. This role is assignable by sn_si.admin.sn\_si.special\_access\_enabler
Security Incident Special Access Writer Manager \[sn\_si.special\_access\_write\_manager\]Manage the Security Incident Special Access [sn_si.special_access] role. Use this role to modify the Privileged access field in the security incident form. This role is assignable by sn_si.admin.sn\_si.special\_access\_enabler
Secops Setup Assistant Administrator\[sn\_secops\_setup.admin\]Full control over Setup Assistant configuration. This role is required to access the Setup Assistant UI and related REST endpoints.N/A

Scheduled jobs installed

Scheduled jobDescription
Lookup Security Incident ObservablesPerforms a lookup for observables on a user-defined schedule.

Tables installed

TableDescription
News Feed Configuration\[sn\_si\_feed\_configuration\]Configuration records used to define the content displayed in the security incident news feed.
Post Incident Review Assignment Rule\[sn\_si\_pir\_condition\]Automates selection of participants of a post incident review survey when a security incident is closed.
Security Incident\[sn\_si\_incident\]Stores a security incident, the responses to the incident, all linked tasks, changes, problems, and incidents related to this security incident.
Security Incident Attack Vectors\[sn\_si\_attack\_vector\]Attack vector options.
Security Incident Audit Log\[sn\_si\_audit\_log\]Stores security incident enrichment audit logs.
Security Incident Calculator\[sn\_si\_calculator\]A calculator to set certain security incident fields when certain conditions are met.
Security Incident Calculator Group\[sn\_si\_calculator\_group\]A grouping of security incident calculators. The order of the calculator group determines which group is evaluated first, and in each group, one calculator at most is used.
Security Incident Enrichment Firewall\[sn\_si\_enrichment\_firewall\]Extends from the base table \(sn\_sec\_cmn\_enrichment\_data\_base\) and includes all enrichment records specific to Palo Alto Networks Firewall.
Security Incident Enrichment Malware Results\[sn\_si\_enrichment\_malware\]Extends from the base table \(sn\_sec\_cmn\_enrichment\_data\_base\) and includes all enrichment records specific to malware.
Security Incident Enrichment Network Statistics\[sn\_si\_enrichment\_network\_statistics\]Extends from the base table \(sn\_sec\_cmn\_enrichment\_data\_base\) and includes all enrichment records specific to network statistics.
Security Incident Enrichment Running Processes\[sn\_si\_enrichment\_running \_processes\]Extends from the base table \(sn\_sec\_cmn\_enrichment\_data\_base\) and includes all enrichment records specific to running processes.
Security Incident Enrichment Running Services\[sn\_si\_enrichment\_running\_service\]Extends from the base table \(sn\_sec\_cmn\_enrichment\_data\_base\) and includes all enrichment records specific to running services.
Security Incident Email Search\[sn\_si\_m2m\_incident\_email\_search\]Maps email search records to security incidents.
Security Incident Import\[sn\_si\_incident\_import\]Import table for security incidents. Used to create security incidents from external systems.
Security Incident Process Definition\[sn\_si\_process\_definition\]Stores configuration for Security Incident process flows.
Security Incident Process Definition Selector\[sn\_si\_process\_definition\_selector\]Stores the Security Incident Process Definition to use for security incidents.
Security Incident Related Customer Service Case\[sn\_si\_m2m\_incident\_customerservice\_case\]Maps customer service cases and security incidents
Security Incident Related Enrichment Data\[sn\_si\_m2m\_incident\_enrichment\]Maps security incidents and related enrichment data records.
Security Incident Response Task\[sn\_si\_task\]Manages subtasks related to handling a security incident. These tasks can be assigned to security personnel, or to people in other departments, to manage interdepartmental communication and task tracking.
Security Incident Response Task Template\[sn\_si\_task\_template\]Used to create a Security Incident Response task. These templates are often used in catalog entries, to automatically create a set of appropriate subtasks for a particular type of security incident.
Security Incident Runbook Document\[sn\_si\_runbook\_document\]Associates security incident conditions or filters with a knowledge article. Used to specify runbook procedures for security incident remediation.
Security Incident Template\[sn\_si\_incident\_template\]Used to create a security incident. These templates are often used in catalog entries to create a prebuilt security incident.
Security Request\[sn\_si\_request\]A security-related request to the security team.
Security Scan Request\[sn\_si\_scan\_request\]A request for a threat lookup.
Severity Calculatorsn\_si\_severity\_calculatorDefines the severity, impact, risk, and criticality values for a security incident.
Task Affected User\[sn\_si\_m2m\_task\_affected\_user\]A many-to-many table associating security incidents with affected users.
Template Workflow Activity Outcome Evaluator \[sn\_si\_wf\_activity\_outcome\_evaluator\]Maps a capability with an evaluation script. A new subflow can be added to a template workflow to set a response task outcome rather than having an analyst manually set it.
Setup Status\[sn\_secops\_setup\_status\]Tracks the completion state of each Setup Assistant step. The key and complete fields are enforced as strict read-only.