Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Incident Spam workflow template

The Security Incident - Spam - Template allows you to perform a series of tasks designed to handle email spam on your network.

Before you begin

Role required: sn_si.write

About this task

The workflow is triggered when the Category in a security incident is set or changed to Spam source. This action causes a response task to be created for the first activity in the workflow.

Image omitted: spam-template.png
Security incident spam workflow template

Procedure

  1. Open the security incident for which you want to handle email spam, or create a new security incident.

  2. In Category, select Spam source.

  3. Save the record.

  4. Scroll down and open the Response Tasks related list.

    The first of a series of response tasks appears. Each time the record is saved, your response to the previous task either causes the next response task to be created or the workflow to end.

Response taskActionResults
Spam contains malicious content?Determine whether the spam contains malicious software. In the task, select Yes or No in Outcome.If you selected Yes, the following response tasks are executed:- Quarantine email message - Create malicious software incident If you selected No, the Update email software is executed.
Create malicious software incidentPerform the steps to create a security incident, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, this response task waits until the next three response tasks have been completed. The state of the security incident then transitions to Review.
Quarantine email messagePerform the steps to quarantine the spam, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed.
Block source on firewallPerform the steps to block the email address on the firewall, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed.
Update email softwareAdd the email address to your block list, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed. Note: This response task is also executed if you answered No to the Spam contains malicious content? response task.
Set state to reviewNo action required.The State of the security incident is automatically changed to Review.

Parent Topic:Security Incident Response workflow templates

Related topics

Security Incident Confidential Data Exposure workflow template

Security Incident Denial of Service workflow template

Security Incident Lost Equipment workflow template

Security Incident Malicious Software workflow template

Security Incident Phishing workflow template

Security Incident Policy Violation workflow template

Security Incident Reconnaissance workflow template

Security Incident Rogue Server or Service workflow template

Security Incident Unauthorized Access workflow template

Security Incident Web/BBS Defacement workflow template