Product documentation Docs
    • English
    • Deutsch
    • 日本語
    • 한국어
    • Français
  • More Sites
    • Now Community
    • Developer Site
    • Knowledge Base
    • Product Information
    • ServiceNow.com
    • Training
    • Customer Success Center
    • ServiceNow Support Videos
  • Log in

Product documentation

  • Home
How search works:
  • Punctuation and capital letters are ignored
  • Special characters like underscores (_) are removed
  • Known synonyms are applied
  • The most relevant topics (based on weighting and matching to search terms) are listed first in search results
Topics are ranked in search results by how closely they match your search terms
  • A match on the entire phrase you typed
  • A match on part of the phrase you typed
  • A match on ALL of the terms in the phrase you typed
  • A match on ANY of the terms in the phrase you typed

Note: Matches in titles are always highly ranked.

  • Release version
    Table of Contents
    • Security Operations
Table of Contents
Choose your release version
    Home New York Security Incident Management Security Operations Security Incident Response Managing security incidents and inbound requests Manage post incident activities Configure an assessment trigger condition

    Configure an assessment trigger condition

    • Save as PDF Selected topic Topic & subtopics All topics in contents
    • Unsubscribe Log in to subscribe to topics and get notified when content changes.
    • Share this page

    Configure an assessment trigger condition

    Define rule conditions and generate mandatory and optional assessments for specific security incidents.

    Before you begin

    Role required: sn_si.admin

    Note: To use the Post Incident Review Assessment Trigger Conditions feature, you must upgrade to Security Incident Response 11.0. Before upgrading, you must revert any customizations done to the Post Incident Review Metric type and trigger conditions. In addition, you may also have to revert the customizations done to the business rules specific to the post incident review.
    • Require assessments to be complete
    • Store assignee

    Procedure

    1. Navigate to Security Incident > Administration > Post Incident Review Setup.
    2. In the Assessment Trigger Conditions Configure section, click Configure.
      Note: On the Assessment Trigger Configuration form, in the Assessments Configurations section, the Generate Assessments check box is selected by default.
      • When you select the check box, an optional assessment is created for every security incident.
      • When you deselect the check box, the assessments are not generated. The assessment rules are not displayed and you cannot configure conditions for the security incidents.
    3. On the Assessment Trigger Configuration form, in the Conditions section, specify the required information.
      1. Click Insert a new row.
      2. In the Name field, specify the rule name.
      3. In the Fulfilment field, specify the fulfilment type.
      4. To configure a condition, click the rule record and define conditions in the Condition field.
        Note:
        • If you create a rule without defining a condition in the Condition field, then the condition is evaluated as true and the rule is applicable for all security incidents.
        • You can define a specific rule to make the assessments either mandatory or optional, and the assessments are not generated for the remaining security incidents which don't match the defined rules.

        Trigger conditions

        Figure 1. Trigger conditions

        This image describes the assessment trigger conditions.

    Assessment trigger conditions examples

    The following examples provide different scenarios on how mandatory and optional assessment trigger conditions are generated.

    • On the Assessment Trigger Condition form, generate mandatory assessments when the Priority and Business Impact for a security incident is set to Critical on the Assessment Trigger Rule page. In such scenario, the security analysts cannot close the incident until the mandatory assessments are completed.
      Figure 2. Mandatory assessment example

      This image describes the post incident review mandatory assessment.
      • As you can see, in this example, If a security incident is in a Review state, security analysts cannot close the security incident without completing the Post Incident Review Assessment. An assessment link is available to take the assessment to the security analysts who are assigned (or who had requested for the assessment) to the incident.
    • On the Assessment Trigger Condition form, generate optional assessments when the Priority and Business Impact for a security incident is set to High. In this example, if the security analysts do not complete the assessments and close the security incident, the assessments are automatically canceled.
    • In case, if the mandatory or optional assessments does not match the security incident, assessments are not generated for such security incidents. A security analyst can close the security incident without completing the Post Incident Review assessment.

    Tags:

    Feedback
    On this page

    Previous topic

    Next topic

    • Contact Us
    • Careers
    • Terms of Use
    • Privacy Statement
    • Sitemap
    • © ServiceNow. All rights reserved.

    Release version
    Choose your release version

      Configure an assessment trigger condition

      • Save as PDF Selected topic Topic & subtopics All topics in contents
      • Unsubscribe Log in to subscribe to topics and get notified when content changes.
      • Share this page

      Configure an assessment trigger condition

      Define rule conditions and generate mandatory and optional assessments for specific security incidents.

      Before you begin

      Role required: sn_si.admin

      Note: To use the Post Incident Review Assessment Trigger Conditions feature, you must upgrade to Security Incident Response 11.0. Before upgrading, you must revert any customizations done to the Post Incident Review Metric type and trigger conditions. In addition, you may also have to revert the customizations done to the business rules specific to the post incident review.
      • Require assessments to be complete
      • Store assignee

      Procedure

      1. Navigate to Security Incident > Administration > Post Incident Review Setup.
      2. In the Assessment Trigger Conditions Configure section, click Configure.
        Note: On the Assessment Trigger Configuration form, in the Assessments Configurations section, the Generate Assessments check box is selected by default.
        • When you select the check box, an optional assessment is created for every security incident.
        • When you deselect the check box, the assessments are not generated. The assessment rules are not displayed and you cannot configure conditions for the security incidents.
      3. On the Assessment Trigger Configuration form, in the Conditions section, specify the required information.
        1. Click Insert a new row.
        2. In the Name field, specify the rule name.
        3. In the Fulfilment field, specify the fulfilment type.
        4. To configure a condition, click the rule record and define conditions in the Condition field.
          Note:
          • If you create a rule without defining a condition in the Condition field, then the condition is evaluated as true and the rule is applicable for all security incidents.
          • You can define a specific rule to make the assessments either mandatory or optional, and the assessments are not generated for the remaining security incidents which don't match the defined rules.

          Trigger conditions

          Figure 1. Trigger conditions

          This image describes the assessment trigger conditions.

      Assessment trigger conditions examples

      The following examples provide different scenarios on how mandatory and optional assessment trigger conditions are generated.

      • On the Assessment Trigger Condition form, generate mandatory assessments when the Priority and Business Impact for a security incident is set to Critical on the Assessment Trigger Rule page. In such scenario, the security analysts cannot close the incident until the mandatory assessments are completed.
        Figure 2. Mandatory assessment example

        This image describes the post incident review mandatory assessment.
        • As you can see, in this example, If a security incident is in a Review state, security analysts cannot close the security incident without completing the Post Incident Review Assessment. An assessment link is available to take the assessment to the security analysts who are assigned (or who had requested for the assessment) to the incident.
      • On the Assessment Trigger Condition form, generate optional assessments when the Priority and Business Impact for a security incident is set to High. In this example, if the security analysts do not complete the assessments and close the security incident, the assessments are automatically canceled.
      • In case, if the mandatory or optional assessments does not match the security incident, assessments are not generated for such security incidents. A security analyst can close the security incident without completing the Post Incident Review assessment.

      Tags:

      Feedback

          Share this page

          Got it! Feel free to add a comment
          To share your product suggestions, visit the Idea Portal.
          Please let us know how to improve this content

          Check any that apply

          To share your product suggestions, visit the Idea Portal.
          Confirm

          We were unable to find "Coaching" in Jakarta. Would you like to search instead?

          No Yes
          • Contact Us
          • Careers
          • Terms of Use
          • Privacy Statement
          • Sitemap
          • © ServiceNow. All rights reserved.

          Subscribe Subscribed Unsubscribe Last updated: Tags: January February March April May June July August September October November December No Results Found Versions Search preferences successfully updated My release version successfully updated My release version successfully deleted An error has occurred. Please try again later. You have been unsubscribed from all topics. You are now subscribed to and will receive notifications if any changes are made to this page. You have been unsubscribed from this content Thank you for your feedback. Form temporarily unavailable. Please try again or contact  docfeedback@servicenow.com  to submit your comments. The topic you requested does not exist in the release. You were redirected to a related topic instead. The available release versions for this topic are listed There is no specific version for this documentation. Explore products Click to go to the page. Release notes and upgrades Click to open the dropdown menu. Delete Remove No selected version Reset This field is required You are already subscribed to this topic Attach screenshot The file you uploaded exceeds the allowed file size of 20MB. Please try again with a smaller file. Please complete the reCAPTCHA step to attach a screenshot
          Log in to personalize your search results and subscribe to topics
          No, thanks Login