CIS-SIR · ● Active · Professional · ServiceNow
Exam facts
| Field | Value |
|---|---|
| Cost | $450 USD |
| Duration | 90 minutes |
| Questions | 60 |
| Passing | 70% |
| Format | Multiple choice |
| Delivery | SkillJar (ServiceNow testing platform) |
| Languages | English |
| Valid | 3 years |
| Renewal | Retake exam or pass higher-level cert |
| Prerequisites | CSA (Certified System Administrator) + Security Operations Implementation course |
| Released | 2022 (updated 2024–2025) |
| Retiring | N/A |
Vendor source — ServiceNow Security Operations ↗
Official exam guide — CIS-SIR Exam Blueprint ↗
Learning path — ServiceNow Now Learning — CIS-SIR ↗
About
The CIS-SIR certifies practical expertise in configuring and implementing ServiceNow's Security Incident Response solution within enterprise SOCs. Candidates demonstrate proficiency in incident creation, classification, threat scoring, evidence capture, task assignment, remediation workflows, post-incident analysis, and integration with SIEM, EDR, and threat intelligence platforms. Released in 2022 and updated through 2025, this credential targets security architects, SOC implementation engineers, and security operations consultants who deploy unified incident management across heterogeneous security tool stacks. Requires current CSA (Certified System Administrator) plus completion of the vendor's Security Operations Implementation course before exam eligibility.
Domain context — Security / SOC
Security Operations (SOC) spans incident detection, classification, containment, and remediation within enterprise environments. ServiceNow Security Operations unifies incidents, vulnerabilities, and threat intelligence signals from multiple detection sources (SIEM, EDR, cloud, scanners) into a single system of action, applying business context (CMDB enrichment) and AI-driven prioritisation to reduce dwell time and accelerate response.
Read ecosystem overview — ServiceNow ↗ (file not yet created)
Topics covered
The exam blueprint weights Security Incident Response domains as follows:
- Security Incident Response Lifecycle (20–25%) — Incident creation, classification, severity assignment, threat scoring, enrichment
- Incident Management Workflows (15–20%) — Task routing, assignment, escalation, automation, approval chains, closure
- Evidence & Artifact Handling (10–15%) — Evidence capture, chain of custody, forensic collection, attachment management
- Integration with SIEM / EDR / Threat Intelligence (15–20%) — Inbound integration (ingesting alerts from Splunk, Microsoft Sentinel, CrowdStrike, etc.); outbound orchestration (playbook triggering, containment actions)
- Vulnerability & Configuration Compliance Context (10–15%) — Linking incidents to vulnerability records; CMDB relationships; configuration drift as attack surface
- Post-Incident Analysis & Metrics (10–15%) — Root-cause analysis, lessons-learned capture, KPI reporting (MTTR, dwell time, detection-to-response latency)
- Alert Ingestion & Correlation (5–10%) — Event parsing, deduplication, alert enrichment, false-positive tuning
- Security Orchestration & Response Automation (5–10%) — Workflow automation, API-driven containment, playbook design
Source: ServiceNow CIS-SIR Exam Blueprint ↗
Common skills at Security/SOC · Professional
Shared content for the Security/SOC domain at Professional level — not specific to this cert.
- Incident triage & classification — Assess severity, business impact, and threat actor intent; prioritise response resources
- SIEM / EDR fundamentals — Understand detection signals from Splunk, Sentinel, QRadar, Chronicle, CrowdStrike, Crowdstrike, etc.; interpret alert confidence scores
- Threat intelligence consumption — Track TTPs, IOCs (indicators of compromise), threat actor profiles; map to incident context
- Containment & remediation tactics — Isolate compromised systems, disable credentials, block C2 domains, restore from backups
- CMDB-driven context — Enrich incidents with asset data (owner, criticality, compliance scope, relationships); understand blast radius
- Communication & escalation — Notify stakeholders (CISOs, incident commanders, business owners); coordinate with incident response retainers / law enforcement
- Metrics & reporting — Track MTTR, dwell time, detection latency, analyst efficiency; present risk trends to leadership
Recommended courses at Security/SOC · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| ServiceNow (official) | Security Operations Implementation | Free (requires account) | ↗ |
| ServiceNow (official) | CIS-SIR Learning Path | Free | ↗ |
| Udemy (by ServiceNow partners) | ServiceNow Security Incident Response (CIS-SIR) | $15–$50 | ↗ |
| Pluralsight | ServiceNow Security Operations | $29/month | ↗ |
| A Cloud Guru | ServiceNow SOC Fundamentals | $29–$49/month | ↗ |
Course rule: The ServiceNow Now Learning platform (free with registration) is the official training resource and mandatory before exam attempt. The "Security Operations Implementation" course is a prerequisite; verify completion before scheduling the CIS-SIR exam.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| ServiceNow (official) | Now Learning Practice Exams — CIS-SIR | Free (included in learning path) | ↗ |
| Whizlabs | ServiceNow CIS-SIR Practice Tests | $25–$35 | ↗ |
| ExamTopics | ServiceNow CIS-SIR Community Exam Questions | Free | ↗ |
Note: The official Now Learning platform includes knowledge checks and practice scenarios embedded in the learning path. Third-party vendors (Whizlabs, ExamTopics) provide supplemental problem sets; verify currency against the 2024+ curriculum before purchase.
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| ServiceNow Security Incident Response: Implementation and Operations Guide | Security Incident Response Team (ServiceNow) | ServiceNow Documentation | 2024 | N/A | ↗ |
| The Defender's Advantage: Understanding and Defending Against SOAR and Automation Threats | Lior Div, Avi Chesla | O'Reilly Media | 2023 | 978-1-492-06932-4 | ↗ |
| Incident Response: Investigating and Responding to Cyber Attacks | Paul Asadoorian, Dave Shackleford | Packt Publishing | 2023 | 978-1-80289-783-9 | ↗ |
Book availability note: No dedicated "CIS-SIR Study Guide" workbook is published by ServiceNow or major educational publishers. Recommended texts cover incident response architecture and SOC operations; combine with official Now Learning curriculum for exam prep. ServiceNow's internal documentation on the Security Incident Response module is the primary reference.
Typical job titles at Security/SOC · Professional
ServiceNow SecOps Consultant · Security Operations Engineer (ServiceNow focus) · Incident Response Specialist · SOC Implementation Architect · Security Incident Response Engineer · SOAR/SOC Solutions Architect
(Job titles drawn from LinkedIn, Indeed, and Glassdoor postings that list CIS-SIR or ServiceNow SOC expertise as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $110,000 – $160,000 | Glassdoor (ServiceNow Security Consultant) ↗ · Robert Half (Security Operations) ↗ · 6figr (ServiceNow Consultant) ↗ |
| ZAR | R950,000 – R1,600,000 p.a. | Pnet.co.za ↗ · PayScale ZA ↗ · CareerJunction ↗ |
| GBP | £70,000 – £105,000 | IT Jobs Watch ↗ · Hays Salary Guide ↗ |
| EUR | €85,000 – €135,000 (DE/NL/FR avg.) | PayScale EU ↗ |
| AUD | A$135,000 – A$190,000 | SEEK ↗ · PayScale AU ↗ |
Salary note: Ranges reflect SOC implementation and security consultant roles requiring CIS-SIR or equivalent ServiceNow security expertise. Senior architects and security engineers command premiums (20–30% above listed ranges). GRC and SecOps are where the market demand is in 2026, with security certifications commanding premium rates because demand far outstrips supply; CIS-certified specialists often exceed USD $120k+ for mid-career roles.
Skills validated
Cert-specific — what this exam actually tests, distinct from the shared "Common skills" above.
- ServiceNow Security Incident Response module configuration — Incident forms, tables, task templates, automated routing
- Alert ingestion & event parsing — Configuring inbound integrations from SIEM (Splunk, Microsoft Sentinel, QRadar, Chronicle), EDR (CrowdStrike, Carbon Black), cloud (AWS GuardDuty, Azure Security Center)
- Threat intelligence integration — Enriching incidents with IOC data, threat actor profiles, MITRE ATT&CK mappings via TIP connectors
- Workflow automation & orchestration — Designing playbooks, automating containment actions (credential disable, network isolation, file quarantine), approval chains
- CMDB enrichment for incident context — Linking incidents to configuration items, business services, asset owners, compliance controls
- Evidence & artifact management — Capture chain of custody, forensic file attachments, secure storage, retention policies
- Metrics & KPI reporting — MTTR (mean time to respond), detection-to-response latency, analyst utilisation, incident trends
- SIEM / EDR fundamentals — Understanding detection signal anatomy (severity, confidence, indicator type), alert tuning to reduce noise
- Vulnerability-to-incident correlation — Mapping active vulnerabilities to compromised assets, understanding attack surface exposure
Related certifications
- Prerequisite: ServiceNow Certified System Administrator (CSA) ↗
- Companion cert: CIS-VR (Vulnerability Response) ↗ — Often taken together as a SOC operations stack
- Stacks with: CIS-ITSM (IT Service Management) ↗ · CIS-RC (Risk & Compliance) ↗
- Pathway to: Certified Technical Architect (CTA) ↗ · Certified Master Architect (CMA) ↗
- Vendor overview: ServiceNow Vendor Overview ↗ (file not yet created)
Sources
- ServiceNow Security Operations product page: https://www.servicenow.com/products/security-operations.html
- ServiceNow CIS-SIR Exam Blueprint: https://learning.servicenow.com/lxp/en/credentials/certified-implementation-specialist-security-incidence-response?id=kb_article_view&sysparm_article=KB0011559
- ServiceNow Now Learning — CIS-SIR: https://learning.servicenow.com/lxp/en/pages/now-learning-get-certified?id=amap_detail&achievement_id=908e1d77dbc27f40de3cdb85ca961929
- ServiceNow Security Operations Learning Path: https://learning.servicenow.com/lxp/en/security-operations/security-operations-secops-security-incident-response
- Glassdoor (ServiceNow consultant salary): https://www.glassdoor.com/Salaries/servicenow-consultant-salary-SRCH_KO0,21.htm
- Robert Half Salary Guide: https://www.roberthalf.com/salary-guide
- 6figr (ServiceNow salary data): https://6figr.com/us/salary/servicenow--consultant
- Pnet.co.za (ZAR salary data): https://www.pnet.co.za/
- IT Jobs Watch (GBP roles): https://www.itjobswatch.co.uk/
- Hays Salary Guide: https://www.hays.co.uk/salary-guide
- PayScale (global salary benchmarks): https://www.payscale.com/
- Udemy (ServiceNow CIS-SIR courses): https://www.udemy.com/course/servicenow-cis-security-incident-response/
- ExamTopics (CIS-SIR community questions): https://www.examtopics.com/exams/servicenow/cis-sir/
- Whizlabs (practice exams): https://www.whizlabs.com/
- O'Reilly Media (security incident response): https://www.oreilly.com/
- Packt Publishing (incident response guides): https://www.packtpub.com/
Last verified: 2026-05-01
Parent ecosystem: ServiceNow Platform — in development
Parent domain: Security/SOC (Security Operations Center) — in development
Vendor overview: ServiceNow — in development