---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SIR Workspace plugins

# SIR Workspace plugins {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.

## Applications {#components-installed-with-analyst-workspace__section_pkm_hvz_v5b}

Installing the Security Incident Response application version 13.4.5 or later automatically installs the Security Incident Response Workspace and the following apps.

* Enterprise Security Case Management PAD Commons \[sn_escm_pad_cmn\]
* Security Operations Common Workspace \[sn_escm_ws_cmn\]
* Security Incident UI Card Component \[sn_sirw_evam\]
* Security Operations spoke \[sn_sec_spoke\]
{#components-installed-with-analyst-workspace__ul_klk_nh3_kyb}  
Important:  
* Installing the Security Incident Response 13.4.5 version or later from the ServiceNow Store automatically installs the Security Incident Response Workspace (sn_si_aw) 1.5.1 version or later by default.
* The Security Incident Response Workspace versions 1.5.1 and above can only be installed/upgraded through an installation/upgradation of Security Incident Response and can't be installed independently.
{#components-installed-with-analyst-workspace__ul_ipb_3mz_dcc}

Enterprise Security Case Management PAD Commons requires the
Playbook Experience \[playbook_experience\] plugin.

For information on the Security Incident Response roles, tables, properties, and scheduled jobs, see [Components installed with Security Incident Response](https://servicenow-prod.fluidtopics.net/Ggj2k2A3Ycyj_BpBcgz1tA "Several types of components are installed when you download and activate the Security Incident Response application, including plugin dependencies, user roles, tables, properties, and scheduled jobs.").
**Related concepts**   

* [SIR Workspace features](https://servicenow-prod.fluidtopics.net/8RpOO~NHgmEKOvLelppoQA "The Security Incident Response Workspace consists of the following key features.")
* [SIR Workspace interface overview](https://servicenow-prod.fluidtopics.net/~TZjXfpt806pAVTxJdvewA "The SIR Workspace Overview page consists of the Security Incidents and Response Tasks details that are under security analysts and their team.")
* [Upcoming section](https://servicenow-prod.fluidtopics.net/PYIvFKoYWjA3UhvVIOAXZA "This section displays the upcoming tasks such as the security incidents and response tasks that are due as on the same day and next day.")
* [Quick links section](https://servicenow-prod.fluidtopics.net/94_97N0fwDf7ASqbiWHc2A "Quick links work like bookmark links. You can add external URLs and quickly access them from within the workspace.")
* [Shift Handover Records section](https://servicenow-prod.fluidtopics.net/UXY0oW6ISmUwjCVrPnl48g "The section displays the list of Shift Handover records in the Security Incident Response Workspace.")
* [List view in SIR Workspace](https://servicenow-prod.fluidtopics.net/bStXEweV_IdnZ_UD5B0G9g "The list view consists of the security incidents, response tasks, phishing emails, and assessments.")

