---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure SI design time investigation

# Configure SI design time investigation {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use this section to configure security incident design time investigation page to add
multiple entry points and its associated records within the Security Incident Response Workspace.
Role required: sn_si.admin.  
The following details the steps involved in configuring the investigation page on the Security Incident Response Workspace.

* [Creating View for associated info tables](https://servicenow-prod.fluidtopics.net/jFJN7fDKNVBEQMQyRWGP9g "The investigation screen leverages the related list views created on security incident to configure associated lists.")
* [Adding an entry point list](https://servicenow-prod.fluidtopics.net/jV4hK5PxDo97B_KGW4X62w "Configure the new entry point list to add it to the investigation page.")
* [Mapping View of the Associate Info to the entry point list](https://servicenow-prod.fluidtopics.net/jWGUoUBbdhMNV_swNxSHeg "Map the associated info view to the newly added entry point list using the Map Associated Info View action.")
* [Configure each associated list from the view to handle run time data rendering](https://servicenow-prod.fluidtopics.net/VuO_fUzy0JPzARAs_z6xEA "Configure each associated list from the view to handle run time data rendering.")
{#configure-investigation-canvas-records__ul_nw2_cqn_dwb}
* **[Creating View for associated info tables](https://servicenow-prod.fluidtopics.net/jFJN7fDKNVBEQMQyRWGP9g)**   
  The investigation screen leverages the related list views created on security incident to configure associated lists.
* **[Adding an entry point list](https://servicenow-prod.fluidtopics.net/jV4hK5PxDo97B_KGW4X62w)**   
  Configure the new entry point list to add it to the investigation page.
* **[Mapping View of the Associate Info to the entry point list](https://servicenow-prod.fluidtopics.net/jWGUoUBbdhMNV_swNxSHeg)**   
  Map the associated info view to the newly added entry point list using the Map Associated Info View action.
* **[Configure each associated list from the view to handle run time data rendering](https://servicenow-prod.fluidtopics.net/VuO_fUzy0JPzARAs_z6xEA)**   
  Configure each associated list from the view to handle run time data rendering.

**Related concepts**   

* [Set up view of SIR Records](https://servicenow-prod.fluidtopics.net/p99YPRJHUz3SrQBoAXW8UA "This section describes how the related lists are grouped and presented on the SIR Related Records tab for easy navigation.")
* [SIR Workspace Related Records](https://servicenow-prod.fluidtopics.net/gsDO~PbQk8zzmwnZXCwg6Q#sir-records "This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.")
* [Configure Shift Handover](https://servicenow-prod.fluidtopics.net/Q04QzNU1caN3mjs4rEUNGg "Configure Shift Handover settings to provide complete shift information to the next shift analysts.")
* [Security Incident Response conference call integration](https://servicenow-prod.fluidtopics.net/88P4jTtlgisR6XEYl1fsMA "The Security Incident Response Conference Call integration enables you to manage and initiate conference call and chat for analysts, managers and affected users.")
* [Configure report templates in Security Incident Response](https://servicenow-prod.fluidtopics.net/VKFCEyFnJHSOxoVttZW0gg "You can create report templates that can be used to generate an incident summary or an executive summary for analysis and sharing.")
* [On-Call scheduling in Security Incident Response](https://servicenow-prod.fluidtopics.net/sPKhH7CGbUOINSD8C3fVaQ "Use On-Call Scheduling in Security Incident Response to view and manage shifts for your analysts.")
* [Category management in Security Incident Response](https://servicenow-prod.fluidtopics.net/zKvvJ~woONAARtQWDnLzkQ "Configure security incident categories and subcategories for granular classification of incidents, which helps you accurately route security incidents.")
* [View and update Security Incident Response system properties](https://servicenow-prod.fluidtopics.net/dQgedytB1~M7u70FoX9_oA "View and update the Security Incident Response Workspace system properties from the Security Incident Response Workspace administration panel to access and update the required properties.")
* [Timeline in Security Incident Response Workspace](https://servicenow-prod.fluidtopics.net/U3c3lwBFolisJEn2MEJSmg "The timeline provides a chronological view of events related to a security incident. Events appear as point events or range events. Administrators can configure which events appear on the timeline and what details are shown in event popovers.")
* [Explore Investigation Canvas](https://servicenow-prod.fluidtopics.net/3Mx~XCZXw7LsX0QFKRP_eg "The primary objective of the investigation canvas is to present the necessary security incident data in one common place.")  
**Related tasks**   

* [Define the new Risk Score Calculator Rules](https://servicenow-prod.fluidtopics.net/ccv9hx8vlS4KWyZ44meslQ "Use the new Risk Score Calculator to define and calculate the risk score of security incidents based on the user-defined criteria, which provide a transparent intelligence scoring of security incidents. The risk score is auto-calculated for the security incident records.")
* [Create quick filters for Security Incidents and Response Tasks lists](https://servicenow-prod.fluidtopics.net/SzkWp6I2kcU8DCTa3RrrTw "Create quick filters to create reusable, predefined filters that appear on the security incidents and response tasks list pages enabling security analysts to filter the list items without adding the filter conditions each time.")

