---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure Linked Records in Major Security Incident Management

# Configure Linked Records in Major Security Incident Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use Linked Records Configuration to store the information of task tables that can be
used to link/promote/propose to Major Security Incident.
Role required: admin and sn_msi.workspace_admin.  
Note:  
Admin can create the record and MSIM workspace admin can update the record.  
Procedure

1. Navigate to Major Security Incident ManagementLinked Record Configurations.

   The Linked Record Configuration page displays.
   Figure 1. Linked Record Configuration
2. On the Linked Record Configuration page, click New  
   Note:  
   Ensure that the application is in Major Security Incident Management scope.

3. On the record configuration form, fill in the fields.{#configuring-linked-records-in-major-security-incident-management__table_swd_yks_h5b__entry__2}

   | Field | Description |
   |-|-|
   | Source Table | Indicates the task table that must be linked and rolled up to Major Security Incident. |
   | Order | Allows you to control the order of the current source table in MSIM workspace drop-down. Below is an example of the order. Refer to image 1 below, which is provided after this table. |
   | Model ListView | Select a view which can control the list layout that is shown in the Linked Record Modal List. |
   | Can Promote to MSI | Select this check box to confirm whether the record is a primary record. Below is an example of Can Promote to MSI option selection. Refer to the following image 2, which is provided after this table. If this check box is selected and the value is true, then: * you can directly propose and promote a source record to Major Security Incident using the classic environment actions with additional configurations. * you can link source records to major security incidents both from the classic environment and MSIM workspace. * Major Security Incident Management workspace linked record page displays the linked source table records. {#configuring-linked-records-in-major-security-incident-management__ul_cdz_xps_h5b} Note: If a record can be directly proposed/promoted as a Major Security Incident, then that record is a primary record. For example, in the Security Response task table configuration, the value of Can Promote to MSI is false as you can't directly promote Security Response task to Major Security Incident. Hence, it does not show up in the MSIM workspace linked record tab drop-down list. |
   | MSI Field Mapping | Write a script to map the source record fields to a newly created major security incident when the source tables record is in the process of being proposed or promoted. This script executes only when Can Promote to MSI value is true. |
   [Table 1. Linked Records Field Descriptions]

   {#configuring-linked-records-in-major-security-incident-management__table_swd_yks_h5b} Figure 2. Image 1: Linked Records list view order Figure 3. Image 2: Can Promote to MSI
{#configuring-linked-records-in-major-security-incident-management__ol_pry_3ws_h5b}
**Related concepts**   

* [Configure Rollup Records in Major Security Incident Management](https://servicenow-prod.fluidtopics.net/9eu8e6Eam7vQOe4fzwglrQ "Configure Roll up records in Major Security Incident Management to control the information, which will be rolled up when the source record is linked/proposed/promoted as Major Security Incidents.")
* [Configure List Layout in Major Security Incident Management](https://servicenow-prod.fluidtopics.net/xQN9l~z~JkKN8cPgqDDKBw "Configure list layout to customize the layout and labels used in Major Security Incident Management workspace such as Incident Impact, Linked Records, and Threat Intelligence tabs.")
* [Rollup example use case implementation for a Security Case](https://servicenow-prod.fluidtopics.net/3UAb9GHfMcTZxPwGU~hMWg "The following steps explain an example use case on how to add support to link/propose/promote to Major Security Incident for a Security Case table.")
* [Perform on demand atomic rollup](https://servicenow-prod.fluidtopics.net/Ot5f8sN78VS7PvaJM5joDg "Rollup framework cannot handle updates to the existing linked records. In such cases, on demand atomic rollup should happen for linked records, which can be achieved via business rules.")

*[\>]: and then


