---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create and distribute MSIM Status Reports

# Create and distribute MSIM Status Reports {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

As a Major Security Incident (MSI) manager, you can create and distribute the different status reports to different stakeholders at various intervals based on the configured report template or a previous status report throughout
the course of the major security incident resolution.

## Before you begin

Role required: sn_msi.workspace_manager

You can preview the previously configured summary report data elements, add
additional text or summary, remove individual report components as needed, and
verify the accuracy and completeness of the report before distributing it to
different stakeholders.

Create the status reports by selecting the desired report template that was initially
configured on the MSI Report Templates Setup page.

## Procedure

1. Navigate to WorkspacesMajor Security Incident ManagementMajor Security Incidents.
2. Select the Lists view.
3. Select the respective promoted MSI record.
4. Select the Status Reports tab.  
   The Status Reports tab contains three different types of subsections such as below.{#creating-and-distributing-major-security-incident-status-reports__table_v3s_4cq_d1c__entry__2}

   | Field | Description |
   |-|-|
   | Report Name | Name of the status report template. Note: The Status Reports view lists the existing predefined report templates that are available as a part of the base system for the concerned persona. For example, Executive Status Reports through email (Mobile-friendly), Technical Status Reports and Executive Status Reports as PDFs. |
   | Updated | The date when the report template was last updated. |
   | Report Type | Type of status report. The status report can be in one of the following types: * PDF * Email {#creating-and-distributing-major-security-incident-status-reports__ul_qrh_mgq_d1c} |
   | State | State of the status reports. The status reports can be in one of the following states: * Draft * Queued * Published {#creating-and-distributing-major-security-incident-status-reports__ul_xvp_q2q_d1c} |
   [ ]

   {#creating-and-distributing-major-security-incident-status-reports__table_v3s_4cq_d1c}
5. Select the type of the status report that you would want to view or select New to create a status report.  
   Figure 1. MSIM Status Reports tab
6. Choose one of the following status report types from the list.  
   * Executive Email Status Reports that are mobile-friendly.
   * Technical Status Report PDF
   * Executive Status Report PDF

   {#creating-and-distributing-major-security-incident-status-reports__ul_qb5_n3q_d1c}  
   Note:  
   When you select any desired report template, the preview of the selected report is immediately generated in the right-pane. You can view the selected status report of the MSI.
7. On the Executive Email Status Report template, fill the sections with the details of the status report.

   | Report section | Description |
   | Updates | Provide a summary of the status update. This section contains the following: * MSI Summary: Provide a brief summary of the major security incident. * Append text from last report shared: Select this option to append the text from the last report shared. {#creating-and-distributing-major-security-incident-status-reports__ul_znm_skq_d1c} |
   | Explanation | Add an explanation on what has changed since the last status update was done. This section contains the following: * Key updates: Provide key updates like what the security team should know about the major security incident, name the key events that took place, and list any pending actions. * Next Update: Provide the date and time of the next update for resolving the major security incident. For example, 5:00 pm EST on March 25th, 2024. * Append text from last report shared: Select this option to append the text from the last report shared. * Filter elements: Select the report elements to be included in the report. For example, Key Updates or Next Updates. {#creating-and-distributing-major-security-incident-status-reports__ul_sp5_wqz_21c} |
   | Additional Information | Provide specific details relevant to the status update. |
   | Visualizations | Select the visualizations that best help communicate the status update. * Incident Impact: Select the Incident Impact metrics like Affected Assets, Affected Location, Affected Users that are related to the status update. * Filter elements: Select the report elements to be included in the report. For example, Incident Impact. {#creating-and-distributing-major-security-incident-status-reports__ul_tmg_rtz_21c} |
   | Lists | Select lists of records that provide context to the status update. * Linked records: Select the records that are linked to the major security incident status update. For example, Linked Security Incident. * Filter elements: Select the report elements to be included in the report. For example, Linked records. {#creating-and-distributing-major-security-incident-status-reports__ul_rt1_stz_21c} |
   |-|-|

   {#creating-and-distributing-major-security-incident-status-reports__choicetable_lfv_mkq_d1c}  
   Note:  
   The options that you've selected from the Status Reports section are the same options that are rendered in the Preview report.  
   Figure 2. Status Report Template
8. Select Save to save the updates you made to the status report.
9. Select Share to share the status report with internal and external stakeholders.  
   The Share dialog box appears. Fill in the fields in the dialog box:{#creating-and-distributing-major-security-incident-status-reports__table_ppn_bnj_k3c__entry__2}

   | Field | Description |
   |-|-|
   | Subject | Subject for the email report. |
   | To, Cc, Bcc | Fields to add the email recipients. Emails can be added using one or more of the following: * Select individual users or groups from drop-down lists. * Manually enter email addresses into any of the recipient field. * Copy and paste multiple comma-separated or semicolon-separated email addresses. * Copy and paste existing distribution lists. {#creating-and-distributing-major-security-incident-status-reports__ul_z34_snj_k3c} Note: Recipient fields (To, Cc, and Bcc) are automatically populated with recipients from the most recently sent status report using the same template, eliminating the need to add recipients for recurring status report communications. |
   | Remove Invalid Recipients | Option to remove all the invalid email addresses. This field appears only when there are invalid email addresses in a recipient field. Note: Invalid email addresses are highlighted with an error icon. |
   | Clear ALL Recipients | Option to clear the all the recipients fields simultaneously. This field is enabled only when there is at least one email address in any of the recipient fields. |
   | Body | Body of the email message. |
   [Table 1. Share form table]

   {#creating-and-distributing-major-security-incident-status-reports__table_ppn_bnj_k3c}
10. Select Email Report.  
    An email with the attached PDF Status Report is successfully sent to the concerned recipient for them to verify.Figure 3. Status Report - email
11. You can also perform the following actions on the Status Reports tab:
    1. Use the Refresh action on the Status Reports view to refresh the status reports list.
    2. Use the List Actions action on the Status Reports view to edit columns or reset the widths of the status reports list.
    3. Use the Filter action on the Status Reports view to filter the status reports based on certain conditions.
    {#creating-and-distributing-major-security-incident-status-reports__substeps_kxh_wgr_d1c}
**Related concepts**   

* [Propose, promote, and link incident records](https://servicenow-prod.fluidtopics.net/sk9rqHFZOINPE0X~1U5vMg "Propose or promote security incidents as major security incidents when incidents are identified as critical threat to the organization.")
* [View Major Security Incident impact metrics](https://servicenow-prod.fluidtopics.net/3KBNBqRoz_BkHzUxpjZhkg "Provides up-to-date summary reporting of the impact and progress of major security incidents, which is an important aspect of managing a major security incident using the new workspace.")
* [View Major Security Incident trend charts](https://servicenow-prod.fluidtopics.net/i9L9Hku8t6K3KLufujwM_Q "View the major security incident impact progress metrics visualized as bar graphs and charts.")
* [Update Major Security Incident details](https://servicenow-prod.fluidtopics.net/b07ElfZGURoZjC6mrNQUPg "View and update specific details related to the major security incident such as Incident Record Details, Active Team participants, and the corresponding activity log.")
* [Manage tasks in a Major Security Incident](https://servicenow-prod.fluidtopics.net/Yru0dCGME5pKnCMaKxhciw "The Task tab enables you to track and manage all the tasks associated with a major security incident from the MSIM workspace. You can view the various tasks using the default Visual Task Board (Kanban view) or the List view.")
* [Track collaboration activity via MSIM workspace](https://servicenow-prod.fluidtopics.net/oN75Hkl13nFA0yi30ej7pw#collab-tab "Track chat and file activities related to resolving major security incidents through the MSIM Workspace.")
* [Configure Major Security Incident status reports](https://servicenow-prod.fluidtopics.net/DqCd38vS8avbjUjUZin85w "Configure major security incident reports to set up and download the reports according to your business needs throughout the life cycle of the major security incident record remediation process.")  
**Related tasks**   

* [Using MSI List view in the MSIM workspace](https://servicenow-prod.fluidtopics.net/KCnBshkJxFxNQC_44tHI8g "With the list view in the MSIM workspace, you can view proposed, promoted, and rejected major security incidents.")
* [Link additional records to Major Security Incident](https://servicenow-prod.fluidtopics.net/_LFdjo1aOyMiYBIDPKWA7Q "In the workspace, use the linking records functionality to link any related Security Incident records and its child security incidents, Remediation Tasks from Vulnerability Response, and Security Cases from Threat Intelligence to a Major Security Incident (MSI) record.")
* [Unlink records from Major Security Incident](https://servicenow-prod.fluidtopics.net/T0_CeewhEttOZPLLg8B4Ww "Using the Major Security Incident Management workspace, unlink the major security incident records from the Linked Records section.")

*[\>]: and then


