---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Update information in security incident related records

# Update information in security incident related records {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.

## Before you begin

Limitations:

* You can't modify fields that are restricted by an access control list.
* Fields updated or added by system such as Updated aren't supported for inline editing.
{#edit-related-records-in-list__ul_kxs_2x4_chc}

Role required: sn_si.analyst

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open a security incident.
3. Select the Related Records tab.
4. Open the related records tab for which you want to update information.  
   For example, to update the associated observables records of a security incident, you would select Threat Intel and then select Associated Observables.
5. Select the fields to update.
6. Update the values of the fields.
**Related concepts**   

* [Security Incident Overview section](https://servicenow-prod.fluidtopics.net/6yceUsy~r3iSEJ7DTJLzqw "The Overview section on the workspace presents the key information associated with the security incident.")
* [Security Incident Details section](https://servicenow-prod.fluidtopics.net/0t4Cl0AJwylqeTkve~aFiA "This section displays the security incident form fields that are rendered from the security incident classic UI.")
* [SIR Workspace Orchestration](https://servicenow-prod.fluidtopics.net/X7nsvDJeYY1Bnu338I1MIg "Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.")
* [Security Incident Response Tasks](https://servicenow-prod.fluidtopics.net/kQkQaQKkHJA88mCNui7JdA "All the response tasks associated with a security incident are displayed within the Response Tasks section.")
* [Security Incident Response Other Records](https://servicenow-prod.fluidtopics.net/Bcb9H3wXk8iGqp6PMiXWwQ#security-incident-response-other-records "This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.")
* [Security Incident Response Post Incident Review](https://servicenow-prod.fluidtopics.net/sMFZi8oFyMaTZougxKKaGQ "Post incident review appears when an incident is moved to a Review state.")
* [TISC integration within SIR Workspace](https://servicenow-prod.fluidtopics.net/QzgG5SDXAgV~kQZJg_WphA "The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.")
* [Reports in Security Incident Response](https://servicenow-prod.fluidtopics.net/tBOHHBL3DC9OGClj19ClBA "All the reports associated with a security incident are available within the Reports section for analysis and sharing.")
* [Collaborate using conference call or chat in Security Incident Response](https://servicenow-prod.fluidtopics.net/OrJI18mS_ktHmjCOgaEq0Q "You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.")
* [Viewing incident details with a relationship graph](https://servicenow-prod.fluidtopics.net/ajJ36vkdUXiqndCfWCZsxw "Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.")
* [MITRE attack and defend technique graph](https://servicenow-prod.fluidtopics.net/0~ugWC09RlWCb3fzktbYSA "The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.")  
**Related tasks**   

* [View and filter the incident timeline](https://servicenow-prod.fluidtopics.net/3B4vOJllZEBtYa29ohM7tg "View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.")

*[\>]: and then


