---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Major Security Incident Management

# Major Security Incident Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Major Security Incident Management

Major Security Incident Management (MSIM) enhances the existing Security Incident Response capabilities in ServiceNow by enabling security analysts and incident managers to efficiently track and manage activities involved in resolving major security incidents.
It allows escalation from standard security incidents to major incidents, supporting a streamlined remediation process through an intuitive workspace.
Show full answer Show less  
Security analysts can propose, promote, or reject incidents as major security incidents and link related child incidents to ensure comprehensive incident handling.

## Key Features

* **Dedicated Workspace:** Tailored for the Major Security Incident Manager role to effectively manage major security incidents.
* **Child Incident Organization:** Manage and coordinate response tasks across multiple linked child security incidents.
* **Collaboration Automation:** Automatically creates Microsoft Teams chat channels and SharePoint collaboration folders upon major incident creation, with automated archival upon closure.
* **File Explorer Component:** Integrates with Microsoft SharePoint to organize and track artifacts and files related to the major incident.
* **Communication Management:** Chat channel manager and activity stream components facilitate cross-team communication across security, IT, and functional groups using Microsoft Teams integration.

## Workspace Components

The MSIM product includes new user interface elements designed to support the above features, including:

* A dedicated workspace for major security incident management.
* Tools to organize tasks and communications across multiple child incidents.
* Integration with Microsoft Teams and SharePoint for streamlined collaboration and artifact management.

## Supported Versions and Requirements

* MSIM requires ServiceNow AI Platform® Rome release or later.
* Supports Microsoft Teams as part of Microsoft Office 365 for chat and collaboration features.
* Requires installation and activation of standard Security Operations plugins, including Security Incident Response and related dependencies, which are available via the ServiceNow Store.

## Practical Benefits for ServiceNow Customers

Implementing Major Security Incident Management enables security teams to handle complex incidents more effectively by providing:

* A centralized and role-specific workspace for major incident oversight.
* Improved coordination of multiple related incidents ensuring no aspect is overlooked.
* Automated collaboration setup reducing manual overhead during critical incident response times.
* Enhanced communication and artifact tracking through integrations with widely used Microsoft collaboration tools.

This results in faster, coordinated, and more transparent remediation of major security incidents within your ServiceNow environment.  
Track and manage various activities that are typically part of resolving a major security incident through Major Security Incident Management. Through an intuitive workspace, incident managers and those working on an incident can propose and promote incidents to major incidents, track major security incident activities, and easily
collaborate with colleagues.

## Major Security Incident Management Overview {#major-security-incident-management__section_vsn_fzh_z2b}

The major security incident management capabilities work in conjunction with the existing
security incident response product capabilities. This includes an ability for a security analyst
to escalate a standard security incident to a major security incident, so that the new product
capabilities are available to support the remediation process.

After you install on your ServiceNow instance, a security incident
analyst can:

* Propose a security incident to major security incident candidate to initiate a review process on the need to create a major security incident.
* Directly promote a security incident to a major security incident without the need for an additional review process.
* Reject a security incident that is proposed as a major security incident (MSI).
* Link a security incident as a child incident to the major security incident (MSI) so that all security incidents can be worked.
{#major-security-incident-management__ul_d2r_yhz_mpb}

## Key features {#major-security-incident-management__section_dn4_n1z_mfb}

Major Security Incident Management (MSIM) improves the major security incident remediation process with the following features:

* Dedicated workspace for managing major security incidents designed for the major security incident manager user role.
* Organize response tasks across multiple 'child' security incidents.
* Automate creation of collaboration folders and chat communication channels after a major security incident is created, as well as archival as part of incident closure.
* File explorer component to organize and track the collection of artifacts (files) related to the major security incident via a Microsoft SharePoint integration.
* Chat channel manager and activity stream components to manage communications across multiple security, IT, and functional groups via a Microsoft Teams integration.
{#major-security-incident-management__ul_ysz_cjm_wpb}

## Workspace Components {#major-security-incident-management__section_ul2_w1n_ypb}

The Major Security Incident Management product contains several new workspace components and user interface pages that deliver the key features functionality:

* Dedicated workspace for managing major security incidents specifically designed for the major Security Incident Manager user role.
* Organize response tasks across multiple child security incidents.
* Automate creation of collaboration folders and chat communication channels after a major security incident is created, as well as archival as part of incident closure.
* File explorer component to organize and track the collection of artifacts (files) related to the major security incident via a Microsoft SharePoint integration.
* Chat channel manager and activity stream components to manage communications across multiple security, IT, and functional groups via a Microsoft Teams integration.
{#major-security-incident-management__ul_vl2_w1n_ypb}

## Supported Major Security Incident Management versions {#major-security-incident-management__section_j25_1jm_y2b}

Major Security Incident Management (MSIM) requires ServiceNow AI Platform® Rome version.

This feature supports Microsoft Teams, which is a chat-centered workspace in the Microsoft Office 365 suite. Earlier Microsoft Teams was a separate installation from Microsoft Office 365 applications.

## Supported ServiceNow AI Platform versions {#major-security-incident-management__section_x15_vjm_y2b}

This
feature is supported on Rome and later releases.  
The following Security Operations applications are the standard Security Incident Response plugins that will likely be installed for most of the users if they're using already Security Incident Response (SIR). If not installed, you must install and activate from ServiceNow Store. Install and then activate one application at a time in the order mentioned to ensure a smooth installation:

1. Security Incident Response: com.snc.si_dep is the dependent plugin. Installing this plugin activates the other Security Operations applications.
2. Security Integration Framework
3. Security Support Common
4. Security Support Common Orchestration
{#major-security-incident-management__ol_xcx_jzk_tgb}
**Related reference**   

* [Get started with MSIM](https://servicenow-prod.fluidtopics.net/7vXPafzH3keuDnwsZHvFSg "Review the following information before you start working with Major Security Incident Management.")
* [Checklist for MSIM setup](https://servicenow-prod.fluidtopics.net/~RRxSBcWML8JrPJh1EEPGA "Before using the ServiceNow Major Security Incident Management (MSIM) application, download the application from the ServiceNow Store.")
* [Major Security Incident Management roles](https://servicenow-prod.fluidtopics.net/44PWW6LjROjdrNzuhQbfXA "Assign roles to ensure that users can perform all necessary actions within the MSIM application.")
* [Environment reference for MSIM setup](https://servicenow-prod.fluidtopics.net/PXYEyKM0Fb2TJS9qXdq02Q "Use this reference table to track environment-specific values while you set up Major Security Incident Management. Complete one column per environment.")

