---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Overview section

# Security Incident Overview section {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Overview section on the workspace presents the key information associated with the
security incident.

The donut charts are drill down enabled, when an analyst selects any of the chart items, then it navigates you to the respective record with a filtered list view of items within that corresponding tab. For example, if
Malicious Observables is selected it takes you to the observables with a filtered list view of malicious observables on the Related Records tab.  
The Overview section displays the following:

* Description of the security incident.
* Business impact details such as the configuration items by asset type and affected users by criticality - whether VIP users or other users.
* Threat intelligence items such as observables by finding whether the observables or malicious or unknown, and by type.
* Response Tasks by state and assignment group.
* Related security incidents comprising child security incidents by state - whether open or closed, and similar security incidents by state - whether open or closed.
* The Resolution section is displayed when an incident moves to the Review state, then the resolution section is displayed within the Overview section with an ability to view the post incident review.
* Resolution - view post incident review: Select the link to navigate to the post incident review page.
* After the incident is closed, the Resolution section displays the resolution code, resolution notes, and resolved by (user) along with the post incident review details.
* Initials of all the users who are currently accessing the same incident.
{#security-incident-overview__ul_vg3_5lq_gwb}
Figure 1. Overview section
**Related concepts**   

* [Security Incident Details section](https://servicenow-prod.fluidtopics.net/0t4Cl0AJwylqeTkve~aFiA "This section displays the security incident form fields that are rendered from the security incident classic UI.")
* [SIR Workspace Orchestration](https://servicenow-prod.fluidtopics.net/X7nsvDJeYY1Bnu338I1MIg "Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.")
* [Security Incident Response Tasks](https://servicenow-prod.fluidtopics.net/kQkQaQKkHJA88mCNui7JdA "All the response tasks associated with a security incident are displayed within the Response Tasks section.")
* [Security Incident Response Other Records](https://servicenow-prod.fluidtopics.net/Bcb9H3wXk8iGqp6PMiXWwQ#security-incident-response-other-records "This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.")
* [Security Incident Response Post Incident Review](https://servicenow-prod.fluidtopics.net/sMFZi8oFyMaTZougxKKaGQ "Post incident review appears when an incident is moved to a Review state.")
* [TISC integration within SIR Workspace](https://servicenow-prod.fluidtopics.net/QzgG5SDXAgV~kQZJg_WphA "The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.")
* [Reports in Security Incident Response](https://servicenow-prod.fluidtopics.net/tBOHHBL3DC9OGClj19ClBA "All the reports associated with a security incident are available within the Reports section for analysis and sharing.")
* [Collaborate using conference call or chat in Security Incident Response](https://servicenow-prod.fluidtopics.net/OrJI18mS_ktHmjCOgaEq0Q "You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.")
* [Viewing incident details with a relationship graph](https://servicenow-prod.fluidtopics.net/ajJ36vkdUXiqndCfWCZsxw "Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.")
* [MITRE attack and defend technique graph](https://servicenow-prod.fluidtopics.net/0~ugWC09RlWCb3fzktbYSA "The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.")  
**Related tasks**   

* [Update information in security incident related records](https://servicenow-prod.fluidtopics.net/NT0C1x0hmtn6DMBUF67v8w "Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.")
* [View and filter the incident timeline](https://servicenow-prod.fluidtopics.net/3B4vOJllZEBtYa29ohM7tg "View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.")

