---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response Other Records

# Security Incident Response Other Records {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

This section displays the other records such as IT related records and email records.
Under IT records, Incident, Change Request, Problem and Outages are displayed.

Under Email, Draft, Sent Emails and Received Emails are displayed.
Figure 1. Other Records
**Related concepts**   

* [Security Incident Overview section](https://servicenow-prod.fluidtopics.net/6yceUsy~r3iSEJ7DTJLzqw "The Overview section on the workspace presents the key information associated with the security incident.")
* [Security Incident Details section](https://servicenow-prod.fluidtopics.net/0t4Cl0AJwylqeTkve~aFiA "This section displays the security incident form fields that are rendered from the security incident classic UI.")
* [SIR Workspace Orchestration](https://servicenow-prod.fluidtopics.net/X7nsvDJeYY1Bnu338I1MIg "Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.")
* [Security Incident Response Tasks](https://servicenow-prod.fluidtopics.net/kQkQaQKkHJA88mCNui7JdA "All the response tasks associated with a security incident are displayed within the Response Tasks section.")
* [Security Incident Response Post Incident Review](https://servicenow-prod.fluidtopics.net/sMFZi8oFyMaTZougxKKaGQ "Post incident review appears when an incident is moved to a Review state.")
* [TISC integration within SIR Workspace](https://servicenow-prod.fluidtopics.net/QzgG5SDXAgV~kQZJg_WphA "The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.")
* [Reports in Security Incident Response](https://servicenow-prod.fluidtopics.net/tBOHHBL3DC9OGClj19ClBA "All the reports associated with a security incident are available within the Reports section for analysis and sharing.")
* [Collaborate using conference call or chat in Security Incident Response](https://servicenow-prod.fluidtopics.net/OrJI18mS_ktHmjCOgaEq0Q "You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.")
* [Viewing incident details with a relationship graph](https://servicenow-prod.fluidtopics.net/ajJ36vkdUXiqndCfWCZsxw "Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.")
* [MITRE attack and defend technique graph](https://servicenow-prod.fluidtopics.net/0~ugWC09RlWCb3fzktbYSA "The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.")  
**Related tasks**   

* [Update information in security incident related records](https://servicenow-prod.fluidtopics.net/NT0C1x0hmtn6DMBUF67v8w "Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.")
* [View and filter the incident timeline](https://servicenow-prod.fluidtopics.net/3B4vOJllZEBtYa29ohM7tg "View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.")

## Create an incident {#ariaid-title2}

Create an incident within a security incident.

### Before you begin

Role required: sn_si.analyst.

### Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open any incident record.
3. Click Create Incident.  
4. Enter the details such as Configuration Item, Impact, Urgency, Location, Priority, and Short Description.
5. Click Create.
6. An incident gets created.

## Link multiple ITSM incidents, problems or change requests to a security incident {#ariaid-title3}

Link related multiple IT Service Management (ITSM) incidents, problems or change requests to a security incident.

### Before you begin

Role required: sn_si.analyst

### Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Select the Security Incidents icon ![]().
3. Open the incident record.
4. Select the Other Records tab.
5. Under IT records, select Incident or Problems or Change Requests.
6. Select Link.
7. Select the ITSM record you want to link to the selected security incident.
8. Select Link.

### Result

The selected ITSM records are listed in the IT records section of the selected security incident record.

## Create a problem task {#ariaid-title4}

Create a problem task.

### Before you begin

Role required: sn_si.analyst

### Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open any incident record.
3. Select Create Problem.
4. Fill in the details such as Configuration Item, Location, Impact, Urgency, Priority, and Short description.
5. Select Create.
6. A problem task gets created.
{#create_problem__steps_bml_x2j_v5b}

## Create a change request {#ariaid-title5}

Create a change request.

### Before you begin

Role required: sn_si.analyst.

### Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open any incident record.
3. Click Create Change Request.
4. Enter the details such as Configuration Item, Location, Priority, and Short description.
5. Click Create.
6. A change request gets created.
{#create_change_request__steps_bml_x2j_v5b}

## Create outage {#ariaid-title6}

Crete an outage from an incident to track the down time of a configuration
item.

### Before you begin

Role required: sn_si.analyst

### Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open any incident record.
3. Click Create outage.
4. Enter the details such as Configuration Item, Begin date, End date, Type, and Short description.
5. Click Create.
{#create_outage__steps_bml_x2j_v5b}

## Compose Emails {#ariaid-title7}

As an analyst, you can compose emails directly from security incidents.

### Before you begin

Role required: sn_si.analyst

### Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Select and open the incident for which you want to compose an email.
3. Click the overflow and select Compose Email.  
4. Enter the To and CC field.
5. Add attachments, if any.
6. Within the Email form, click Quick Messages to view the quick messages which is displayed on the right side of the Compose Emails section.  
   The available quick messages are displayed. Select the message and click Insert. The messages gets inserted in the body of the email.
7. Compose your email and click Send Email.  
   Note:  
   You can save an email as a draft. These draft emails will be available under the Other records tab.
   How to configure Quick Messages:
   1. Navigate to AllSystem DefinitionsTables.
   2. Search for Quick Message (sys_email_canned_message) table.  
   3. Go to Related LinksShow List.
   4. Create New.
   5. Enter the Title, body of the message, select the Table: Security Incident (sn_si_incident) and Active check box.  
   6. Click Submit.  
      After a new entry is created within the table, the quick message appears in the contextual menu.
   {#compose_emails__substeps_km4_ml2_z5b}
8. Click Templates to add any template if required.
9. Select the Response Template and click Copy to clipboard and apply the template, if required.  
   How to configure Response Templates:
   1. Navigate to System DefinitionsTables.
   2. Search for the Response Template (sn_templated_snip_note_template) table.  
   3. Go to Related LinksShow List.
   4. Create New.
   5. Enter the Name, Short Name, select the Table: Security Incident (sn_si_incident) and Template body.  
   6. Click Submit.  
      After a new entry is created within the table, the new template appears in the contextual menu.
   {#compose_emails__substeps_zg3_g42_z5b}

*[\>]: and then


