---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# List view in SIR Workspace

# List view in SIR Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of List view in SIR Workspace

The List view in the Security Incident Response (SIR) Workspace provides ServiceNow security analysts with an efficient interface to manage Security Incidents, Response Tasks, Phishing Emails, Assessments, and Shift Handover records.
Pre-applied filters and customizable list views enable quick access to relevant work items, streamlining incident management and team collaboration.
Show full answer Show less  

## Key Features

* **Security Incidents:** Multiple filtered lists such as Assigned to Me, Assigned to Team, Unassigned, All Open, and All allow analysts to quickly locate and manage incidents. Analysts can configure visible columns, assign or delete incidents, create new incidents, apply quick filters for immediate priority, refresh lists, and export data in Excel, CSV, JSON, or PDF formats.
* **Response Tasks:** Similar to Security Incidents, with lists for Assigned to Me, Assigned to Team, Unassigned, All Open, and All. Analysts can configure columns, assign tasks to others, create new tasks, apply quick filters, refresh, and export the task list.
* **Phishing Emails:** Displays all phishing emails sorted by last update. Analysts can report phishing emails directly from the list, delete emails, and export the list in various formats.
* **Assessments:** Lists pending and all assessments needed for post-incident reviews, enabling analysts to track and complete required assessments.
* **Shift Handover Records:** Provides lists filtered by team assignments and all records. Supports roles including Admin (shift owner), Security Analyst (shift analyst), and Security Manager with role-based access controls for editing or viewing records. Analysts can create, edit, copy, or delete Shift Handover records tied to Shift Handover Report Templates.
* **Quick Filters:** Easily accessible filters for Security Incidents and Response Tasks that help analysts prioritize work items without using advanced filters.
* **Personalization:** Security analysts and managers can personalize list views for incidents, response tasks, or phishing emails based on individual preferences.

## Key Outcomes

* Improved efficiency in managing and navigating security incidents and response tasks through predefined and customizable filters and views.
* Enhanced team collaboration by enabling assignment and reassignment of incidents and tasks directly from the list view.
* Streamlined handling of phishing emails with reporting, deletion, and export capabilities.
* Effective management of Shift Handover records with role-based access and editing capabilities ensuring continuity across shifts.
* Ability to export critical security data in multiple formats for reporting and analysis purposes.
* Quick access to pending assessments to ensure timely post-incident reviews.  
The list view consists of the security incidents, response tasks, phishing emails, and
assessments.

The list view has pre applied filters such as Assigned to Me, Assigned to Team, Unassigned, All
Open, All, and so on.

Using these list categories and filtered lists, analysts can quickly find the required Security
Incidents and Response Tasks records that they need to work on.

To get to the list view, select the list icon (![list view icon]()). When you select a record in a list view, the record opens in a new tab.

## List types {#setting-up-list-view-in-analyst-workspace__section_jx4_53r_55b}

The following gives you an example view of the lists.

The list pane contains the following sections:  
{#setting-up-list-view-in-analyst-workspace__table_gkm_1lr_55b__entry__3}

| List item | Description | Capability |
|-|-|-|
| Security Incidents | View the list of security incidents and navigate to the desired incident to start working on them. The following lists are available: * Visible to Me: Security incidents that are visible to the logged in user. * Assigned to Me: Security incidents that are assigned to the analyst. * Assigned to the Team: Security incidents that are assigned to all the teams that the analysts belongs to. * Unassigned: List of unassigned security incidents. * All Open: List of all open security incidents. * All: List of all security incidents. {#setting-up-list-view-in-analyst-workspace__ul_hmf_x3h_v5b} | * On the List view, the Analyst can configure the list of columns by clicking on the gear icon which is available above the incident columns. * The analyst can select one or more security incident(s) and assign those incidents to the other users. * The analyst can delete the security incidents. * The analyst can create a new security incident. * The analyst can apply the quick filters. Apply the filters by clicking on the Quick Filters option instead of using the advance Filter option. Using the quick filters, you can quickly filter the list of security incidents that needs immediate attention. For more information, see [Working with quick filters](https://servicenow-prod.fluidtopics.net/Dm_XloOH7st7z7LSR6BbAA "Quick filters are easily accessible filters that are available on, security incidents and response tasks lists."). * The analysts can refresh the list of incidents. * The analyst can export the list view to Excel, CSV, JSON, and PDF formats. {#setting-up-list-view-in-analyst-workspace__ul_mrv_qjs_55b} |
| Shift Handover Records | View the list of Shift Handover records. The following lists are available: * Assigned to the Team: Shift Handover records that are assigned to all the teams/user groups that the analysts belongs to. * All: List of all security incidents. {#setting-up-list-view-in-analyst-workspace__ul_mfw_xrk_gbc} | Shift Handover supports the following three roles: * Admin: Shift owner role * Security Analyst: Shift analyst role * Security Manager: Shift owner role, but doesn't have access to user group to which the Shift Handover record is assigned to. {#setting-up-list-view-in-analyst-workspace__ul_pnc_qsk_gbc} * The users with the Shift Owner/Analyst role who are part of the user group in the active shift can add or modify content in the shift handover records in the draft state. * The users who don't have the Shift owner/analyst role or are not part of the user group in the active shift can only view the content in the Shift Handover records. {#setting-up-list-view-in-analyst-workspace__ul_n4c_d5k_gbc} |
| Response Tasks | View the list of response tasks and navigate to the desired response task to start working on them. The list view contains: * Assigned to Me: Response tasks that are assigned to the analyst. * Assigned to the Team: Response tasks that are assigned to the teams to the analysts belongs to. * Unassigned: List of unassigned response tasks. * All Open: List of all open response tasks. * All: List of all response tasks. {#setting-up-list-view-in-analyst-workspace__ul_hbs_t3h_v5b} | * On the List view, the Analyst can configure the list of columns by clicking on the gear icon which is available above the incident columns. * The analyst can select one or more response task(s) and assign those tasks to other users. * The analyst can create a new response task. * The analyst can apply the quick filters. Apply the filters by clicking on the Quick Filters option instead of using the advance Filter option. Using the quick filters, you can quickly filter the list of response tasks that needs immediate attention. * The analysts can refresh the list of response tasks. * The analyst can export the list view to Excel, CSV, JSON, and PDF formats. For more information, see [Export Security Incidents or Response Tasks](https://servicenow-prod.fluidtopics.net/JHtI68igM~InPCAaJ594~w "Export the security incidents or response tasks from the list view."). {#setting-up-list-view-in-analyst-workspace__ul_ovb_2km_x5b} |
| Phishing Emails | View the list of all Phishing emails. The list view will be sorted based on the last update. | * Report Phishing Email. For more information, see [Report Phish Email](https://servicenow-prod.fluidtopics.net/Xa19dE_pFpmbf9OFlZFXxg "Report phishing emails from the lists view.") on how to report a phishing email. * Delete phishing emails. * Export the phishing emails list view to Excel, CSV, JSON, and PDF formats. {#setting-up-list-view-in-analyst-workspace__ul_icl_nlr_55b} |
| Assessments | View the list of assessments needed to perform post incident review. * My pending Assessments: List of pending assessments. * My All Assessments: List of all assessments. {#setting-up-list-view-in-analyst-workspace__ul_wbr_1kh_v5b} | Take assessments. |
[Table 1. Lists]

{#setting-up-list-view-in-analyst-workspace__table_gkm_1lr_55b}
* **[Personalize a list](https://servicenow-prod.fluidtopics.net/_RxhTpnln1PmOuwEqp9R1g)**   
  Security analysts or managers can personalize the security incidents or response tasks or phishing emails custom list view based on their individual preferences.
* **[Apply quick filters on Security Incidents and Response Tasks lists](https://servicenow-prod.fluidtopics.net/35Z73~2baAzbxtNGCt72ew)**   
  Apply the predefined quick filters on Security Incidents and Response Tasks lists to get the desired work items.
* **[Assign Security Incidents](https://servicenow-prod.fluidtopics.net/aP2FfEOHr0CacFo6ua40IQ)**   
  Assign security incidents.
* **[Close multiple security incidents](https://servicenow-prod.fluidtopics.net/Dvg2PBwYt_q~KLReXA~5sg)**   
  Close multiple security incidents at the same time to avoid having to close related incidents individually, such as incidents created with a common root cause or false positive incidents.
* **[Assign Response Tasks](https://servicenow-prod.fluidtopics.net/W_pvOPoYfE6SM60RAY0HNg)**   
  Assign Response tasks for a security issue.
* **[Report Phish Email](https://servicenow-prod.fluidtopics.net/Xa19dE_pFpmbf9OFlZFXxg)**   
  Report phishing emails from the lists view.
* **[Working with quick filters](https://servicenow-prod.fluidtopics.net/Dm_XloOH7st7z7LSR6BbAA)**   
  Quick filters are easily accessible filters that are available on, security incidents and response tasks lists.
* **[Export Security Incidents or Response Tasks](https://servicenow-prod.fluidtopics.net/JHtI68igM~InPCAaJ594~w)**   
  Export the security incidents or response tasks from the list view.
* **[Manage Shift Handover records](https://servicenow-prod.fluidtopics.net/cnHScVK7WGH36Kp9gnPgZw)**   
  Use the Shift Handover records list view to create, edit, copy, or delete Shift Handover records. Each Shift Handover record is associated with a Shift Handover Report Template.

**Related concepts**   

* [SIR Workspace features](https://servicenow-prod.fluidtopics.net/8RpOO~NHgmEKOvLelppoQA "The Security Incident Response Workspace consists of the following key features.")
* [SIR Workspace interface overview](https://servicenow-prod.fluidtopics.net/~TZjXfpt806pAVTxJdvewA "The SIR Workspace Overview page consists of the Security Incidents and Response Tasks details that are under security analysts and their team.")
* [Upcoming section](https://servicenow-prod.fluidtopics.net/PYIvFKoYWjA3UhvVIOAXZA "This section displays the upcoming tasks such as the security incidents and response tasks that are due as on the same day and next day.")
* [Quick links section](https://servicenow-prod.fluidtopics.net/94_97N0fwDf7ASqbiWHc2A "Quick links work like bookmark links. You can add external URLs and quickly access them from within the workspace.")
* [Shift Handover Records section](https://servicenow-prod.fluidtopics.net/UXY0oW6ISmUwjCVrPnl48g "The section displays the list of Shift Handover records in the Security Incident Response Workspace.")  
**Related reference**   

* [SIR Workspace plugins](https://servicenow-prod.fluidtopics.net/DT9niT7CHKbBFZbGrlMamw "The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.")

