---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View affected items for a security incident

# View affected items for a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.

## Before you begin

Role required: sn_si.basic

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open the security incident for which you want to view affected items.
3. Select the Related Records tab.
4. Select Business Impact.
5. Select any of the related lists to view or add information for the security incident.  
   {#show-affected-items-for-si__table_hng_51r_yy__entry__2}

   | Tab | Description |
   |-|-|
   | Configuration Items | Affected configuration items (CI). After affected CIs are identified, you can manually add affected resources from this related list. |
   | Affected Users | After affected users are identified, you can manually add affected users from this related list. |
   | Affected Services | View or add business services associated with the security incident. Note: If an affected CI is added after the security incident is opened, select and hold (or right-click) in the form header and select Refresh Impacted Services. |
   | Unmatched Affected Users | View or add the users who are affected by a security incident but cannot be matched to existing user records in the Users \[sys_user\] table. |
   [ ]

   {#show-affected-items-for-si__table_hng_51r_yy}  
   Note:  
   If the [Security Operations Integration - Get Running Processes](https://servicenow-prod.fluidtopics.net/7G0Det4oSs92UixHhucV7w "The Get Running Processes capability retrieves a list of running processes on a configuration item (CI) from a host or endpoint. This capability is used for incident enrichment during investigations.") integration capability is active, and you add a CI to a security incident, the [Get Running Processes](https://servicenow-prod.fluidtopics.net/7PKofxKKNYMks5dGSVT6Xw "The Security Operations - Get Running Processes flow is a high-level flow independent of integrations. It retrieves a list of running processes on a configuration item (CI) from a host. Use it to fulfill an integration, such as Carbon Black, or for a Windows-based security incident.") workflow runs and retrieves a list of running processes on the CI.

   If the [Security Operations Integration - Isolate Host](https://servicenow-prod.fluidtopics.net/l37EZFEV1U1ZHH_Y5hUuWQ "The Isolate Host capability restricts system connections to other devices. Isolate host is executed against a configuration item (CI).") integration capability is active, you can select one or more CIs and restrict their system connections to other devices. To do
   this, select the check boxes for the CIs and select Isolate Host from the Actions on selected rows choice list.
6. Selected any of the following related links to further update the security incident:  
   * [Show Related Items](https://servicenow-prod.fluidtopics.net/5dWDw6sQ~pOrALbzetUbNg "You can view related items, such as similar and child security incidents, related users, vulnerability groups, and vulnerable items associated with a security incident.")
   * [Show IoC](https://servicenow-prod.fluidtopics.net/QiPYhovl9Rh2EBQRXKLqlA "You can view IoC information, such as observables and sightings search results associated with a security incident.")
   * [Show Enrichment Data](https://servicenow-prod.fluidtopics.net/vfRbfkT4oIhy008Ej9qB8g "You can view enrichment data, such as running processes, running services, and network statistics associated with a security incident.")
   * [Show Response Tasks](https://servicenow-prod.fluidtopics.net/w0eTEV1T~Ug1aQGp91dl0A "You can view response task information, such as task SLAs, risk score audits and outages associated with a security incident.")
   {#show-affected-items-for-si__ul_rxz_h1q_vz}
7. When you have completed your entries, select Save.

*[\>]: and then


