---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View related items for a security incident

# View related items for a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

You can view related items, such as similar and child security incidents, related
users, vulnerability groups, and vulnerable items associated with a security
incident.

## Before you begin

Role required: sn_si.basic

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open the security incident for which you want to view related items.
3. Select the Related Records tab.
4. Select any of the related lists to view or add information for the security incident.  
   {#show-related-items-for-si__table_hng_51r_yy__entry__2}

   | Tab | Description |
   |-|-|
   | Child Security Incidents | The task record related to the issue that created the caused this security incident. |
   | Similar Security Incidents | Other security incidents associated with any of the same observable records. The Link as Children button can be used to assign the selected similar security incidents as the children of the currently opened security incident. |
   | Related Configuration Items | Displays a list of security incidents containing configuration items with the same observable as this security incident. This list can be filtered using the CI exclusions filter group. When an observable is added to a security incident this list is automatically updated. By default, observables with a context type of Destination are excluded. |
   | Related Users | Displays a list of security incidents containing users with the same observables as this security incident. This list can be filtered using the User exclusion filter group. When an observable is added to a security incident this list is automatically updated. By default, observables with a context type of Destination are excluded. |
   | Related Filter Group | After configuration items are identified, any matching CI or Filter group are automatically added. |
   | Vulnerability Groups | If Vulnerability Response is activated, you can view vulnerability groups associated with this security incident. |
   | Vulnerable Items | If Vulnerability Response is activated, you can view vulnerability items associated with this security incident. |
   | Risks | If any of the core Risk Management plugins (Policy and Compliance Management, Audit, Management, or Risk Management) are activated, you can view or add risks associated with the security incident. This related list can be from the form header context menu under ConfigureRelated Lists. |
   | Configuration item events | Tab to view events, if Event Management is activated. |
   | Configuration item alerts | Tab to view alerts, if Event Management is activated. |
   | Customer Service Cases | Tab to view Customer Service case information, if Customer Service is activated. |
   [ ]

   {#show-related-items-for-si__table_hng_51r_yy}
5. Select any of the following related links to further update the security incident:  
   * [Show Affected Items](https://servicenow-prod.fluidtopics.net/v5P23O5qpqXvK~jeo5tUXw "You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.")
   * [Show IoC](https://servicenow-prod.fluidtopics.net/QiPYhovl9Rh2EBQRXKLqlA "You can view IoC information, such as observables and sightings search results associated with a security incident.")
   * [Show Enrichment Data](https://servicenow-prod.fluidtopics.net/vfRbfkT4oIhy008Ej9qB8g "You can view enrichment data, such as running processes, running services, and network statistics associated with a security incident.")
   * [Show Response Tasks](https://servicenow-prod.fluidtopics.net/w0eTEV1T~Ug1aQGp91dl0A "You can view response task information, such as task SLAs, risk score audits and outages associated with a security incident.")
   {#show-related-items-for-si__ul_rxz_h1q_vz}
6. Select Submit.
{#show-related-items-for-si__steps_akt_2wc_wz}

*[\>]: and then


