---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Viewing incident details with a relationship graph

# Viewing incident details with a relationship graph {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.

Items related to a security incident could include associated observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related lists.

The following relationship graph example displays details for a security incident.

When you open a relationship graph for a security incident, the available configurations are visible by default. You can interact with the graph as follows:

* Zoom into any object fit into the screen and drag the nodes.
* Add subnodes for each node, if available, and view details of the subnodes.
* Hide any node or subnode from the graph.
* View details of a subnode.
{#sir-relationship-graph__ul_osm_vcd_b2c}
* **[Customize a relationship graph](https://servicenow-prod.fluidtopics.net/xkQz27gjvxd266Qq3C4P8g)**   
  Visualize and analyze security incidents and their associated data in a relationship graph.
* **[Create a relationship graph for an incident](https://servicenow-prod.fluidtopics.net/MJ2HIomtwLMNGpJrZ9x6Eg)**   
  Create a node relationship graph in Security Incident Response so you can better analyze a security incident by correlating it with malicious observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related information.

**Related concepts**   

* [Security Incident Overview section](https://servicenow-prod.fluidtopics.net/6yceUsy~r3iSEJ7DTJLzqw "The Overview section on the workspace presents the key information associated with the security incident.")
* [Security Incident Details section](https://servicenow-prod.fluidtopics.net/0t4Cl0AJwylqeTkve~aFiA "This section displays the security incident form fields that are rendered from the security incident classic UI.")
* [SIR Workspace Orchestration](https://servicenow-prod.fluidtopics.net/X7nsvDJeYY1Bnu338I1MIg "Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.")
* [Security Incident Response Tasks](https://servicenow-prod.fluidtopics.net/kQkQaQKkHJA88mCNui7JdA "All the response tasks associated with a security incident are displayed within the Response Tasks section.")
* [Security Incident Response Other Records](https://servicenow-prod.fluidtopics.net/Bcb9H3wXk8iGqp6PMiXWwQ#security-incident-response-other-records "This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.")
* [Security Incident Response Post Incident Review](https://servicenow-prod.fluidtopics.net/sMFZi8oFyMaTZougxKKaGQ "Post incident review appears when an incident is moved to a Review state.")
* [TISC integration within SIR Workspace](https://servicenow-prod.fluidtopics.net/QzgG5SDXAgV~kQZJg_WphA "The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.")
* [Reports in Security Incident Response](https://servicenow-prod.fluidtopics.net/tBOHHBL3DC9OGClj19ClBA "All the reports associated with a security incident are available within the Reports section for analysis and sharing.")
* [Collaborate using conference call or chat in Security Incident Response](https://servicenow-prod.fluidtopics.net/OrJI18mS_ktHmjCOgaEq0Q "You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.")
* [MITRE attack and defend technique graph](https://servicenow-prod.fluidtopics.net/0~ugWC09RlWCb3fzktbYSA "The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.")  
**Related tasks**   

* [Update information in security incident related records](https://servicenow-prod.fluidtopics.net/NT0C1x0hmtn6DMBUF67v8w "Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.")
* [View and filter the incident timeline](https://servicenow-prod.fluidtopics.net/3B4vOJllZEBtYa29ohM7tg "View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.")

