Working with Security Incident Records
Summarize
Summary of Working with Security Incident Records
The Security Incident Record in ServiceNow provides a comprehensive interface for managing security incidents through various components and tabs. It consolidates essential information, investigation tools, response actions, and collaboration features into a unified workspace that enhances incident handling efficiency and context awareness.
Show less
Key Components of a Security Incident Record
- Security Incident Number: Displayed on the tab for quick identification.
- Short Description: A brief summary shown above the form banner.
- Form Banner: Read-only section with key fields such as Category, Priority, Risk Score, State, and Assignment details; supports platform tags.
- Security Tags: Displays tags linked to the incident for categorization and filtering.
- Overview: Snapshot including Description, Business Impact (assets and affected users), Threat Intelligence items (observables), Response Tasks, and related incidents.
- Details: The core form for detailed incident information.
- Investigation: Provides the investigation experience for analysts.
- Playbook: Triggered via Process Automation Designer when configured, guiding automated or manual response processes.
- Response Tasks: Lists all tasks associated with the incident response.
- Related Records: Groups related lists from the classic UI, organized for easy navigation (e.g., business impact, threat intel).
- Other Records: Displays IT records like change requests, incidents, and emails linked to the incident.
- Post Incident Review: Appears when the incident moves to Review state, containing assessments and reports.
- Contextual Menu: Provides quick access to actions and resources such as Activity Stream, Playbooks, Analyst Assist, Runbook Templates, and Attachments.
- Form UI Actions: Actions available on the form’s top right, including creating response tasks, composing emails, linking incidents, promoting to major incidents, and more, enabling streamlined workflow management.
Security Incident Workspace Features
- Orchestration: Enables viewing of the investigation canvas and performing applicable actions within the workspace.
- Response Tasks and Other Records: Centralized display of all tasks and IT-related records such as incidents, changes, problems, and outages.
- Post Incident Review: Facilitates capturing and managing reviews once incidents progress to the Review state.
- Direct Editing: Allows updating related records directly from the Related Records tab without losing context.
- TISC Integration: Integrates Threat Intelligence Security Center content within the workspace for enriched incident context.
- Reports: Access to all incident-related reports for analysis and sharing.
- Collaboration: Supports communication via conference calls or chat with analysts and affected users directly in the Security Incident Response application.
- Relationship Graph: Visualizes connections between the incident and related items to aid comprehensive analysis.
- MITRE Attack and Defend Technique Graph: Interactive visualization of attack and defense techniques linked to the incident.
- Incident Timeline: Shows chronological events with filtering options to focus on relevant activities.
Practical Benefits for ServiceNow Customers
This structured and feature-rich interface enables security teams to efficiently track, analyze, and respond to security incidents. By leveraging automation through playbooks, integrated threat intelligence, and collaborative tools, customers can improve incident resolution times and maintain thorough documentation and post-incident assessments. The capability to view related records and visualize incident context supports informed decision-making and risk reduction.
The Security Incident Record consists of the following.
| Number | Name | Description |
|---|---|---|
| 1 | Security incident number | The security incident number is available against the tab name. |
| 2 | Short description | Short description of the security incident which is displayed above the form banner. |
| 3 | Form banner | This is read-only section, which contains the key fields such as Category, Priority, Risk score, State, and the incident assignment details. Note: The regular platform tags can be applied here as
well. |
| 4 | Security tags | Displays the security tags associated with a security incident. |
| 5 | Overview | Provides a snapshot overview of the security incident such as Description, Business Impact comprising of asset details by type, affected users by criticality, Threat intelligence items comprising of observables by finding and by type, Response Tasks, Related security incidents comprising of child security incidents and similar security incidents. |
| 6 | Details | The details tab displays the security incident form. |
| 7 | Investigation | The Investigation tab displays the incident investigation experience. |
| 8 | Playbook | Playbook is triggered through Process Automation Designer (PAD). If a process is created, and if the a trigger condition is set to trigger the playbook for a security incident. Then a playbook appears. |
| 9 | Response Tasks | The Response Tasks captures all the response tasks associated with a security incident. |
| 10 | Related Records | The Related Records tab consists of all the related lists from the classic UI under this section. The related lists are grouped under various section such as business impact, threat intel, and so on for an easy navigation. |
| 11 | Other Records | Other records tab consists of IT records such as changes requests, incidents, and emails grouped and displayed in this section. |
| 12 | Post Incident Review tab | As the security incident progresses to the Review state, the Post Incident Review tab is displayed with the post incident assessments and reports within the tab. |
| 13 | Contextual menu | Provides easy access to the quick actions and is available across all the tabs for the analyst to access whenever required. The contextual menu provides easy navigation to the multiple resources such as:
|
| 14 | Form UI actions | The various security incident form UI actions are displayed on the top right of the incident form. The available form UI actions are:
For more information, see Working with Form UI actions. |