---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Working with Security Incident Records

# Working with Security Incident Records {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Working with Security Incident Records

The Security Incident Record in ServiceNow provides a comprehensive interface for managing security incidents through various components and tabs.
It consolidates essential information, investigation tools, response actions, and collaboration features into a unified workspace that enhances incident handling efficiency and context awareness.
Show full answer Show less  

## Key Components of a Security Incident Record

* **Security Incident Number:** Displayed on the tab for quick identification.
* **Short Description:** A brief summary shown above the form banner.
* **Form Banner:** Read-only section with key fields such as Category, Priority, Risk Score, State, and Assignment details; supports platform tags.
* **Security Tags:** Displays tags linked to the incident for categorization and filtering.
* **Overview:** Snapshot including Description, Business Impact (assets and affected users), Threat Intelligence items (observables), Response Tasks, and related incidents.
* **Details:** The core form for detailed incident information.
* **Investigation:** Provides the investigation experience for analysts.
* **Playbook:** Triggered via Process Automation Designer when configured, guiding automated or manual response processes.
* **Response Tasks:** Lists all tasks associated with the incident response.
* **Related Records:** Groups related lists from the classic UI, organized for easy navigation (e.g., business impact, threat intel).
* **Other Records:** Displays IT records like change requests, incidents, and emails linked to the incident.
* **Post Incident Review:** Appears when the incident moves to Review state, containing assessments and reports.
* **Contextual Menu:** Provides quick access to actions and resources such as Activity Stream, Playbooks, Analyst Assist, Runbook Templates, and Attachments.
* **Form UI Actions:** Actions available on the form's top right, including creating response tasks, composing emails, linking incidents, promoting to major incidents, and more, enabling streamlined workflow management.

## Security Incident Workspace Features

* **Orchestration:** Enables viewing of the investigation canvas and performing applicable actions within the workspace.
* **Response Tasks and Other Records:** Centralized display of all tasks and IT-related records such as incidents, changes, problems, and outages.
* **Post Incident Review:** Facilitates capturing and managing reviews once incidents progress to the Review state.
* **Direct Editing:** Allows updating related records directly from the Related Records tab without losing context.
* **TISC Integration:** Integrates Threat Intelligence Security Center content within the workspace for enriched incident context.
* **Reports:** Access to all incident-related reports for analysis and sharing.
* **Collaboration:** Supports communication via conference calls or chat with analysts and affected users directly in the Security Incident Response application.
* **Relationship Graph:** Visualizes connections between the incident and related items to aid comprehensive analysis.
* **MITRE Attack and Defend Technique Graph:** Interactive visualization of attack and defense techniques linked to the incident.
* **Incident Timeline:** Shows chronological events with filtering options to focus on relevant activities.

## Practical Benefits for ServiceNow Customers

This structured and feature-rich interface enables security teams to efficiently track, analyze, and respond to security incidents. By leveraging automation through playbooks, integrated threat intelligence, and collaborative tools, customers can improve incident resolution times and maintain thorough documentation and post-incident assessments. The capability to view related records and visualize incident context supports informed decision-making and risk reduction.  
The Security Incident Record consists of the following.  
Key components available on a security incident record:Figure 1. Key components of a security incident {#using-analyst-workspace__table_ijt_rl5_x5b__entry__3}

| Number | Name | Description |
|-|-|-|
| 1 | Security incident number | The security incident number is available against the tab name. |
| 2 | Short description | Short description of the security incident which is displayed above the form banner. |
| 3 | Form banner | This is read-only section, which contains the key fields such as Category, Priority, Risk score, State, and the incident assignment details. Note: The regular platform tags can be applied here as well. |
| 4 | Security tags | Displays the security tags associated with a security incident. |
| 5 | Overview | Provides a snapshot overview of the security incident such as Description, Business Impact comprising of asset details by type, affected users by criticality, Threat intelligence items comprising of observables by finding and by type, Response Tasks, Related security incidents comprising of child security incidents and similar security incidents. |
| 6 | Details | The details tab displays the security incident form. |
| 7 | Investigation | The Investigation tab displays the incident investigation experience. |
| 8 | Playbook | Playbook is triggered through Process Automation Designer (PAD). If a process is created, and if the a trigger condition is set to trigger the playbook for a security incident. Then a playbook appears. |
| 9 | Response Tasks | The Response Tasks captures all the response tasks associated with a security incident. |
| 10 | Related Records | The Related Records tab consists of all the related lists from the classic UI under this section. The related lists are grouped under various section such as business impact, threat intel, and so on for an easy navigation. |
| 11 | Other Records | Other records tab consists of IT records such as changes requests, incidents, and emails grouped and displayed in this section. |
| 12 | Post Incident Review tab | As the security incident progresses to the Review state, the Post Incident Review tab is displayed with the post incident assessments and reports within the tab. |
| 13 | Contextual menu | Provides easy access to the quick actions and is available across all the tabs for the analyst to access whenever required. The contextual menu provides easy navigation to the multiple resources such as: 1. Activity Stream 2. Playbook 3. Analyst Assist 4. Runbook 5. Templates 6. Attachments {#using-analyst-workspace__ol_hyd_vzj_w5b} |
| 14 | Form UI actions | The various security incident form UI actions are displayed on the top right of the incident form. The available form UI actions are: * Discuss * Save * Create Response Task * Compose Email * Add Playbook * Open Associated Workflow(s) * Crete incident * Create Problem * Create Change Request * Create Outage * Calculate Severity * Link to Major Security Incident * Propose as Major Security Incident * Promote to Major Security Incident * Run Additional Action(s) on Endpoint * Associate MITRE ATT\&CK Technique * Switch to Classic UI * Add to Security Case * Delete {#using-analyst-workspace__ul_y51_5t5_x5b} For more information, see [Working with Form UI actions](https://servicenow-prod.fluidtopics.net/BiVNOVqIU5VY5t0VA35xHg "Following are the UI actions that are displayed on the security incident form."). |
[ ]

{#using-analyst-workspace__table_ijt_rl5_x5b}
* **[Security Incident Overview section](https://servicenow-prod.fluidtopics.net/6yceUsy~r3iSEJ7DTJLzqw)**   
  The Overview section on the workspace presents the key information associated with the security incident.
* **[Security Incident Details section](https://servicenow-prod.fluidtopics.net/0t4Cl0AJwylqeTkve~aFiA)**   
  This section displays the security incident form fields that are rendered from the security incident classic UI.
* **[SIR Workspace Orchestration](https://servicenow-prod.fluidtopics.net/X7nsvDJeYY1Bnu338I1MIg)**   
  Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.
* **[Security Incident Response Tasks](https://servicenow-prod.fluidtopics.net/kQkQaQKkHJA88mCNui7JdA)**   
  All the response tasks associated with a security incident are displayed within the Response Tasks section.
* **[Security Incident Response Other Records](https://servicenow-prod.fluidtopics.net/Bcb9H3wXk8iGqp6PMiXWwQ#security-incident-response-other-records)**   
  This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
* **[Security Incident Response Post Incident Review](https://servicenow-prod.fluidtopics.net/sMFZi8oFyMaTZougxKKaGQ)**   
  Post incident review appears when an incident is moved to a Review state.
* **[Update information in security incident related records](https://servicenow-prod.fluidtopics.net/NT0C1x0hmtn6DMBUF67v8w)**   
  Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.
* **[TISC integration within SIR Workspace](https://servicenow-prod.fluidtopics.net/QzgG5SDXAgV~kQZJg_WphA)**   
  The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.
* **[Reports in Security Incident Response](https://servicenow-prod.fluidtopics.net/tBOHHBL3DC9OGClj19ClBA)**   
  All the reports associated with a security incident are available within the Reports section for analysis and sharing.
* **[Collaborate using conference call or chat in Security Incident Response](https://servicenow-prod.fluidtopics.net/OrJI18mS_ktHmjCOgaEq0Q)**   
  You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.
* **[Viewing incident details with a relationship graph](https://servicenow-prod.fluidtopics.net/ajJ36vkdUXiqndCfWCZsxw)**   
  Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.
* **[MITRE attack and defend technique graph](https://servicenow-prod.fluidtopics.net/0~ugWC09RlWCb3fzktbYSA)**   
  The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.
* **[View and filter the incident timeline](https://servicenow-prod.fluidtopics.net/3B4vOJllZEBtYa29ohM7tg)**   
  View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.

**Related concepts**   

* [Security Incident Playbook](https://servicenow-prod.fluidtopics.net/Or37s267AkF~R9MUgzRYiQ#security-incident-playbook "Invoke the security incident playbook flow automatically or manually.")
* [Prerequisites for the Playbooks](https://servicenow-prod.fluidtopics.net/POSOIYPbrf55BhB5oZj_Tw "You need the following roles and plugins to build the Playbooks.")
* [Rebuilding existing playbooks in Workflow Studio](https://servicenow-prod.fluidtopics.net/Gxrs6Kmn6bmfB680yQYz3A "You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.")
* [Activity Definitions](https://servicenow-prod.fluidtopics.net/IMGNwpKoJREVXgsdWM6BEg "The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.")
* [Sample Playbooks for SIR Workspace](https://servicenow-prod.fluidtopics.net/LJZS56n6O87_ZQicnhxpTw "You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.")
* [Working with MSI Records](https://servicenow-prod.fluidtopics.net/EzBRz3gfWLnRuxl~O9DXuA "Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.")
* [Working with Form UI actions](https://servicenow-prod.fluidtopics.net/BiVNOVqIU5VY5t0VA35xHg "Following are the UI actions that are displayed on the security incident form.")  
**Related tasks**   

* [Security Incident Closure workflow](https://servicenow-prod.fluidtopics.net/eUcWbP2pHl3bZk_3cBQ5EA "Close the security incident by updating the incident state.")
* [Handle security incidents using Advanced Work Assignment](https://servicenow-prod.fluidtopics.net/T3UyVFGugN7M9V4Ol1CCLg "Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.")

