---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View Major Security Incident trend charts

# View Major Security Incident trend charts {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of View Major Security Incident trend charts

This feature enables ServiceNow customers to visualize major security incident metrics through bar graphs and charts.
It provides an Overview tab that details impact metrics, including affected assets, users, locations, and team resources, which evolve with the changing scope of incidents.
The visualizations reflect active tasks linked to Security Incident Response (SIR) incidents, helping users track the nature and volume of ongoing activities.
Show full answer Show less  

## Key Features

* **Time Tracking:** Displays the total active days of a major security incident based on the Detection Date, automatically updated.
* **Estimated Resolution Date:** Shows when the incident is expected to be resolved, refreshed based on input from the Details tab.
* **Active Team Overview:** Lists response teams and members involved, along with a trend chart showing their activity over time.
* **Linked SIR Incidents:** Visualizes the distribution and trends of linked security incidents by their current state.
* **SIR Tasks Management:** Provides insights on active task totals, their states, and overdue tasks, with options to filter and update task details.
* **MSI Tasks:** Displays tasks created directly on the Major Security Incident record, allowing for management and updates.
* **External Collaboration:** Tracks collaboration activities linked to Microsoft Teams and SharePoint, categorized by incident state.

## Key Outcomes

By utilizing these features, ServiceNow customers can effectively manage and monitor major security incidents, ensuring timely responses and resolution. The ability to visualize trends and track tasks enhances operational efficiency and helps in making informed decisions regarding incident management.  
View the major security incident impact progress metrics visualized as bar graphs and charts.

In addition to the incident timeline and progress trend chart visualizations, the Overview tab provides relevant impact metrics to manage the changing scope of the incident,
including rollup of affected assets, users, locations, and team resources.

The counts displayed in the visualization components are based on active tasks on linked Security Incident Response (SIR) incidents. As tasks are opened and closed, these counts change in terms of the nature and volume of remaining
activity planned for the major security incident to represent the trends shown in the trend chart visualization components.  
Figure 1. MSIM Overview tab impact metrics  
Refer to the following table for the UI actions that you can perform from the Overview section:{#viewing-msi-impact-metrics__table_o5x_ryq_vrb__entry__2}

| Title | Description |
|-|-|
| Time | Displays the period in total number of days from when the major security incident is active. The time is calculated based on the Detection Date entered in the Details tab of the workspace. The Detection Date is often captured initially when the major security incident was first created or proposed. Whenever, this date is modified the time is automatically calculated, refreshed, and displayed in the format days: hours: minutes, for example 20D: 13H: 58M. Estimated resolution date: The date by when the incident resolution date is estimated to resolve. This date is often captured initially when the major security incident was first created or promoted. The date is updated and refreshed based on the estimated date provided in the Details tab of the workspace. If the estimated date is not provided in the Details section, then this section displays 'hyphen' without any date value. |
| Active Team | Displays the different response teams and team members from each team who are actively working on the major security incident and its related tasks. Active Team trend: Displays the trend chart of each team and its team members who are actively working on the major security incident and related tasks on regular interval. Note: View the assigned active groups from the Details tab of the workspace. |
| Linked SIR incidents | By incident state: View the distribution of linked security incidents based on a incident state such as Analysis, Contain, Eradicate, Recover, or Review. Trends by incident state: Further indicates the trend view of how the number of linked incidents are progressing based on incident state. Selecting each incident state link allows you to navigate and view the linked security incident details directly on the Linked SI/VI tab of the workspace. This section is updated and refreshed automatically whenever changes occur to the underlying incidents. |
| SIR Tasks | Displays active task totals that are linked to the MSI record via SIR incidents. * By task state: View the incident response tasks based on the incident state such as Draft, Assigned, Work in progress, Closed Complete. This distribution chart allows for a further distribution breakdown by assignment groups. Selecting each task state allows you to view a filtered list by incident task state on the Tasks tab of the workspace. The filtered view allows you to view and update individual task details. * In progress tasks by incident state label: Displays active tasks and groups based on incident state label that must be applied in the Task Organizer components. These default labels have values such as Analysis, Contain, Eradicate, Recover, or Review to indicate the nature of the task involved. * Overdue: Displays the security incident response tasks, which are active and had exceeded the due date. You can view the details of all the overdue tasks by selecting the total Overdue count and having it auto navigate to the Tasks tab. * Trends by task state: View the progress trend of both work in progress and closed response tasks over the incident duration. {#viewing-msi-impact-metrics__ul_ovc_1gr_vrb} Note: The trend chart graph retrieves the latest data based on the scheduled job. You can configure or modify the data retrieval time interval as required. |
| MSI Tasks | Displays active tasks in total, which were created directly on the MSI record (and these aren't linked response tasks): By task state: View the major security incident created tasks, assigned tasks and its related information. Selecting each task state allows you to view a filtered list by incident task state on the Tasks tab of the workspace. The filtered view will allow for viewing and updating individual task details. |
| External Collaboration | Displays collaboration activities in total for all the labelled collaboration activities from the Collaboration Activity Stream: * By incident state label:View the incident collaboration activities data that are coordinated with Microsoft Teams and Microsoft SharePoint files and folders and are labeled using incident state labels such as Analysis, Contain, Eradicate, or Recover from the Collaboration tab of the workspace. * Trends by activity type: View the trend chart for the number of Microsoft Teams and Microsoft SharePoint files and folders activities over the incident duration. {#viewing-msi-impact-metrics__ul_h45_ylr_vrb} |
[Table 1. Overview UI sections]

{#viewing-msi-impact-metrics__table_o5x_ryq_vrb}
**Related concepts**   

* [Propose, promote, and link incident records](https://servicenow-prod.fluidtopics.net/sk9rqHFZOINPE0X~1U5vMg "Propose or promote security incidents as major security incidents when incidents are identified as critical threat to the organization.")
* [View Major Security Incident impact metrics](https://servicenow-prod.fluidtopics.net/3KBNBqRoz_BkHzUxpjZhkg "Provides up-to-date summary reporting of the impact and progress of major security incidents, which is an important aspect of managing a major security incident using the new workspace.")
* [Update Major Security Incident details](https://servicenow-prod.fluidtopics.net/b07ElfZGURoZjC6mrNQUPg "View and update specific details related to the major security incident such as Incident Record Details, Active Team participants, and the corresponding activity log.")
* [Manage tasks in a Major Security Incident](https://servicenow-prod.fluidtopics.net/Yru0dCGME5pKnCMaKxhciw "The Task tab enables you to track and manage all the tasks associated with a major security incident from the MSIM workspace. You can view the various tasks using the default Visual Task Board (Kanban view) or the List view.")
* [Track collaboration activity via MSIM workspace](https://servicenow-prod.fluidtopics.net/oN75Hkl13nFA0yi30ej7pw#collab-tab "Track chat and file activities related to resolving major security incidents through the MSIM Workspace.")  
**Related tasks**   

* [Using MSI List view in the MSIM workspace](https://servicenow-prod.fluidtopics.net/KCnBshkJxFxNQC_44tHI8g "With the list view in the MSIM workspace, you can view proposed, promoted, and rejected major security incidents.")
* [Link additional records to Major Security Incident](https://servicenow-prod.fluidtopics.net/_LFdjo1aOyMiYBIDPKWA7Q "In the workspace, use the linking records functionality to link any related Security Incident records and its child security incidents, Remediation Tasks from Vulnerability Response, and Security Cases from Threat Intelligence to a Major Security Incident (MSI) record.")
* [Unlink records from Major Security Incident](https://servicenow-prod.fluidtopics.net/T0_CeewhEttOZPLLg8B4Ww "Using the Major Security Incident Management workspace, unlink the major security incident records from the Linked Records section.")
* [Create and distribute MSIM Status Reports](https://servicenow-prod.fluidtopics.net/~mxDy9mmDysMOt7PL5mv3A "As a Major Security Incident (MSI) manager, you can create and distribute the different status reports to different stakeholders at various intervals based on the configured report template or a previous status report throughout the course of the major security incident resolution.")

