---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Link the vulnerability assessment record to major security incident in Major Security Incident Management

# Link the vulnerability assessment record to major security incident in Major Security Incident Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can link, propose or promote the assessment record to a Major Security Incident provided you have access to the Major Security Incident Management application.

## Before you begin

Role required: sn_vul_analyst.vul_event_manager, sn_si.analyst, sn_msi.workspace_admin

## About this task

You can move the assessment record to be associated with an existing major security incident, create a new MSI from the assessment record or promote the vulnerability assessment record to a major security incident. Leverage
the Major Security Incident Management features such as the integrations with Microsoft Teams and Microsoft SharePoint.

You can also view the link to major security incidents on the Vulnerability Manager Workspace for vulnerable items. The MSIM link will be associated with the vulnerable assessment which will be shown on the vulnerability items and as well as on the other workspaces of Vulnerability Response.

## Procedure

1. Navigate to WorkspacesVulnerability Assessment Workspace.
2. Select the assessment record you want to link to a major security incident.
3. Select the More Actions icon, on the Details tab.
4. Select one of the following.

   | Option | Description |
   | Link to Major Security Incident | Select the existing MSI record from the list of Major Security Incidents. The vulnerability assessment record is linked to the existing major security incident. |
   | Propose as Major Security Incident | Enter the following details and select Propose. * Detection Date * Justification * Potential Impact {#link-vuln-assessment-msim-vr-va-ws__ul_p15_p45_gzb} |
   | Promote as Major Security Incident | Enter the following details and select Promote. * Detection Date * Estimated resolution date * Justification * Potential Impact {#link-vuln-assessment-msim-vr-va-ws__ul_skt_m45_gzb} |
   |-|-|

   {#link-vuln-assessment-msim-vr-va-ws__choicetable_zgd_f45_gzb}
5. Select Save.

## What to do next

Select the MSI record to open the record in the Major Security Incident Management view.
**Related tasks**   

* [Link to Major Security Incident](https://servicenow-prod.fluidtopics.net/QSupANeHEuMHdWLwo8J2nw "Link security incidents to a major security incident.")
* [Propose as a Major Security Incident](https://servicenow-prod.fluidtopics.net/m6qUwNXHPosFWQYfUNo7yQ "Propose a security incident to a major security incident.")
* [Promote to a Major Security Incident](https://servicenow-prod.fluidtopics.net/AthhVItLh5ohnsxWvMMSaQ "Promote a security incident to a major security incident or reject promoted proposals through the Major Security Incident Management (MSIM) Workspace.")

*[\>]: and then


