This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of Working with Security Incident Records
The Security Incident Record in ServiceNow Security Incident Response (SIR) provides a comprehensive workspace to manage and investigate security incidents.It consolidates critical incident data, investigation tools, and collaboration features to enable security analysts to efficiently respond to and resolve incidents.
Show full answerShow less
Key Components of a Security Incident Record
Security incident number: Displays the unique identifier for the incident.
Short description: A brief summary visible above the form banner.
Form banner: Read-only key fields including Category, Priority, Risk score, State, and assignment details, with support for platform tags.
Security tags: Shows tags related to the incident for classification.
Overview: Snapshot of incident details such as description, business impact (asset and user criticality), threat intelligence (observables by finding/type), response tasks, and related incidents.
Details tab: Displays the full security incident form with classic UI fields.
Investigation tab: Provides an investigation experience canvas for analysts to track and analyze incident data.
Playbook tab: Displays automated response playbooks triggered via Process Automation Designer (PAD) based on set conditions.
Response Tasks: Lists all tasks associated with the incident response.
Related Records: Groups related lists such as business impact and threat intelligence for easy navigation.
Other Records: Displays IT records including change requests, incidents, problems, outages, and emails linked to the incident.
Post Incident Review tab: Available when the incident enters the Review state, containing assessments and reports.
Contextual menu: Provides quick access to actions like Activity Stream, Playbook, Analyst Assist, Runbook Templates, and Attachments across all tabs.
Form UI actions: Located at the top right of the form, enabling actions such as discussing, saving, creating tasks, sending emails, linking to major incidents, promoting incidents, associating MITRE ATT&CK techniques, switching UI views, and deleting records.
Security Incident Response Workspace Features
Investigation Canvas: Orchestrates activities for detailed incident analysis.
Response Tasks: Centralized view and management of all response-related tasks.
Other Records: Consolidates related IT and email records to provide full incident context.
Post Incident Review: Facilitates formal review processes once the incident is resolved.
Edit Related Records: Allows inline editing of related records without leaving the current workspace.
TISC Integration: Integrates Threat Intelligence Security Center data directly within the workspace for enriched threat context.
Reporting: Access to all incident-related reports for analysis and sharing.
Collaboration: Enables communication with analysts and affected users via conference calls or chat.
Visualization Tools
Relationship Graph: Visualizes connections between a security incident and related items for comprehensive context analysis.
MITRE ATT&CK and Defend Technique Graph: Interactive node-based visualization of attack and defense techniques linked to the incident for deeper threat understanding.
Practical Benefits for ServiceNow Customers
This structured and feature-rich security incident record enables security teams to:
Quickly access and update critical incident information.
Leverage automated playbooks to streamline response actions.
Coordinate incident investigations efficiently through integrated canvases and task management.
Enhance threat analysis with integrated threat intelligence and visual tools.
Collaborate seamlessly with stakeholders using built-in communication channels.
Conduct thorough post-incident reviews to improve future response strategies.
The Security Incident Record consists of the following.
Key components available on a security incident record:Figure 1. Key components of a security incident
Number
Name
Description
1
Security incident number
The security incident number is available against the tab name.
2
Short description
Short description of the security incident which is displayed above the form banner.
3
Form banner
This is read-only section, which contains the key fields such as Category, Priority, Risk score, State, and the incident assignment details.
Note:
The regular platform tags can be applied here as
well.
4
Security tags
Displays the security tags associated with a security incident.
5
Overview
Provides a snapshot overview of the security incident such as Description, Business Impact comprising of asset details by type, affected users by criticality, Threat intelligence items comprising of observables
by finding and by type, Response Tasks, Related security incidents comprising of child security incidents and similar security incidents.
6
Details
The details tab displays the security incident form.
7
Investigation
The Investigation tab displays the incident investigation experience.
8
Playbook
Playbook is triggered through Process Automation Designer (PAD). If a process is created, and if the a trigger condition is set to trigger the playbook for a security incident. Then a playbook appears.
9
Response Tasks
The Response Tasks captures all the response tasks associated with a security incident.
10
Related Records
The Related Records tab consists of all the related lists from the classic UI under this section. The related lists are grouped under various section such as business impact, threat intel, and so on for an easy
navigation.
11
Other Records
Other records tab consists of IT records such as changes requests, incidents, and emails grouped and displayed in this section.
12
Post Incident Review tab
As the security incident progresses to the Review state, the Post Incident Review tab is displayed with the post incident assessments and reports within the tab.
13
Contextual menu
Provides easy access to the quick actions and is available across all the tabs for the analyst to access whenever required.
The contextual menu provides easy navigation to the multiple resources such as:
Activity Stream
Playbook
Analyst Assist
Runbook
Templates
Attachments
14
Form UI actions
The various security incident form UI actions are displayed on the top right of the incident form. The available form UI actions are: