Skip to content
Release: Australia · Updated: 2026-07-09 · Official documentation · View source

View affected items for a security incident

You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.

Before you begin

Role required: sn_si.basic

Procedure

  1. Navigate to Workspaces > Security Incident Response Workspace.

  2. Open the security incident for which you want to view affected items.

  3. Select the Related Records tab.

  4. Select Business Impact.

  5. Select any of the related lists to view or add information for the security incident.

TabDescription
Configuration ItemsAffected configuration items \(CI\). After affected CIs are identified, you can manually add affected resources from this related list.
Affected UsersAfter affected users are identified, you can manually add affected users from this related list.
Affected ServicesView or add business services associated with the security incident. Note: If an affected CI is added after the security incident is opened, select and hold (or right-click) in the form header and select Refresh Impacted Services.
Unmatched Affected UsersView or add the users who are affected by a security incident but cannot be matched to existing user records in the Users \[sys\_user\] table.
**Note:** If the [Security Operations Integration - Get Running Processes](../get-running-processes-capability.md) integration capability is active, and you add a CI to a security incident, the [Get Running Processes](../secops-integration-get-running-processes-workflow.md) workflow runs and retrieves a list of running processes on the CI.

If the [Security Operations Integration - Isolate Host](../isolate-host-capability.md) integration capability is active, you can select one or more CIs and restrict their system connections to other devices. To do this, select the check boxes for the CIs and select **Isolate Host** from the **Actions on selected rows** choice list.
  1. Selected any of the following related links to further update the security incident: