Unlink records from Major Security Incident
Using the Major Security Incident Management workspace, unlink the major security incident records from the Linked Records section.
Before you begin
Role required: sn_msi.workspace_manager and sn_msi.workspace_responder
Note: You can only unlink a single record at a time. After you unlink a record, the related rolled up information will be removed from the Incident Impact and Threat Intelligence sections on the workspace and the action can't be undone.
For more information on roll up records, see Rollup Framework for MSIM.
Procedure
Navigate to Major Security Incident Response > MSIM Workspace.
Navigate to Lists view, which is displayed in the left pane of the workspace.
Select Accepted to select the promoted major security incident records.
Select the Linked Records tab.
This section displays the linked records and its related records, which are linked to the Major Security Incident.
Select the desired table view such as Security Incidents, Remediation Tasks (vulnerable items), or Security Case.
Select the record to unlink from the list view of records.
Select Unlink Record.
Unlink Record remediation task.
- A warning message is displayed asking if you want to unlink the selected record from MSI.
Unlink Record warning message.
Select Unlink Record.
The record is unlinked and once unlinked, the changes can't be reverted. The list view of Linked Records will be refreshed after unlinking.
Parent Topic:Using Major Security Incident Management
Related topics
Propose, promote, and link incident records
Using MSI List view in the MSIM workspace
View Major Security Incident impact metrics
View Major Security Incident trend charts
Update Major Security Incident details
Link additional records to Major Security Incident
Manage tasks in a Major Security Incident
Track collaboration activity via MSIM workspace
Create and distribute MSIM Status Reports
Configure Linked Records in Major Security Incident Management
Configure Rollup Records in Major Security Incident Management