Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Working with Security Incident Records

The Security Incident Record consists of the following.

Key components available on a security incident record:

Image omitted: key-features-security-incident-record.png
Working with Security Incident Records
NumberNameDescription
1Security incident numberThe security incident number is available against the tab name.
2Short descriptionShort description of the security incident which is displayed above the form banner.
3Form bannerThis is read-only section, which contains the key fields such as Category, Priority, Risk score, State, and the incident assignment details.Note: The regular platform tags can be applied here as well.
4Security tagsDisplays the security tags associated with a security incident.
5OverviewProvides a snapshot overview of the security incident such as Description, Business Impact comprising of asset details by type, affected users by criticality, Threat intelligence items comprising of observables by finding and by type, Response Tasks, Related security incidents comprising of child security incidents and similar security incidents.
6DetailsThe details tab displays the security incident form.
7InvestigationThe Investigation tab displays the incident investigation experience.
8PlaybookPlaybook is triggered through Process Automation Designer \(PAD\). If a process is created, and if the a trigger condition is set to trigger the playbook for a security incident. Then a playbook appears.
9Response TasksThe Response Tasks captures all the response tasks associated with a security incident.
10Related RecordsThe Related Records tab consists of all the related lists from the classic UI under this section. The related lists are grouped under various section such as business impact, threat intel, and so on for an easy navigation.
11Other RecordsOther records tab consists of IT records such as changes requests, incidents, and emails grouped and displayed in this section.
12Post Incident Review tabAs the security incident progresses to the Review state, the Post Incident Review tab is displayed with the post incident assessments and reports within the tab.
13Contextual menuProvides easy access to the quick actions and is available across all the tabs for the analyst to access whenever required. The contextual menu provides easy navigation to the multiple resources such as: 1. Activity Stream 2. Playbook 3. Analyst Assist 4. Runbook 5. Templates 6. Attachments
14Form UI actionsThe various security incident form UI actions are displayed on the top right of the incident form. The available form UI actions are:- Discuss - Save - Create Response Task - Compose Email - Add Playbook - Open Associated Workflow\(s\) - Crete incident - Create Problem - Create Change Request - Create Outage - Calculate Severity - Link to Major Security Incident - Propose as Major Security Incident - Promote to Major Security Incident - Run Additional Action\(s\) on Endpoint - Associate MITRE ATT&CK Technique - Switch to Classic UI - Add to Security Case - Delete For more information, see Working with Form UI actions.

Parent Topic:Using SIR Workspace

Related topics

Security Incident Playbook

Prerequisites for the Playbooks

Rebuilding existing playbooks in Workflow Studio

Activity Definitions

Sample Playbooks for SIR Workspace

Working with MSI Records

Working with Form UI actions

Security Incident Closure workflow

Handle security incidents using Advanced Work Assignment