- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-07-2022 12:25 AM
We would like to know which fields, if any, that if they are changed in a parent SIR, are also changed in its child SIRs.
It is just a question to understand the relationship between parent and child SIRs
Could you please help me on this.
Solved! Go to Solution.
- Labels:
-
Security Incident Response
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-07-2022 07:02 AM
Hi Srikanth,
All work notes recorded in the parent are propagated to any active children in Activities under the Incident Details tab. When a parent is closed or canceled, any active children are also closed or canceled. Any active Response Tasks on the child incident(s) are canceled. If there are no other open Tasks, the child incident is closed. When closed, the Post Incident Interview records the closure and the information found on the Closure Information tab is propagated from the parent to the children.
https://docs.servicenow.com/csh?topicname=perform-addtl-tasks-on-si.html&version=latest
Also a nice feature, if you install the Security Incident Response Spoke, is the Child Security Incident Automation Playbook. It rolls up the affected users and CIs to the parent security incidents, adds observables from the child incident to the parent security incident, and closes or cancels the child security incident when the parent security incident is closed. You will need to enable this Flow or copy and create your own.
https://docs.servicenow.com/csh?topicname=cj-sir-flow-library4.html&version=latest
- Brad
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-14-2022 10:12 PM
This is helpful. One of the main things we wanted to understand was if any of the other fields were changed in a parent, if their corresponding field in the child tickets would change, too. For example, Incident Category, Detection Source, Impacted Region, etc.