---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SIR Workspace plugins

# SIR Workspace plugins {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.

## Applications {#components-installed-with-analyst-workspace__section_pkm_hvz_v5b}

Installing the Security Incident Response application version 13.4.5 or later automatically installs the Security Incident Response Workspace and the following apps.

* Enterprise Security Case Management PAD Commons \[sn_escm_pad_cmn\]
* Security Operations Common Workspace \[sn_escm_ws_cmn\]
* Security Incident UI Card Component \[sn_sirw_evam\]
* Security Operations spoke \[sn_sec_spoke\]
{#components-installed-with-analyst-workspace__ul_klk_nh3_kyb}  
Important:  
* Installing the Security Incident Response 13.4.5 version or later from the ServiceNow Store automatically installs the Security Incident Response Workspace (sn_si_aw) 1.5.1 version or later by default.
* The Security Incident Response Workspace versions 1.5.1 and above can only be installed/upgraded through an installation/upgradation of Security Incident Response and can't be installed independently.
{#components-installed-with-analyst-workspace__ul_ipb_3mz_dcc}

Enterprise Security Case Management PAD Commons requires the
Playbook Experience \[playbook_experience\] plugin.

For information on the Security Incident Response roles, tables, properties, and scheduled jobs, see [Components installed with Security Incident Response](https://www.servicenow.com/docs/Bq5cClKVDRPSPABXKrKkGg "Several types of components are installed when you download and activate the Security Incident Response application, including user roles, tables, properties, and scheduled jobs.").
**Related concepts**   

* [SIR Workspace features](https://www.servicenow.com/docs/__YyqUaZiNskGidNTHwV8w "The Security Incident Response Workspace consists of the following key features.")
* [SIR Workspace interface overview](https://www.servicenow.com/docs/tEzXsrQyN21x4wLb~8cuYQ "The SIR Workspace Overview page consists of the Security Incidents and Response Tasks details that are under security analysts and their team.")
* [Upcoming section](https://www.servicenow.com/docs/BkzmzwxiZT0bh3Ov0kDDvQ "This section displays the upcoming tasks such as the security incidents and response tasks that are due as on the same day and next day.")
* [Quick links section](https://www.servicenow.com/docs/IxRg1x9rb4Y0E6czNSaUaA "Quick links work like bookmark links. You can add external URLs and quickly access them from within the workspace.")
* [Shift Handover Records section](https://www.servicenow.com/docs/w5wqFr9iA~DslfK_pIXPkA "The section displays the list of Shift Handover records in the Security Incident Response Workspace.")
* [List view in SIR Workspace](https://www.servicenow.com/docs/4wWu3eur8K08hLJNuRbjBQ "The list view consists of the security incidents, response tasks, phishing emails, and assessments.")

