---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response Workspace

# Security Incident Response Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The ServiceNow®
Security Incident Response Workspace is a reimagined interface that provides a next-gen user experience for the security analysts and SOC managers. The security analysts can use this to manage the life cycle of security incidents
from an initial analysis to containment, eradication, and recovery.

## Get started with SIR Workspace {#sir-workspace-landing-page__id_wzz_vjx_fwb}

Select a tile to get started.

|-|-|
| [Explore Workspace Learn about SIR Workspace concepts and features](https://www.servicenow.com/docs/6f~buZ4IWr~lgKund9gWew "Explore Security Incident Response Workspace to understand how the security analysts and managers perform their day-to-day operations with an improved user experience, do a complete incident investigation, and get an overview of the security incidents, response tasks and SLAs assigned to the security analyst and team.") | [Admins using Workspace Configure SIR Workspace and features](https://www.servicenow.com/docs/J9oqRchaULP_jdm6V5rB3A "This section describes the configurations needed to work with the Security Incident Response Workspace.") |
| [Analysts using Workspace Learn how Analysts use SIR Workspace](https://www.servicenow.com/docs/Pvl3~WZ8LCYXV1VVFoh08w "Security Analysts and managers use SIR Workspace to perform day-to-day operations with an improved user experience, do complete incident investigation, and get an overview.") | [View SIR Dashboards View SIR Workspace dashboards](https://www.servicenow.com/docs/hyW4HP0TVEyiWaxR5kw0Fg "This section present the important metrics to analyze your Security Incident Response process such as new security incidents or the average age of open security incidents.") |
[ ]

{#sir-workspace-landing-page__table_sxm_bbz_xtb}

## Request apps on Store {#sir-workspace-landing-page__parent-topic-send-to-store}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release
notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#sir-workspace-landing-page__inline-send-to-store}  
Important:  
* Installing the Security Incident Response 13.4.5 version or later from the ServiceNow Store will automatically install the Security Incident Response Workspace (sn_si_aw) 1.5.1 version or later by default. For more information on the dependent applications, refer to the [SIR Workspace plugins](https://www.servicenow.com/docs/DT9niT7CHKbBFZbGrlMamw "The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.") section.
* Please note that the Security Incident Response Workspace versions 1.5.1 and above can only be installed/upgraded through an installation/upgradation of Security Incident Response and can't be installed independently.
{#sir-workspace-landing-page__ul_ipb_3mz_dcc}

## More resources {#sir-workspace-landing-page__section_zxm_bbz_xtb}

Visit the [Security Incident Response
forum on the ServiceNow Community.](https://www.servicenow.com/community/secops-articles/tkb-p/security-operations-kb/label-name/security%20incident%20response?labels=security%20incident%20response)

