---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View related items for a security incident

# View related items for a security incident {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 2, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can view related items, such as similar and child security incidents, related
users, vulnerability groups, and vulnerable items associated with a security
incident.

## Before you begin

Role required: sn_si.basic

## Procedure

1. If it is not already open, open the security incident for which you want to view related items.
2. Click the Show Related Items related link.
3. Click any of the related lists to view or add information for the security incident.  
   {#show-related-items-for-si__table_hng_51r_yy__entry__2}

   | Tab | Description |
   |-|-|
   | Child Security Incidents | Select a task record related to the issue that caused this security incident to be created. |
   | Similar Security Incidents | View any other security incidents associated with any of the same observable records. |
   | Related Configuration Items | Displays a list of security incidents containing configuration items with the same observable as this security incident. This list can be filtered using the CI exclusions filter group. When an observable is added to a security incident this list is automatically updated. By default, observables with a context type of Destination are excluded. |
   | Related Users | Displays a list of security incidents containing users with the same observables as this security incident. This list can be filtered using the User exclusion filter group. When an observable is added to a security incident this list is automatically updated. By default, observables with a context type of Destination are excluded. |
   | Related Filter Group | After configuration items are identified, any matching CI or Filter group are automatically added. |
   | Vulnerability Groups | If Vulnerability Response is activated, you can view vulnerability groups associated with this security incident. |
   | Vulnerable Items | If Vulnerability Response is activated, you can view vulnerability items associated with this security incident. |
   | Risks | If any of the core Risk Management plugins (Policy and Compliance Management, Audit, Management, or Risk Management) are activated, you can view or add risks associated with the security incident. You can add this related list from the form header context menu under ConfigureRelated Lists. |
   | Configuration item events | If Event Management is activated, you can view events. |
   | Configuration item alerts | If Event Management is activated, you can view alerts. |
   | Customer Service Cases | If Customer Service is activated, you can view Customer Service case information. |
   [ ]

   {#show-related-items-for-si__table_hng_51r_yy}
4. Click any of the following related links to further update the security incident:  
   * [Show Affected Items](https://www.servicenow.com/docs/XiFziSfy9LM9NKnCuPRc2w "You can view affected items, such as CIs, affected users, and affected services associated with a security incident.")
   * [Show IoC](https://www.servicenow.com/docs/Gmj8E~szVaA5i9rBzQXbVA "You can view IoC information, such as observables and sightings search results associated with a security incident.")
   * [Show Enrichment
     Data](https://www.servicenow.com/docs/gVdlQhjbILWmhe23CSL9OQ "You can view enrichment data, such as running processes, running services, and network statistics associated with a security incident.")
   * [Show Response
     Tasks](https://www.servicenow.com/docs/RJwD0tS~LAgfcJAdSNdX8Q "You can view response task information, such as task SLAs, risk score audits. and outages associated with a security incident.")
   {#show-related-items-for-si__ul_rxz_h1q_vz}
5. When you have completed your entries, click Submit.
{#show-related-items-for-si__steps_akt_2wc_wz}

*[\>]: and then


