---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Link additional records to Major Security Incident

# Link additional records to Major Security Incident {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In the workspace, use the linking records functionality to link any related Security Incident records and its child security incidents, Remediation Tasks from Vulnerability Response, and Security Cases from Threat Intelligence
to a Major Security Incident (MSI) record.

## Before you begin

Role required: sn_msi.workspace_manager and sn_msi.workspace_responder

## Procedure

1. Navigate to Major Security Incident ResponseMSIM Workspace.
2. Navigate to the Lists view, which is displayed in the left pane of the workspace.
3. Click Accepted to select the promoted major security incident records.
4. Select the incident record that is required to be linked which is not in the Closed state from the list of promoted records.
5. Click Linked Records tab.  
   A drop-down list is provided to select other linked record tables.  
   The Linked Records section displays the linked records and its related records, which were linked to the Major Security Incident.
6. Select the desired table view such as Security Incidents, Remediation Tasks (vulnerable items), or Security Case from the list.  
   Based on your selection type records table view, the linked records that linked to the major security incident records are displayed.
7. Link a record that is not linked to any MSI record and is in the Open state by selecting the record and clicking Link Record in the top right of the page.  
   Note:  
   You can't link an incident record to an MSI record if it's in the Closed state.
8. Select the record to be linked and click Link.  
   A confirmation message displays that the record is linked successfully and the rollup of related records will be processed in the background.  
   Note:  
   After a record is linked, the list view is refreshed automatically and lists the updated list of incident records.
{#linking-additional-records-to-major-security-incidents__steps_mtr_5jw_g5b}
**Related concepts**   

* [Propose, promote, and link incident records](https://www.servicenow.com/docs/MboWejSsp~zn2BO9Br2rGw "Propose or promote security incidents as major security incidents when incidents are identified as critical threat to the organization.")
* [View Major Security Incident impact metrics](https://www.servicenow.com/docs/75nwdoi9EgPPNjaahVBQXA "Provides up-to-date summary reporting of the impact and progress of major security incidents, which is an important aspect of managing a major security incident using the new workspace.")
* [View Major Security Incident trend charts](https://www.servicenow.com/docs/801UFkcn4TIBkW4fA~uHTg "View the major security incident impact progress metrics visualized as bar graphs and charts.")
* [Update Major Security Incident details](https://www.servicenow.com/docs/zFJcVLrFR9JApVmc512xvg "View and update specific details related to the major security incident such as Incident Record Details, Active Team participants, and the corresponding activity log.")
* [Manage tasks in a Major Security Incident](https://www.servicenow.com/docs/5997jGRwqBVzl6tfMUqOIA "The Task tab enables you to track and manage all the tasks associated with a major security incident from the MSIM workspace. You can view the various tasks using the default Visual Task Board (Kanban view) or the List view.")
* [Track collaboration activity via MSIM workspace](https://www.servicenow.com/docs/HUxZheo_2hESfpYeH2MnOQ#collab-tab "Track chat and file activities related to resolving major security incidents through the MSIM Workspace.")  
**Related tasks**   

* [Using MSI List view in the MSIM workspace](https://www.servicenow.com/docs/09pyM6z1aEItnfdwA_mbxg "With the list view in the MSIM workspace, you can view proposed, promoted, and rejected major security incidents.")
* [Unlink records from Major Security Incident](https://www.servicenow.com/docs/X1XdnnLwA_1aWV5Zg3CphQ "Using the Major Security Incident Management workspace, unlink the major security incident records from the Linked Records section.")
* [Create and distribute MSIM Status Reports](https://www.servicenow.com/docs/TrmrGo3e8s6gEHrTa0RHWQ "As a Major Security Incident (MSI) manager, you can create and distribute the different status reports to different stakeholders at various intervals based on the configured report template or a previous status report throughout the course of the major security incident resolution.")
* [Unlink records from Major Security Incident](https://www.servicenow.com/docs/X1XdnnLwA_1aWV5Zg3CphQ "Using the Major Security Incident Management workspace, unlink the major security incident records from the Linked Records section.")

*[\>]: and then


