---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Details section

# Security Incident Details section {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This section displays the security incident form fields that are rendered from the
security incident classic UI.

The Classic UI has a view called SIRW View created. This view is mapped to the Details tab in the workspace. Any customizations that are required need to be implemented in this
view.

The form fields are grouped into the following sections and displayed on the Details tab form view. Select any of the section or jump to the respective section within the form:

* Security Incident
* Priority
* Source
* Parent
* Assignment
* Access Controls
* Affected Items
* Restriction
* Resolution

{#security-incident-details__ul_sv4_vkg_y5b}

The Details tab contains the Activity stream section within the details form itself for a quick access to the security analysts to add any comments and post
it. Additionally, you can also use the Email option, to send email about this security incident to the necessary stakeholders.  
Figure 1. Details tab and Activity stream

View the SIR Analyst Workspace view:  
1. Navigate to AllSecurity IncidentShow Open incidents.
2. Select any security incident record.
3. Select the context menu and select Viewsirw.  
   Note:  
   You can customize using sirw workspace view in the classic UI form.
4. The security incident workspace view is rendered as shown below.Figure 2. SIR workspace view
5. On the Security Incident record, right click and go to ConfigureForm Layout.
6. Drill down to the Form view and section and select New from Section to create a new section.
7. Provide the new section name and select OK.

   For example, Incident form.
8. The new section is created and added to the Section.
9. Select your new section and add the required section fields to the slush bucket and select Save.
10. The newly added section is displayed along with the existing section layout within the security incident form.
11. Select Switch to SIR workspace to jump to the security incident form and the customized section within the Details tab of the workspace.
{#security-incident-details__ol_cxc_g2v_x5b}
* **[Security incident Details tab](https://www.servicenow.com/docs/_O6xo1juNVILe5JKkiHZ4Q)**   
  This section describes all the fields of the Details tab of a security incident.

**Related concepts**   

* [Security Incident Overview section](https://www.servicenow.com/docs/FKdF0FKsLkc1LTLhuSgk4w "The Overview section on the workspace presents the key information associated with the security incident.")
* [SIR Workspace Orchestration](https://www.servicenow.com/docs/kZaelya9p~1bW3C4md4wQw "Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.")
* [Security Incident Response Tasks](https://www.servicenow.com/docs/poXcxG_IY52isqVB69uZyg "All the response tasks associated with a security incident are displayed within the Response Tasks section.")
* [Security Incident Response Other Records](https://www.servicenow.com/docs/l8okmX47QRzqkQmEmlL0pQ#security-incident-response-other-records "This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.")
* [Security Incident Response Post Incident Review](https://www.servicenow.com/docs/V7~SfbbWbuVlv4H3ZSH7yQ "Post incident review appears when an incident is moved to a Review state.")
* [TISC integration within SIR Workspace](https://www.servicenow.com/docs/R8vQjkmxUTHpPF0xDNBnnA "The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.")
* [Reports in Security Incident Response](https://www.servicenow.com/docs/FAuzcZBVQsq1m9_4D40mLg "All the reports associated with a security incident are available within the Reports section for analysis and sharing.")
* [Collaborate using conference call or chat in Security Incident Response](https://www.servicenow.com/docs/RbWdIaMFprlz1ibGvAjEjQ "You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.")
* [Viewing incident details with a relationship graph](https://www.servicenow.com/docs/9InlzSjKbNMpdf_N5qywIQ "Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.")
* [MITRE attack and defend technique graph](https://www.servicenow.com/docs/zETV8NNZ4IxMxRKrDupx4w "The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.")  
**Related tasks**   

* [Update information in security incident related records](https://www.servicenow.com/docs/ISpHgHQu8W6FVBLnk3s0pg "Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.")
* [View and filter the incident timeline](https://www.servicenow.com/docs/5_fCN2qfg8gvZM7uqhjuGg "View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.")

*[\>]: and then


