---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response Post Incident Review

# Security Incident Response Post Incident Review {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Post incident review appears when an incident is moved to a Review state.

For more detailed information on the conducting the post incident activities, see [Post incident review report](https://www.servicenow.com/docs/P6NdbvqylV38D5e7Ypg_TA "The Post Incident Review (PIR) reports feature enables you to set up and download the post incident review reports using the Post Incident Review tab.")

The Post incident review consists of the following sections:

1. Assessments
2. Reports

{#security-incident-response-post-incident-review__ol_x5s_fdx_x5b}  
From the Security Incident Response workspace, you will be able to request and take assessments using these new two UI actions.{#security-incident-response-post-incident-review__table_vxk_t2x_x5b__entry__2}

| Name | Description |
|-|-|
| Assessments | Assessment displays all the assessments that are associated with the security incident other assessments. The analyst will be able to take assessments and request assessments. * Take assessments: Click on Take assessments to take the assessments (if applicable) and complete the assessment. Before completing the assessment, the security incident state is Ready to take and Due date of the incident is indicated in Red. * Request assessments: Click on Request assessment for any additional assessments and you can add the new users whom you want to request. Note: Users who had already requested will not appear in this section. Any assessment for this incident has been configured based on the conditions set on the Post Incident Review, it be either mandatory or optional. {#security-incident-response-post-incident-review__ul_u2r_zfx_x5b} |
| Reports | Modify the runtime configurations and generate the report. Select the Report instance, modify the filters and save the report. The analyst can preview and download the PIR report. |
[ ]

{#security-incident-response-post-incident-review__table_vxk_t2x_x5b}
**Related concepts**   

* [Security Incident Overview section](https://www.servicenow.com/docs/FKdF0FKsLkc1LTLhuSgk4w "The Overview section on the workspace presents the key information associated with the security incident.")
* [Security Incident Details section](https://www.servicenow.com/docs/vhI80oW9WEkFU4iLIo56ag "This section displays the security incident form fields that are rendered from the security incident classic UI.")
* [SIR Workspace Orchestration](https://www.servicenow.com/docs/kZaelya9p~1bW3C4md4wQw "Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.")
* [Security Incident Response Tasks](https://www.servicenow.com/docs/poXcxG_IY52isqVB69uZyg "All the response tasks associated with a security incident are displayed within the Response Tasks section.")
* [Security Incident Response Other Records](https://www.servicenow.com/docs/l8okmX47QRzqkQmEmlL0pQ#security-incident-response-other-records "This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.")
* [TISC integration within SIR Workspace](https://www.servicenow.com/docs/R8vQjkmxUTHpPF0xDNBnnA "The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.")
* [Reports in Security Incident Response](https://www.servicenow.com/docs/FAuzcZBVQsq1m9_4D40mLg "All the reports associated with a security incident are available within the Reports section for analysis and sharing.")
* [Collaborate using conference call or chat in Security Incident Response](https://www.servicenow.com/docs/RbWdIaMFprlz1ibGvAjEjQ "You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.")
* [Viewing incident details with a relationship graph](https://www.servicenow.com/docs/9InlzSjKbNMpdf_N5qywIQ "Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.")
* [MITRE attack and defend technique graph](https://www.servicenow.com/docs/zETV8NNZ4IxMxRKrDupx4w "The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.")  
**Related tasks**   

* [Update information in security incident related records](https://www.servicenow.com/docs/ISpHgHQu8W6FVBLnk3s0pg "Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.")
* [View and filter the incident timeline](https://www.servicenow.com/docs/5_fCN2qfg8gvZM7uqhjuGg "View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.")

