Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Update Major Security Incident details

View and update specific details related to the major security incident such as Incident Record Details, Active Team participants, and the corresponding activity log.

All the related details of the major security incident are displayed with various Form sections on the Details tab of the workspace. Displays the details such as Incident Record Details, Active Team participants, and the corresponding activity log. You can also view the linked SIR incidents, Vulnerability Group record details, and an ability to broadcast an activity posting to all the linked incident records.

Primarily the Details tab contains:

  1. Major Security Incident Form fields and incident-related UI sections.
  2. Activity stream

The following table provides the details of the major security incident form fields:

FieldDescription
Incident
NumberMajor security incident record number.
Primary stateThe primary state of the major security incident record.
Detection DateThe date when the major security incident was first created or proposed.Whenever you modify the Detection date on the Details tab, the date and time of the MSI is automatically calculated, refreshed, and displayed on the Time > Time since the incident started section on the Overview section of the workspace.
TitleTitle of the Major security incident.
Code nameCode name for the major security incident. For example, Blue Tiger.
Next update onThe date and time of the next update for resolving the major security incident. For example, 5:00 pm EST on March 25, 2024.
CategoryCategory of the major security incident.
Sub categorySubcategory type of the major security incident.
Estimated resolution dateThe estimated date by when the incident is expected to be resolved. The default value is 7 days from the time of the major security incident creation.
PriorityPriority of the major security incident.
Alert sensorAlert sensor of the major security incident. For example, User Reported Phishing.
SourceSource of the major security incident.
Active Team
Incident ManagerName of the incident manager.
Assignment GroupsIndicates the different response teams and team members from each team who are actively working on the major security incident.
Candidate
MSI candidate stateIndicates the major security incident candidate state such as proposed or promoted. If the incident is promoted, then the state is displayed as Accepted.
Promoted byUser who had promoted the major security incident.
PromotedDate when the major security incident was promoted.
JustificationJustification of the major security incident. The justification should include the MSI number and the code name.
Potential impactThe potential impact and severity of the major security incident. The Potential impact should include the MSI number and the code name.
Restriction
Enforce restrictionSelect this option to enforce restrictions on certain major security incident restrictions. You can enforce restrictions to limit the view or modify access only to certain users or groups. For more information, see Restrict access to certain major security incidents.
Allowed membersList of users who can access the major security incident.
Allowed groupsList of groups who can access the major security incident.
Other actions
AttachmentAny attachments related to the major security incident.Select Select option to add attachments to the incident.
Conference CallUse conference calls with the third-party service providers as a communication channel to meet with the stakeholders to resolve the major security incidents. For more information, see Major Security Incident Management Conference Call Integration

Activity:

Use the Activity section to add your work notes and comments, and post your activity privately and also add additional comments as required using the Compose section. Save the activity after you post your work notes and comments to view the added activity or work notes in the Activity section.

Note: Select the Show more details link to view the details of a specific security incident record, which are associated with that major security incident.

Set your preferences to view the related activities such as:

  1. Filters: Select the Filter sets icon to set filters.

    Set filters to view the activity conversations such as activities added on the work notes, email, Timeline, and any additional comments.

  2. Flagged: Select the Flagged icon to flag the activities.

    Flag any important activity conversations for you to keep them handy.

  3. Restrict access to certain major security incidents
    Manage who can view or modify major security incidents that contain sensitive information. You can enforce major security incident restrictions to determine who has access to view or modify certain major security incident records and related lists and limit the read or write access only to certain users or groups.

Parent Topic:Using Major Security Incident Management

Related topics

Propose, promote, and link incident records

Using MSI List view in the MSIM workspace

View Major Security Incident impact metrics

View Major Security Incident trend charts

Link additional records to Major Security Incident

Unlink records from Major Security Incident

Manage tasks in a Major Security Incident

Track collaboration activity via MSIM workspace

Create and distribute MSIM Status Reports