Security Incident Details section
This section displays the security incident form fields that are rendered from the security incident classic UI.
The Classic UI has a view called SIRW View created. This view is mapped to the Details tab in the workspace. Any customizations that are required need to be implemented in this view.
The form fields are grouped into the following sections and displayed on the Details tab form view. Select any of the section or jump to the respective section within the form:
- Security Incident
- Priority
- Source
- Parent
- Assignment
- Access Controls
- Affected Items
- Restriction
- Resolution
The Details tab contains the Activity stream section within the details form itself for a quick access to the security analysts to add any comments and post it. Additionally, you can also use the Email option, to send email about this security incident to the necessary stakeholders.
Malicious code activity view: Details tab.
View the SIR Analyst Workspace view:
- Navigate to All > Security Incident > Show Open incidents.
- Select any security incident record.
Select the context menu and select View > sirw.
Note: You can customize using sirw workspace view in the classic UI form.
Classic UI security incident
- The security incident workspace view is rendered as shown below.
Security incident in SIR workspace view
- On the Security Incident record, right click and go to Configure > Form Layout.
- Drill down to the Form view and section and select New from Section to create a new section.
Provide the new section name and select OK.
For example, Incident form.
The new section is created and added to the Section.
- Select your new section and add the required section fields to the slush bucket and select Save.
- The newly added section is displayed along with the existing section layout within the security incident form.
Select Switch to SIR workspace to jump to the security incident form and the customized section within the Details tab of the workspace.
Security incident Details tab
This section describes all the fields of the Details tab of a security incident.
Parent Topic:Working with Security Incident Records
Related topics
Security Incident Overview section
Security Incident Response Tasks
Security Incident Response Other Records
Security Incident Response Post Incident Review
Update information in security incident related records
TISC integration within SIR Workspace
Reports in Security Incident Response
Collaborate using conference call or chat in Security Incident Response
Viewing incident details with a relationship graph