---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Change policies based on security summary tables

# Change policies based on security summary tables {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
You can use the security conditions that are available in the base system or customize them based on your requirement.
The vulnerability severity conditions are present in the Fetch Risk Sonar Security and Incident data action in the DevOps Gather Change Policy Data subflow of the DevOps Default Change
Request flow.

If the severity condition is classified as HIGH or VERY HIGH from Veracode or Checkmarx, then the change request is automatically rejected.

If you are an upgrading customer and you want to customize the conditions with any additional security data or change the existing conditions, you must update the script in the Fetch Risk Sonar Security and Incident data action in the change flow. Ensure that you are referring to the Application Vulnerability Scan Summary Details (sn_vul_app_vul_scan_summary_details) table in the script when you customize. For
more information, see [Security scan results](https://servicenow-prod.fluidtopics.net/lFOZN4q9l4hz~6IV6W6Kfw "Security scan results display scan details from security scans configured on your GitHub Actions, Jenkins, Azure DevOps, GitLab, or Harness pipelines.").

