---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuring remediation target rules

# Configuring remediation target rules {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 min. de leitura

By configuring remediation target rules, you can set the expected time frame for addressing findings, similar to how service level agreements (SLAs) set deadlines for fixing vulnerabilities.  
The base system ships with three remediation target rules that are applicable only for application vulnerable items:

* Critical Risk Rating Rule: A remediation target with a 1-Critical risk rating, a remediation target of 15 days, and a reminder of 7 days before the target date.
* Less Critical Risk Rating Rule: A remediation target with either a 2-High or 3-Medium risk rating a remediation target of 30 days, and a reminder of 7 days before the target date.
* Medium-High RIsk Rating Rule: A remediation target with a 4-Low risk rating a remediation target of 45 days, and a reminder of 7 days before the target date.
{#sem-configure-remediation-target-rules__ul_ams_15c_5fc}These rules are inactive by default. If you choose to edit one, rather than create a new one, remember to check the Active box before saving.
**Conceitos relacionados**   

* [Defining your own service level agreements (SLAs) using remediation target rules](https://servicenow-prod.fluidtopics.net/alRGFurQAfVHRs~TQtX95A "Remediation target rules set the expected time frame for addressing findings, similar to how service level agreements (SLAs) set deadlines for fixing vulnerabilities. You can also send notifications to users and groups when target dates are approaching and when they are past due.")

## Create or edit remediation target rules {#ariaid-title2}

Create remediation target rules to ensure the timely remediation of high-risk vulnerabilities by setting up a remediation target rule at the findings level.

### Antes de Iniciar

Role required: See [Access control lists (ACLs) for administration rules](https://servicenow-prod.fluidtopics.net/OOZfh~3y7q7~R6CPggT5cg "You can either view or modify the administration rules based on the roles assigned to you.")

### Procedimento

1. Navigate to WorkspacesSecurity Exposure Management Workspace.
2. Select Administration in the navigation pane.
3. Select Review on the Remediation target rules tile.
4. On the Rules page, select Remediation target in the navigation pane.
5. Select New.
6. On the remediation target rule form, enter the required details.  
   For a full description of each field, see [Remediation target rule fields](https://servicenow-prod.fluidtopics.net/lKAXay0mx8q3UVtewXFR6w "Use remediation target rules to define how remediation timelines are calculated and maintained for findings. Administrators can configure base target dates and recalculation behavior when risk ratings change. The following table describes all fields available in the remediation target rule form.").
7. Select Save.  
   This rule goes into effect during the next run of the scheduled job, Evaluate remediation targets or when using the Reapply button on the Remediation target rules list view.
   The same is true when an existing rule is updated.
{#sem-create-edit-remediation-target-rules__steps_ush_xnz_nfc}
**Tarefas relacionadas**   

* [Create or edit remediation target rules](https://servicenow-prod.fluidtopics.net/FKXELFUUbjfzFZ1oPFioJw#sem-create-edit-remediation-target-rules "Create remediation target rules to ensure the timely remediation of high-risk vulnerabilities by setting up a remediation target rule at the findings level.")
* [Recalculate a remediation target date](https://servicenow-prod.fluidtopics.net/FKXELFUUbjfzFZ1oPFioJw#sem-recalculate-rt-date "The remediation target (RT) date defines when a finding must be remediated. Recalculation verifies that RT dates stay accurate and reflect the latest risk rating updates. When a finding’s risk rating changes, the system can recalculate RT dates using the most recent update date, helping maintain accurate SLAs and avoid outdated or overdue target dates.")  
**Referência relacionada**   

* [Examples of recalculating a remediation target date](https://servicenow-prod.fluidtopics.net/FKXELFUUbjfzFZ1oPFioJw#sem-recalculate-rt-date-examples "The following examples show how the system recalculates the remediation target date based on different rule selections and risk rating changes.")

### Recalculate a remediation target date {#ariaid-title3}

The remediation target (RT) date defines when a finding must be remediated. Recalculation verifies that RT dates stay accurate and reflect the latest risk rating updates. When a finding's risk rating changes, the system can
recalculate RT dates using the most recent update date, helping maintain accurate SLAs and avoid outdated or overdue target dates.

#### Antes de Iniciar

Nota:  
By default, recalculation applies only to findings that aren't overdue. To include overdue findings in the recalculation, enable the sn_sec_cmn.evaluate_targetmissed_records system property.

Role required: admin

#### Procedimento

1. Navigate to Security Exposure ManagementAdministrationRemediation Target Rules.
2. Open an existing rule to make updates.  
   If you need to create a new rule, select New.
   For instructions, see [Create or edit a Vulnerability Response remediation target rule](https://servicenow-prod.fluidtopics.net/SFqGqxkr6LzNUo8IADts~A "Set up remediation target rules after completing your initial assessment in the Setup Assistant. Vulnerability managers can set up a remediation target rule at the vulnerable item level to drive the remediation of high-risk vulnerabilities in a timely manner. When the remediation date for a vulnerable item is approaching, the system sends a notification to the users or groups specified in the rule.").
3. Choose how the system should recalculate the remediation target (RT) date when the risk rating changes.  
   * In Workspace, this option appears in the Recalculate target date section
   * In Classic view, use the Target recalculation method field.
   {#sem-recalculate-rt-date__ul_xm1_cwr_3hc}

   | Choice | Description |
   | Default calculation | Retains the existing RT date. The recalculated date isn't applied. |
   | Recalculate from risk change date | Updates the Remediation Target date to: Field change time + Target (days) based on the new risk rating. |
   | Recalculate from risk change date and always set to earliest target date | Compares the existing RT date with Field change time + Target (days) and applies the earlier date. |
   | Recalculate from risk change date and set to earliest target date only when risk rating increases | If the risk increases: Compares the existing RT date and the recalculated RT date and applies the earliest date. If the risk decreases: Applies Field change time + Target (days) without comparison. |
   |-|-|

   {#sem-recalculate-rt-date__choicetable_bb3_q3b_fhc}
4. Select Save.

#### O que Fazer Depois

For more information on remediation target rules, see:

* [Vulnerability Response remediation target rules](https://servicenow-prod.fluidtopics.net/lgebnQz~f0bCtTdmAY4GcA "Remediation target rules define the expected time frame for remediating vulnerable items (VI), much like SLAs provide a time frame for remediating the vulnerability itself. For example, if an asset contains PCI data (credit card data) then the vulnerability on that item must be fixed within 30 days according to PCI DSS.")
* [Create or edit a Vulnerability Response remediation target rule](https://servicenow-prod.fluidtopics.net/SFqGqxkr6LzNUo8IADts~A "Set up remediation target rules after completing your initial assessment in the Setup Assistant. Vulnerability managers can set up a remediation target rule at the vulnerable item level to drive the remediation of high-risk vulnerabilities in a timely manner. When the remediation date for a vulnerable item is approaching, the system sends a notification to the users or groups specified in the rule.")
* [Examples of recalculating a remediation target date](https://servicenow-prod.fluidtopics.net/FKXELFUUbjfzFZ1oPFioJw#sem-recalculate-rt-date-examples "The following examples show how the system recalculates the remediation target date based on different rule selections and risk rating changes.")
{#sem-recalculate-rt-date__ul_fm5_5hb_fhc}

#### Examples of recalculating a remediation target date {#ariaid-title4}

The following examples show how the system recalculates the remediation target date based on different rule selections and risk rating changes.  
Nota:  
By default, SLAs define the remediation window for each risk level:

* Low risk: 30 days
* Medium risk: 15 days
* High risk: 10 days
{#sem-recalculate-rt-date-examples__ul_dg4_dhb_fhc}
{#sem-recalculate-rt-date-examples__table_xf5_cfb_fhc__entry__6}

| Target from (date) | Field change time | Initial risk (Target (days)) → New risk (Target (days)) | Existing RT date | Recalculated RT date | What happens |
|-|-|-|-|-|-|
| Default calculation ||||||
| Feb 1 | Feb 10 | Medium (15 days) → High (10 days) | Feb 16 (retained) | Feb 20 | The recalculated RT date isn't applied. The system keeps the original RT date: Target from (date) + Target (days) → Feb 1 + 15 = Feb 16. |
| Recalculate from risk change date ||||||
| Feb 1 | Feb 10 | Medium (15 days) → High (10 days) | Feb 16 | Feb 20 (applied) | Uses the recalculation formula: Field change time + Target (days) → Feb 10 + 10 = Feb 20. |
| Recalculate from risk change date and always set to earliest target date ||||||
| Feb 1 | Feb 10 | Medium (15 days) → Low (30 days) | Feb 16 (applied) | Mar 12 | Compares the existing RT date (Feb 16) with the recalculated date (Feb 10 + 30 = Mar 12) and selects the earliest date → Feb 16. |
| Recalculate from risk change date and set to earliest target date only when risk rating increases ||||||
| Feb 1 | Feb 10 | Low (30 days) → High (10 days) | Mar 3 | Feb 20 (applied) | Because the risk increased, the system compares the existing RT date (Mar 3) with the recalculated date (Feb 20) and applies the earlier date → Feb 20. |
| Feb 1 | Feb 10 | High (10 days) → Low (30 days) | Feb 11 | Mar 12 (applied) | Because the risk decreased, no comparison is performed. The system sets RT date to: Field change time + Target (days) → Feb 10 + 30 = Mar 12. |
[ ]

{#sem-recalculate-rt-date-examples__table_xf5_cfb_fhc}

