---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Grouping multiple findings as remediation tasks for easy processing using remediation task rules

# Grouping multiple findings as remediation tasks for easy processing using remediation task rules {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Remediation tasks help vulnerability analysts and remediation teams manage findings in bulk. By configuring remediation task rules, you can automatically group findings into remediation tasks, eliminating the need for manual
task creation and streamlining remediation efforts.  
Remediation task rules define how findings are grouped into tasks. A default rule based on vulnerability is included in the system, but rules can also use other attributes such as:

* Vulnerability severity or summary
* Configuration item (CI) or product model
* Assignment group
* Risk score
* Technology or attack vector

{#sem-grouping-multiple-findings-remediation-tasks-processing__ul_gky_jv2_xfc}You can define up to six "Group by" criteria and apply multiple conditions. Once a match is found, the system either adds the finding to an existing Open remediation task or creates a new one. These rules apply to newly created findings or the ones updated with attributes that impact task assignment: Task rules can be reapplied to update groupings as needed. Rules are evaluated after CI matching, risk calculation, and assignment.  
Nota:  
Excessive rules may impact performance. Ensure that rules are optimized to avoid duplication and inefficiency.️

## How remediation task rules work {#sem-grouping-multiple-findings-remediation-tasks-processing__section_ejv_5gs_fgc}

When a new finding is created, imported, or reopened, the system evaluates it against the defined remediation task rules. For each rule where the condition matches, the system pulls the relevant data from the "Group by" selections
and builds a group name. If a matching open remediation task exists, the finding is added to it. Otherwise, a new task is created. By default, remediation task rules use the assignment group set by the assignment rules on the
finding. The assignment of these remediation tasks is controlled by the assignment rules. When a task rule is deleted, you have the option to delete all open tasks created by that rule.

## Managing remediation task rules {#sem-grouping-multiple-findings-remediation-tasks-processing__section_brs_hw2_xfc}

Remediation rules: Use the Reapply button on the rule form to rerun the rule on all open remediation tasks it created. The reapplication process deletes and recreates tasks based on the
updated rule.

Deleting rules: When deleting a rule, you may also delete the open tasks created by it. Tasks not in the Open state remain unaffected.

## Creating and managing remediation tasks {#sem-grouping-multiple-findings-remediation-tasks-processing__section_zql_ggg_xfc}

Remediation tasks can be created in the following ways:

* Automatically using remediation task rules (recommended for efficiency).
* Manually in the IT Remediation Workspace. For more information, see [Create a remediation task manually in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/bkRMHS3TkEC52sbB5gjGTg "Starting with v25.0.4 of Vulnerability Response, you can create remediation tasks manually from the Host vulnerable items, Application Vulnerable items, Container vulnerable items, and Configuration test results lists on the List page of IT Remediation Workspace.").
{#sem-grouping-multiple-findings-remediation-tasks-processing__ul_n5v_hgg_xfc}

## State synchronization {#sem-grouping-multiple-findings-remediation-tasks-processing__section_ckd_j4g_xfc}

* Rolldown: When a remediation task state changes (for example, from Open to Under Investigation, this change is pushed to all associated findings.)
* Rollup: When all associated findings share a common terminal state (for example, Deferred, Closed - Fixed), their state rolls up to the remediation task. Rollup jobs run at scheduled intervals (for example, every 15 minutes).
{#sem-grouping-multiple-findings-remediation-tasks-processing__ul_tby_k4g_xfc}

## Assignment management {#sem-grouping-multiple-findings-remediation-tasks-processing__section_y12_y4g_xfc}

Assignment groups and assignees from remediation tasks are rolled down to associated findings unless those findings already have different assignments. This roll down helps standardize ownership across all related records.
**Conceitos relacionados**   

* [Configuring remediation task rules](https://servicenow-prod.fluidtopics.net/JKAykFk_uKohV_7OZ0f7Bw#sem-configure-remediation-task-rules "By configuring remediation task rules, you can automatically group findings based on filter conditions.")

