---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Risk score calculation example for Vulnerability Response

# Risk score calculation example for Vulnerability Response {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

You can determine the risk score calculators to generate risk scores that use the
vulnerability and asset data unique to your organization.

## Example of determining risk rule calculators scores {#vuln-calc-risk-rule-example__section_ck4_nf5_5pb}

The following example demonstrates how scores for risk rule calculators are determined.  
Assume that a risk rule calculator is configured with the fields in this table:{#vuln-calc-risk-rule-example__table_vdf_v5c_tpb__entry__3}

| Field | Weightage | Weight breakdown |
|-|-|-|
| Vulnerability.Severity | 50 | Default: 20 1 - Critical: 100 2 - High: 80 3 - Medium: 60 4 - Low: 40 5 - None: 20 |
| Vulnerability.Exploit Exists | 50 | Default: 50 Yes: 100 No: 0 |
[ ]

{#vuln-calc-risk-rule-example__table_vdf_v5c_tpb}Also, assume that the vulnerable items that are shown in this table are present in the system:{#vuln-calc-risk-rule-example__table_wm5_wvc_tpb__entry__3}

| ID | Vulnerability severity | Vulnerability exploit exists |
|-|-|-|
| VIT00001 | 1 - Critical | 1 - Yes |
| VIT00002 | 2 - High | 1 - Yes |
| VIT00003 | 3 - Medium | 2 -- No |
| VIT00004 | 4 - Low | 2 -- No |
| VIT00005 | 5 - None | 2 -- No |
[ ]

{#vuln-calc-risk-rule-example__table_wm5_wvc_tpb}The risk score calculation for the vulnerable items is calculated based on the formula:

`Risk Score = (W(severity) * FV (severity). + W(exploitexists) * FV(exploit exists))
/ 100`

where W is the weight and FV is the weight
percentage of the field value.

The resulting risk score for these vulnerable items is described in this table:
{#vuln-calc-risk-rule-example__table_pzl_hwc_tpb__entry__4}

| ID | Vulnerability severity (50%) | Vulnerability exploit exists (50%) | Resultant risk score |
|-|-|-|-|
| VIT00001 | 1 -- Critical (50% x 100) | 1 -- Yes (50% x 100) | 100 |
| VIT00002 | 2 -- High (50% x 80) | 1 -- Yes (50% x 100) | 90 |
| VIT00003 | 3 -- Medium (50% x 60) | 2 -- No (50% x 0) | 30 |
| VIT00004 | 4 -- Low (50% x 40) | 2 -- No (50% x 0) | 20 |
| VIT00005 | 5 - None (50% x 20) | 2 -- No (50% x 0) | 10 |
[ ]

{#vuln-calc-risk-rule-example__table_pzl_hwc_tpb}  
Nota:  
For VIT00005, because the value of the severity is empty, the default weightage is applied.

If the weightage percentage is changed for one of the field values, see this table for the
results:
{#vuln-calc-risk-rule-example__table_svk_ywc_tpb__entry__3}

| Field | Weightage | Weight breakdown |
|-|-|-|
| Vulnerability.Severity | 50 | * Default: 20 * 1 - Critical: 100 * 2 - High: 70 \*revised value * 3 - Medium: 60 * 4 - Low: 40 {#vuln-calc-risk-rule-example__ul_sfm_vcf_tpb} |
| Vulnerability.Exploit Exists | 50 | * Default: 50 * Yes: 100 * No: 0 {#vuln-calc-risk-rule-example__ul_vbj_ycf_tpb} |
[ ]

{#vuln-calc-risk-rule-example__table_svk_ywc_tpb}

The risk score for the vulnerable items after reapplying the calculator is shown in this
table:
{#vuln-calc-risk-rule-example__table_whl_xxc_tpb__entry__4}

| ID | Vulnerability severity (50%) | Vulnerability exploit exists (50%) | Resultant risk score |
|-|-|-|-|
| VIT00001 | 1 -- Critical (50% x 100) | 1 -- Yes (50% x 100) | 100 |
| VIT00002 | 2 -- High (50% x 70) \*revised value | 1 -- Yes (50% x 100) | 85 \*revised value |
| VIT00003 | 3 -- Medium (50% x 60) | 2 -- No (50% x 0) | 30 |
| VIT00004 | 4 -- Low (50% x 40) | 2 -- No (50% x 0) | 20 |
| VIT00005 | 5 - None (50% x 20) | 2 -- No (50% x 0) | 10 |
[ ]

{#vuln-calc-risk-rule-example__table_whl_xxc_tpb}

