---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Change management for Vulnerability Response

# Change management for Vulnerability Response {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

As an IT remediation owner, you can create and manage change requests (CHG) directly from remediation tasks (RT) in the Vulnerability Response application. Change requests help you initiate and track change activities on your assets so that you can remediate your remediation tasks and their corresponding vulnerable items.

## Change requests and the vulnerability workflow {#vuln-change_mgmnt_ovrvw__section_nf1_lck_x3b}

If you are not familiar with the Vulnerability Response application, for more information see [Exploring the Vulnerability Response application](https://servicenow-prod.fluidtopics.net/KAvmypVLSlLueEfclf8vZg "The ServiceNow Vulnerability Response application imports and automatically groups vulnerable items according to rules that permit you to remediate vulnerabilities quickly. Vulnerability data is pulled from external sources, such as the National Vulnerability Database (NVD) and third-party integrations, and processed with applications developed by ServiceNow.").

The following image illustrates the flow of information for Vulnerability Response, from integration (scanner) set up through automated triage and into investigation.

Change requests and change management are part of the remediation process (Assess/Fix state) in the Vulnerability Response workflow shown in the following figure. During this phase, you might use change requests to initiate and track the remediation of vulnerabilities. You can create and manage change requests directly
from the remediation task and list investigation and remediation tasks that include solutions for impacted assets for the configuration items (CI) in your CMDB.
Figura 1. Change requests in Vulnerability Response

## When to use change requests in vulnerability response {#vuln-change_mgmnt_ovrvw__section_vwv_nck_x3b}

As an IT remediation owner, you might create change requests from a remediation task if a manual and controlled process of any kind is required for modification or removal of supported configuration items (CIs) in your CMDB.
Creating and managing change requests directly from a remediation task record helps you investigate and resolve vulnerabilities quickly. The VIs of a resolved remediation tasks can be scanned and verified during the next
scheduled scan in your ServiceNow AI Platform and returned to the automated triage of the Vulnerability Response workflow. Manual interventions that might require change requests include the following examples:

* A software patch, fix, or other task by IT that is required on vulnerable items prior to RT resolution.
* You determine a subset of the vulnerable items in a remediation task requires further investigation or reassignment to another department.
* You determine that a subset of vulnerable items in a RT with a large set of vulnerable items can be moved into a new remediation task.
* You might associate a remediation task to an existing change request to avoid duplication of remediation tasks.
{#vuln-change_mgmnt_ovrvw__ul_ipn_lbs_cjb}

## Types of change requests for an RT {#vuln-change_mgmnt_ovrvw__section_rg2_1hk_x3b}

The Vulnerability Response application utilizes the three types of service changes supported by the ITSM
Change Management product on your ServiceNow AI Platform® instance --- standard, emergency, and normal. The type of change you select determines which state model is invoked and the change process that must be followed. Change requests record the
detailed information about the change, such as the reason of the change, the priority, the risk, the type of change, and the change category. See [Change types](https://www.servicenow.com/docs/access?context=change-types&version=australia&pubname=australia-it-service-management&ft:locale=en-US).  
As a Vulnerability Response IT remediation owner, you have the following options for creating normal, standard, and emergency change requests directly from a remediation task:

* You can create change requests that contain pre-populated information from the remediation task to streamline the process and save time.
* You can associate a remediation task to an existing change request to avoid creating duplicate change requests that share similar information and vulnerable items.
* Using a set of conditions, you can filter out a subset of vulnerable items and split a remediation task. The items that you select are automatically moved to a new RT.
{#vuln-change_mgmnt_ovrvw__ul_apq_3td_x3b}

You can filter vulnerable items using values from any fields from a remediation task and apply the change request to only those items that match your filter criteria.
**Conceitos relacionados**   

* [State synchronization between change requests and remediation tasks](https://servicenow-prod.fluidtopics.net/4mYP6HpuKLR4HaCv8ed66Q "There is a synchronized relationship between the State fields of remediation tasks (VULs) and the State fields of change requests (CHG) in the Vulnerability Response product. As a change request moves through its life cycle, it also moves the state of any related remediation tasks automatically.")  
**Tarefas relacionadas**   

* [Create a change request from a remediation task](https://servicenow-prod.fluidtopics.net/3Iv8v_ZZh2c3qNk7tjb9eQ "As an IT remediation owner, create a change request (CHG) directly from a remediation task (VUL) for all the vulnerable items in the group. Create a change request with pre-populated information that includes the preferred solution to expedite your investigation for vulnerabilities that require manual intervention.")
* [Associate a remediation task to an existing change request](https://servicenow-prod.fluidtopics.net/T8XW1OrGlziGcDCCwILTig "As an IT remediation owner, avoid creating duplicate change requests (CHG) as you work to resolve your remediation tasks by associating a remediation task (VUL) to a change request that is already available in your instance.")
* [Split a remediation task](https://servicenow-prod.fluidtopics.net/0uvMFQDfdQueHGdrUSI73w "As an IT remediation owner, from an existing remediation task (VUL), identify a subset of vulnerable items (VI) that you want to move to a new group.")

