---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create or edit Application Vulnerability Response assignment rules

# Create or edit Application Vulnerability Response assignment rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can create rules to automatically assign application vulnerable items (AVIs)
based on filter conditions. These rules assign AVIs as they are imported or manually
created.

## Before you begin

Role required: App-Sec Manager group

## About this task

With assignment rules, you define the condition of assignment and the order of
execution. Once an AVI matches a rule condition, the assignment lookup stops. See
[Filtering within Application Vulnerability Management](https://servicenow-prod.fluidtopics.net/MXVWRbuZvpPnH7bFBWJH~A "Calculators, and Assignment Rules use conditions during import, created using the condition builder. Changes to their criteria can affect performance since each record is evaluated using these filters.") for
more information.

## Procedure

1. Navigate to AllApplication Vulnerability ResponseAdministrationAssignment Rules.
2. Click New.
3. If New, fill in the fields on the form, as appropriate.  
   {#avm-create-assign-rules__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the group rule. |
   | Active | Indicates whether the assignment rule is active. |
   | Execution order | Order in which the rules are evaluated. High priority rules, items that need special handling, where risk is critical, or an AVI should be handled by regulatory compliance, to be run first. Next, run your general rules, where no special handling is required, and you know who should be responsible for them. Finally, create a default rule to assign AVIs to the group that will figure out what assignment group it should belong to. This group could add another rule to cover their decisions. This default rule would run last. |
   | Description | Description of the assignment rule. |
   | Condition ||
   | Condition fields | Conditions that must be met. |
   | New Criteria | Adds more condition filter fields to choose from. |
   | Assign using | To automate the assignment of groups created based on this rule, choose one of the options available. * User group: Select a user group from the lookup table. * User group field: Select a user group field from the list menu. * Script: Create or edit a script. Note: Creating or edit a script requires ServiceNow expertise. {#avm-create-assign-rules__ul_ejb_pvs_mdb} |
   [Table 1. Application Vulnerability Assignment Rule]

   {#avm-create-assign-rules__table_vks_thr_ns}
4. Click Submit.  
   New or updated rules are evaluated on the next import.

*[\>]: and then


