---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create, edit, and delete Application Vulnerability Response remediation task rules

# Create, edit, and delete Application Vulnerability Response remediation task rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

You can create rules to automatically group application vulnerable items (AVI) into remediation tasks (AVUL) based on filter conditions. These rules automatically group AVIs as they're imported or manually
created.

## Before you begin

If you create a new rule, it doesn't apply to existing data. After you submit it, it's run against new imports.

Role required: sn_vul.app_sec_manager

## Procedure

1. Navigate to AllApplication Vulnerability ResponseAdministrationRemediation Task Rules.
2. Open the rule or select New.
3. Fill in the fields on the form or edit them.  
   {#avm-create-rt-rule__table_g2b_tmn_rkb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the task rule. |
   | Active | Indicates whether the task is active. |
   | Description | Description of the rule. |
   | Case sensitive | Determines whether a condition is case sensitive or not. Note: The default value is case insensitive. |
   | Condition | Optional filter conditions for the rule. By default, (Case sensitive check box not selected), the search text you enter in the condition builder on task rules records and forms isn't case-sensitive. You have the option to enable case-sensitive searches on task records and forms. An example condition is VulnerabilityisVULNENT123451 (a known imported vulnerability). Any AVIs that have this vulnerability match this condition. |
   | Group by (up to six condition sets are available) ||
   | Group application vulnerable items from | The table the rule uses to group AVIs. Select the elements from the tree: * Application Vulnerable Item \[sn_vuln_vulnerable_item\] * Application Vulnerable Item Configuration Item \[cmdb_ci\] * Application Vulnerable Item Application Vulnerability \[sn_vul_third_party_entry\] * Application Vulnerable Item Product Model {#avm-create-rt-rule__ul_yhb_ffv_rkb} Note: If you choose an extended table, the Using field is applied only for application vulnerable items that use that extended table. |
   | Using field | Field on the table that the rule uses to group AVIs. Select conditions from the tree. Note: You can create group by conditions so that not all the AVIs that share data are assigned to the same remediation task. For example, if you select Assignment group and IP Address as the Using fields, and multiple AVIs match the initial filtering condition Vulnerability, these AVIs can be assigned to distinct assignment groups for remediation using the many options available in the Group by section. The Group by conditions give you the flexibility to create distinct remediation tasks that can be assigned to different group even if they share some data. |
   | Assignment ||
   | Assign remediation tasks by | When automatically assigning remediation tasks, the Assignment choice is used in addition to the Group By choices to group the vulnerable items. New tasks are created, as needed, so that each AVI is placed in a task with a matching assignment group set. To automate the assignment of tasks created based on this rule, choose one of the options available. * Group by field: If you selected any user group field from the Using field values in the Group bysection, they appear in the drop-down menu. * User Group: Use the lookup list to select a static user group. {#avm-create-rt-rule__ul_j2b_tmn_rkb} |
   [Table 1. Remediation Task Rule]

   {#avm-create-rt-rule__table_g2b_tmn_rkb}

   if you delete a rule from either the form or list view, you have the option to delete all Open remediation tasks created by that rule. Groups not in the Open state are
   excluded.
4. Select Submit for new rules.  
   After you select Submit, your rule is displayed on the Remediation Task Rules list \[sn_vul_grouping_rule\]. The following situations initiate your rule.
   * When new AVIs are created.
   * When you select Reapply. You select Reapply to evaluate task rules on existing remediation tasks only.
   * When AVIs are updated, either by you or by the system.  
     If an AVI is updated, task rules are evaluated for matches to existing remediation tasks. Some common updates that initiate a rules check are:
     * When the State changes from Closed to Open, or from Closed to Under Investigation.
     * The configuration item (CI) is changed.
     * The vulnerability is changed.
     {#avm-create-rt-rule__ul_ylb_dth_1zb}

   {#avm-create-rt-rule__ul_xwb_fsh_1zb}

   The system checks all the task rules for matches to the updated AVI. If the conditions of a rule match the conditions of a remediation task, matching AVIs are assigned to it.

   If no match is found, a new
   remediation task is created.

   For more information about state roll up from AVIs to remediation tasks and state roll down from remediation tasks to AVIs, see [Application Vulnerability Response remediation tasks and task rules overview](https://servicenow-prod.fluidtopics.net/04vGngzlHZdIp~Z43var8Q "Configure remediation tasks (AVULs) to help analysts and remediation specialists organize application vulnerable items (AVI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that AVIs are automatically assigned into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.").

   For an example of a remediation task rule, see [Application Vulnerability Response remediation task rule examples](https://servicenow-prod.fluidtopics.net/GC9m8YGJuGc0gpgVD~Ikqw "A example of a remediation task rule example using the condition builder.").
5. To delete a task rule, select the rule from the Remediation Task Rules list and select Delete.  
   The following message is displayed: The selected remediation task rule created n remediation tasks. Of the remediation tasks, n are in the Open state.. {#avm-create-rt-rule__table_htj_nx3_1zb__entry__2}

   | Option | Description |
   |-|-|
   | Check box deactivated (default). | Only delete the rule. Tasks not in the Open state are excluded. |
   | Check box selected. | Include the remediation tasks in the Open state when you delete the remediation task rule. Delete the rule and any remediation tasks in the Open state. |
   [ ]

   {#avm-create-rt-rule__table_htj_nx3_1zb}
6. Choose one option and select Delete.

*[\>]: and then


