---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Managing state mapping for deferrals and false positives in Application Vulnerability Response

# Managing state mapping for deferrals and false positives in Application Vulnerability Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Managing State Mapping for Deferrals and False Positives in Application Vulnerability Response

This guide details how to manage the mapping of source states from Application Vulnerability Items (AVIs) imported through Veracode and Fortify Vulnerability Integrations in ServiceNow.
It highlights the options available for triaging imported AVIs, particularly focusing on managing exceptions and false positives, starting from version 20.0 of Vulnerability Response.
Show full answer Show less  

## Key Features

* **Manage Exceptions:** Allows users to triage AVIs marked for the Deferred state via the ServiceNow Exception Management workflow. Users can either preserve the source states or map them to target states based on their configuration choices.
* **Manage False Positives:** Similar to exceptions, this feature helps in handling AVIs flagged as false positives. Users can request a false positive from AVI records or preserve source states based on their preferences.
* **Role Requirement:** App-Sec Manager role is necessary to manage these configurations.

## Key Outcomes

By configuring these options, ServiceNow customers can effectively manage how AVIs are classified and triaged within their instance, which enhances accuracy in vulnerability response workflows. Customers can select options that align with their operational needs, ensuring that false positives and exceptions are handled appropriately to maintain the integrity of their security processes.  
You can manage how the Source states on application vulnerable items (AVIs) imported by the Veracode Vulnerability Integration and Fortify Vulnerability Integration are mapped in your instance after import.
Starting with v20.0 of Vulnerability Response, you have more options for triaging your imported AVIs with ServiceNow workflows.  
When you [Configure the Fortify Vulnerability Integration](https://servicenow-prod.fluidtopics.net/Qq4zZyUi4QH3DaBTO~X19A "Before you run the integration on your instance, the installation and configuration steps must be completed so the Fortify product properly integrates with the Application Vulnerability Response feature of Vulnerability Response. This application is available as a separate subscription.") or the [Configure the Veracode Vulnerability Integration](https://servicenow-prod.fluidtopics.net/OoZv1FYIP~iu48z_TT2dMA "Before you run the integration on your instance, the installation and configuration steps must be completed so the Veracode product properly integrates with Application Vulnerability Response. This application is available as a separate subscription."), the integration configuration pages provide you with two options to help you manage exceptions and false positives in your instance.

* Manage exceptions in ServiceNow
* Manage false positives in ServiceNow
{#avm-excep-fp-triage-mapping-example__ul_mlc_35b_fzb}Role required: App-Sec Manager.

## Use case for Exception management {#avm-excep-fp-triage-mapping-example__section_ac5_2nt_dzb}

AVIs are imported from these integrations with Source states. Upon import, these state are mapped to Target and Target reason states in your instance, because in
some cases there are no exact matches between the source states of your scanner and the states used by your instance.

For example, source states such as Will Not Fix, Remediation Deferred, Risk Accepted, and Risk Mitigated from the [Fortify Vulnerability Integration](https://servicenow-prod.fluidtopics.net/Ua~e5pANzgi~D2xgaYrzcw "The Fortify Vulnerability Integration uses data imported from the Fortify product to help you determine the impact and priority of flaws in your code.") are mapped to the Deferred state with a substate of Risk Accepted or Mitigating Control in Place in your instance.

You have the following options on the configuration pages for these integrations:
{#avm-excep-fp-triage-mapping-example__table_wsc_4pt_dzb__entry__3}

| Option | Check box selected | Description |
|-|-|-|
| Manage exceptions in ServiceNow | Y (by default) | If you leave this option selected, you must request exceptions from AVI records. Imported AVIs marked for the Deferred state are triaged with the ServiceNow Exception Management workflow. AVIs with Source states that normally are mapped to a Deferred state are mapped to the Target triage state in the Open state. |
|   | N | If you deactivate the check box, you preserve the Source states imported from your scanner. These AVIs are mapped to the Target state as Deferred, and to a Target reason state in your instance. They are not triaged by the exception workflow, because they are not mapped to the Target triage state and Target triage reason states. The Request Exception UI action is not available on the AVI record, because the record already in the Deferred Target state. |
[ ]

{#avm-excep-fp-triage-mapping-example__table_wsc_4pt_dzb}

## Use case for False positive {#avm-excep-fp-triage-mapping-example__section_nmg_prt_dzb}

For false positives from the [Veracode Vulnerability Integration](https://servicenow-prod.fluidtopics.net/UaJdOAyH3lz8Z703obNHTg "The Vulnerability Response Integration with Veracode application uses data imported from the Veracode product to help you determine the impact and priority of flaws in your code.") as an aexample, source states such as False Positive or Potential False Positive are mapped to the Closed
Target state with a substate of False Positive.
{#avm-excep-fp-triage-mapping-example__table_tpd_jst_dzb__entry__3}

| Option | Check box selected | Description |
|-|-|-|
| Manage false positives in ServiceNow | Y (by default) | If you leave this option selected, you must request a False Positive from AVI records. Imported AVIs marked for the False Positive or Potential False Positive states are triaged with the ServiceNow Exception Management workflow. AVIs with Source states that normally are mapped to a Closed Target state are mapped to a Target triage state in Open. The False Positive UI action is available on the AVI record. |
|   | N | If you deactivate the check box, you preserve the Source states imported from your scanner. These AVIs are mapped to the Target state as Closed and a Target reason state in False Positive in your instance. They are not triaged by the false positive workflow. The False Positive UI action is not available on the AVI record, because the record is already in the Closed Target state. |
[ ]

{#avm-excep-fp-triage-mapping-example__table_tpd_jst_dzb}

