---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuration Compliance remediation tasks and remediation task rules overview

# Configuration Compliance remediation tasks and remediation task rules overview {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Configuration Compliance Remediation Tasks and Remediation Task Rules Overview

This guide outlines the functionality of remediation tasks (RTs) and remediation task rules within the Configuration Compliance module.
These tools automate the grouping and management of test results, allowing users to efficiently analyze and address compliance issues without manual intervention.
Show full answer Show less  

## Key Features

* **Automated Task Creation:** Remediation tasks can be automatically generated using remediation task rules, simplifying the process of managing test results.
* **Flexible Grouping:** Users can create conditions to group test results based on various criteria such as technologies and risk scores, enhancing organizational adaptability.
* **Manual and Automatic Options:** Tasks can be created manually or automatically, with the latter being the preferred approach for efficiency.
* **Task Management:** From a remediation task, users can assign test results, defer them, or create Change Requests, streamlining the remediation process.
* **Deferral Tracking:** The system tracks how many times test results or remediation tasks have been deferred, providing visibility into ongoing compliance management efforts.

## Key Outcomes

By utilizing remediation tasks and rules, ServiceNow customers can expect:

* Increased efficiency in managing compliance by automating the grouping of test results.
* Improved organization of test results, enabling bulk updates and state changes.
* Enhanced visibility and control over remediation efforts through deferral tracking and assignment management.
* Streamlined processes for handling test results that require attention, reducing the time and effort needed to maintain compliance.  
Automatically create remediation tasks (RTs) to analyze results in bulk using remediation task rules. The criteria by which tasks are formed is configured so that you do not have to manually assign test results into
remediation tasks.  
Note:  
Starting with v14.9 of Configuration Compliance, the following terms have been renamed:{#cc-groups__entry__2}

| Terminology prior to v14.9 | Terminology v14.9 onwards |
|-|-|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
[Table 1. Changes in terminology]

## Understanding remediation tasks

Remediation tasks represent a set of test results to remediate. Grouping test results has many advantages. You can move test results through the remediation states, mark them under investigation, defer them, mark them resolved in
bulk by using groups. You can create conditions to automatically group all results with specified results, technologies, risk scores, and any other data related to the test results. Test results can belong to more than one
remediation task giving you the flexibility to actively work with one remediation task and monitor another. It all depends on your organizational needs. For example, you could group by assignment, and also create a group containing
technologies.  
Remediation tasks are created as follows.

* Manually, using one of two options, to add test results to the group.
  * Manual: creates a remediation task with no entries. Test results must be added manually.
  * Filter: creates a remediation task and uses conditions to automatically add test results to that remediation task.

  {#cc-groups__ul_jsg_y21_gdb}  
  Note:  
  Manually added test results are not automatically removed from remediation tasks by remediation task rules or remediation task conditions.
* Automatically, using remediation task rules. This option is the easiest option, once configured, remediation task rules create all desired remediation tasks.
{#cc-groups__ul_k53_dn2_pbb}

From a remediation task, the group of test results may be assigned to a user, deferred until later, used to create a Change Request, and so on.  
Note:  
With the sn_vulc.remediation_owner role, you can view and update test results and remediation tasks that are assigned to you or to your assignment groups. To view the modules, navigate to AllConfiguration ComplianceTest ResultsMy Open Test Results, or Configuration ComplianceRemediation TasksMy Open Tasks.

When it is determined that a new test result can be added to a remediation task, the test result is included in the Test Results related list of the remediation task.

When updating the state of a remediation task, associated test results can have their state updated to match this remediation task. For more information on state changes, see [Configuration Compliance states](https://servicenow-prod.fluidtopics.net/~iB1agJRWCu2YgGdRipCSA "With Configuration Compliance, you can see a state model to learn what the status of the remediation task is at any given time. The remediation task states control the test result states by precedence.").

## Understanding remediation task rules {#cc-groups__VulGrpRules}

Remediation task rules allow you to define how test results are automatically grouped and assigned. A default rule, Assignment group, Test, is included in the base system grouping test results based on a test
result Assignment group and the Test field. This rule is disabled, by default. You can group by any other set of values in columns accessible from the test result. You can use up to six
keys and any number of conditions. For more information, see [Create or edit Configuration Compliance remediation task rules](https://servicenow-prod.fluidtopics.net/4U0qqgADmui8SUMf72r1Zw "You can create rules to automatically group test results based on filter conditions. These rules automatically group test results as they are imported. Use the filter to limit the test results grouped by this rule, such as selecting all test results with exploits.").  
Important:  
As an admin and analyst, you can evaluate the remediation task rules for selected test results in the Vulnerability Manager Workspace. This method is more efficient than reapplying the remediation task rules in the classic UI, which is a time-consuming process. For more information, see [Re-evaluate the remediation properties of the records in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/OepC9QWfPbJ7hX~pujy8SQ "Evaluate the assignments, remediation target date, remediation tasks, exceptions, and risk score for a set of records (VITs, AVITs, CVITs or TRs) in the Vulnerability Manager Workspace.").

For example, you can group your test results by assignment group or technology and configuration item (CI). A different set of rules can be used for test results that expose the company to more risk. You can have one remediation
task rule for low severity or low risk CIs. See [View Configuration Compliance test results](https://servicenow-prod.fluidtopics.net/xs_hqEEdvhbQrc9O74TsGQ "View Configuration Compliance test results for auditing and remediation. The test results are automatically created during third-party vulnerability integration imports.") for more information on available fields.

When a new test result is imported, or reopened after being closed, the remediation task rules are evaluated against it. A test result is only evaluated once, unless it is reopened after being closed.

Remediation task rules are evaluated after CI matching, risk score calculations, and assignment rules.  
The following process is used for each new or reopened test result:

* For each remediation task rule, the test result is compared to the condition filter.
* For each rule where the rule condition matches, it pulls the data from the group key columns on the test result. The rule checks to see if there is a matching Open remediation task that is assigned to the same assignment group as the test result.

  If the remediation task is found, the test result is added to the existing remediation task in the Open state.
* If no remediation task in the Open state is found, the rule creates a remediation task, assigns it based on the User Group or Key value in the rule, and places the test
  result in it.

{#cc-groups__ul_a2p_fj1_gdb}

More than one test result rule can be defined, to group different kinds of results. Since each result is compared with the rule conditions before putting it in a remediation task, too many rules may have a performance impact.

When a remediation task rule is deleted, you have the option to delete all open tasks created by the rule. This applies to both the rule form view and list view.

When a remediation task assignment is made or changed, the Assignment group and the Assigned to fields roll down to all test results, except for those where the test result has a
different assignment group than the RT. For more information on assignment rules, see [Configuration Compliance assignment rules overview](https://servicenow-prod.fluidtopics.net/1A7Ic2vqzxUnETGkDnXr0A "Define the criteria by which test results are automatically assigned to an assignment group for remediation."). These assignments are used automatically for this group on the next import.

## Track deferral counts for test results and remediation tasks {#cc-groups__section_ksv_lbc_35b}

Starting with v14.3, track the number of times a test result or a remediation task is deferred in the Multiple deferrals module. A scheduled job, set deferral counts, runs daily to post counts for records
that are deferred more than once in the Deferral count column in the records that are listed in the Multiple deferrals module.

*[\>]: and then


