---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuration Compliance correlation

# Configuration Compliance correlation {#ariaid-title1}

* Release version: Australia
* 
* Updated August 3, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Configuration Compliance correlation

Configuration Compliance correlation in ServiceNow Australia release helps prioritize and group configuration test results into remediation tasks, enabling efficient handling and resolution of non-compliance issues.
This feature assists customers in managing large volumes of findings by focusing efforts on the highest risk items.
Show full answer Show less  

## Key Features

* **Terminology Updates:** From version 14.9, several terms have been renamed for clarity:
  * Test Result Group → Remediation Task Group
  * Rules → Remediation Task Rules
  * Policy → Test Group
  * Asset-Centric Prioritization → Configuration Compliance prioritization based on asset and test criticality
* **Risk-Based Prioritization:** Configuration scans generate numerous findings that are prioritized using a combined risk score (0--100 scale) based on configuration test criticality and asset criticality. This score can be customized via calculator groups.
* **Automated Post-Import Actions:** Upon completion of third-party import, Configuration Compliance triggers updates such as:
  * Reopening resolved remediation tasks with failed results to "Awaiting implementation"
  * Closing remediation tasks where all results have passed
  * Updating test result states and flags related to active remediation tasks
* **Remediation Task State Management:** When test results belong to multiple remediation groups, their state is computed based on a defined order of precedence, ignoring closed states like Closed-Fixed or Closed-Canceled. Passed test results are always marked Closed-Fixed.
* **Manual Creation of Remediation Tasks:** Customers can create remediation tasks either:
  * Using filters to automatically populate test results based on criteria such as criticality, infrastructure, or application
  * Selecting specific test results manually from the Test Results list for unique or outlier cases
  Note that applying filters after manual selection replaces the existing test results in the task.
* **Ungrouped Test Results Module:** Displays all failed or non-passed test results not currently assigned to an active remediation task, updated after every import or task modification.

## What This Enables You to Do

ServiceNow customers can efficiently manage compliance findings by grouping and prioritizing test results based on risk, ensuring remediation efforts focus on the most critical issues. The manual remediation task creation options offer flexibility to tailor remediation activities to your organizational needs, while automated updates maintain accurate task and result states.

Overall, this capability supports streamlined compliance remediation workflows, clearer visibility into remediation status, and improved risk reduction through prioritized action.  
Configuration Compliance provides prioritization and test result grouping (into remediation task) to aid remediation of non-compliance issues.  
Note:  
Starting with v14.9 of Configuration Compliance, the following terms have been renamed:{#vuln-config-compl-correlation__entry__2}

| Terminology prior to v14.9 | Terminology v14.9 onwards |
|-|-|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
[Table 1. Changes in terminology]

## Asset-Centric Prioritization {#vuln-config-compl-correlation__section_jt3_zh3_jbb}

Configuration scans can produce large number of findings. Prioritize findings for greatest risk reduction. Priority includes both configuration test criticality and asset criticality. Configuration test result priority is expressed
as a 0--100 scale risk score. Calculator groups compute risk score and can be customized.  
When the third-party import is complete, Configuration Compliance sends an event to indicate end-of-import actions. For every active result group, the following actions are taken:

* Resolved remediation tasks with failed results return to the Awaiting implementation state.
* Remediation tasks where all results passed are Closed.
* The state of test results that are in active remediation tasks is updated.
* The flag indicating whether a result is part of an active remediation task is updated.
{#vuln-config-compl-correlation__ul_yms_vs1_lbb}

## Remediation Tasks order of precedence {#vuln-config-compl-correlation__TRGOrderPrecedence}

When test results belong to more than one group, the State of a test result is derived according to an order of precedence.

The State and Resolution fields in the Configuration Test form and the Result field in the Test Result form, are
calculated following this order of precedence.  
Note:  
The group membership precedence only applies to items where the item did not pass the configuration test. Passed items are always in the Closed-Fixed state.

The Result value determines the state. We ignore remediation tasks in the Closed-Fixed and Closed-Canceled state. The item state is computed from the states of
all other remediation tasks it belongs to or is set to Open, if no other group exists for the item.

## Remediation Tasks creation {#vuln-config-compl-correlation__section_sl5_r2g_nbb}

Configuration Compliance Remediation Tasks are created manually.

There are two ways to create and populate Remediation Tasks.  
* From the Remediation Tasks module and using filters that automatically populate the Test Results tab.

  This way is good for when you know what filtering you want to use. For
  example, capturing all failed test results that are moderate and higher criticality, affect the windows-based infrastructure, and apply only to the SAP supply chain application.
* By selecting test results in the Test Results list and creating a remediation task from the Actions on selected rows... menu.

  This method is good for results that are not easily
  filtered, or situations where you want to specify test results for remediation. For example, outliers that have nothing in common.
{#vuln-config-compl-correlation__ul_s1h_wmt_kbb}  
Note:  
If you create a remediation task from the Test Results list and you later decide to use a filter for that remediation task, your original entries are removed and replaced by the filter results.

## Ungrouped Test Results {#vuln-config-compl-correlation__section_pv1_j23_4bb}

Ungrouped Test Results contain all non-pass test results that are not members of an active (non-Closed) remediation task. This module is updated after every import and whenever test
results are added or removed from a remediation task.

