---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Associate compensating controls with CVEs or TPEs for risk reduction requests

# Associate compensating controls with CVEs or TPEs for risk reduction requests {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Security Exposure Management Workspace, which can be used for reducing the risk posed by a vulnerability.

## Before you begin

Role required: sn_vul.vulnerability_analyst, or sn_vul.vulnerability_admin

## About this task

* If you don't associate compensating controls to a CVE or TPE, all the active controls appear in the [Select Compensating Controls](https://servicenow-prod.fluidtopics.net/NwbB~7eEgCUv7AzZ5mK1_g#itr-ws-request-exception-form-rr__entry-select-controls) field of the Request Exception form.
* If you associate a compensating control to a CVE, this compensating control is automatically associated with the TPE, which is mapped to the CVE.
{#sem-associate-controls-cve-risk-reduction__ul_kwn_kk4_21c}  
Note:  
The compensating controls feature is available for host vulnerabilities only.

## Procedure

1. Navigate to WorkspacesSecurity Exposure Management Workspace.
2. On the Lists page, under Libraries, open one of the following for which you want to associate the controls:  
   * CVE from the CVEs list.
   * TPE from the TPEs list.
   {#sem-associate-controls-cve-risk-reduction__ul_jy3_y4h_c1c}
3. Select Associate controls.  
   Note:  
   The Associate controls button appears only when the risk reduction is enabled for a CVE or TPE. In other words, you can associate compensating controls only when risk reduction is enabled for a CVE or TPE. If the Associate controls button isn't visible, select Enable risk reduction.
4. On the Associate controls modal, select the compensating controls that can be applied to vulnerabilities associated with the CVE or TPE for risk reduction.
5. Select Submit.  
   * The associated compensating controls appear in the Applicable compensating controls tab in the record view of the CVE and TPE.
   * While a remediation owner requests risk reduction, these associated compensating controls appear in the [Select Compensating Controls](https://servicenow-prod.fluidtopics.net/NwbB~7eEgCUv7AzZ5mK1_g#itr-ws-request-exception-form-rr__entry-select-controls) field on the Request Exception modal.
   {#sem-associate-controls-cve-risk-reduction__ul_vtp_cj4_21c}
**Related concepts**   

* [Understanding compensating controls for risk reduction](https://servicenow-prod.fluidtopics.net/lfL1ilZ~cS~h1vU8BMI49g "Compensating controls are the measures taken to reduce the risk posed by vulnerabilities that can't be patched immediately. They can be used to mitigate the likelihood or impact of a successful exploit.")
* [Impact of the compensating controls on risk score and expiration date](https://servicenow-prod.fluidtopics.net/bTr0bwJDUG1RCOsW1oW0zA "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.")  
**Related tasks**   

* [Disable or enable risk reduction for a CVE or TPE](https://servicenow-prod.fluidtopics.net/PkBpor8ePECeKOr89863KA "As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.")
* [Add a compensating control to the library](https://servicenow-prod.fluidtopics.net/CnRYfdkCzjQjmVMVX77y8A "As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.")

*[\>]: and then


