---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuring roll-up calculator rules

# Configuring roll-up calculator rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure roll-up calculator rules to compute the cumulative risk score for remediation tasks and imported vulnerabilities.
**Related concepts**   

* [Prioritizing vulnerabilities and other findings using roll-up calculators](https://servicenow-prod.fluidtopics.net/1Rv4OZdtFTWBfBj1oUAxwg "After assessing risk calculators, use the roll-up calculators to configure how the cumulative risk scores are computed for remediation tasks and other higher entities.")

## Create or edit roll-up calculator rules {#ariaid-title2}

Create rules to roll-up risk scores on imported findings and remediation tasks.

### Before you begin

Role required: See [Access control lists (ACLs) for administration rules](https://servicenow-prod.fluidtopics.net/i0KpEC0Q1uMFl7DYVtZUsQ "You can either view or modify the administration rules based on the roles assigned to you.")

### Procedure

1. Navigate to WorkspacesSecurity Exposure Management Workspace.
2. Select Administration in the navigation pane.
3. Select Review on the Roll-up calculator rules tile.
4. On the Rules page, select Roll-up calculator in the navigation pane.
5. Select New and fill in the fields on the form:  
   {#sem-create-edit-risk-rules__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | Details ||
   | Name | Name of the rule. |
   | Target table | Name of the table from which the risk score must be rolled-up. |
   | Target field | Name of the field from the table that must be considered for risk roll-up. |
   | Active | Indicates whether the rule is active. |
   | Description | Description of the rule. |
   | Source selection ||
   | Applies to | The finding table to which the risk score roll-up applies to. The Applies to field is dependent on the selected target table, and its options are updated accordingly. For instance, choosing the Container remediation task \[sn_vul_container_vulnerability\] limits the Applies to field options to Container vulnerable item. This dynamic update ensures that only relevant options are available based on the target table selected. |
   | Include | Defines the conditions for roll-up on the finding table. |
   | Roll-up calculations ||
   | Basic | Assign weightage to specify the relative impact of each of the following factors on the rolled-up risk score: * Maximum risk score: Maximum risk score of the findings considered. * Average score: Aggregate of the risk scores of all the findings. * Count of records: Number of findings. A larger number of findings increases the overall score, while a smaller number lowers it. {#sem-create-edit-risk-rules__ul_fmt_3qg_hgc} |
   | Script (Advanced option) | The scripting feature is an advanced feature to build a custom script that should return the risk score, which is an integer value ranging from 0 to 100. |
   [Table 1. Roll-up calculator rule form]

   {#sem-create-edit-risk-rules__table_vks_thr_ns}
6. Select Save.
{#sem-create-edit-risk-rules__steps_ush_xnz_nfc}

*[\>]: and then


