---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create or edit exclusion rules

# Create or edit exclusion rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create a rule to filter or exclude detections from getting converted into vulnerable items (VITs) during ingestion.

## Before you begin

Role required: admin

## Procedure

1. Navigate to WorkspacesSecurity Exposure Management Workspace.
2. Select Administration in the navigation pane.
3. Select Review on the Exclusion rules tile.
4. On the Rules page, select Exclusion in the navigation pane.
5. Select New and fill in the fields on the form:  
   {#sem-create-or-edit-exclusion-rules__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | Details ||
   | Name | Name of the exclusion rule. |
   | Active | Option to activate the exclusion rule. |
   | Execution order | Unique order for each exclusion rule. |
   | Description | Description of the exclusion rule. |
   | If this condition is met ||
   | Condition | Filter conditions for the detections that can be defined while processing them. |
   [Table 1. Exclusion form]

   {#sem-create-or-edit-exclusion-rules__table_vks_thr_ns}
6. Select Save.  
   Once an exclusion rule is created, it takes effect on detections starting from the subsequent ingestion.
7. To edit, select the rule name and update the required fields and select Update.
{#sem-create-or-edit-exclusion-rules__steps_vkw_33r_3hc}

*[\>]: and then


