---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Disable or enable risk reduction for a CVE or TPE

# Disable or enable risk reduction for a CVE or TPE {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE)
or Third-party Entry (TPE) in the Security Exposure Management Workspace.

## Before you begin

Role required: admin

## About this task

The risk reduction for a CVE and TPE is enabled by default.  
Note:  
The compensating controls feature is available for host vulnerabilities only.

## Procedure

1. Navigate to WorkspacesSecurity Exposure Management Workspace.  
   On the Lists page, under Libraries, open one of the following for which you want to disable the risk reduction requests:
   * CVE from the CVEs list.
   * TPEs from the TPEs list.
   {#sem-disable-risk-reduction__ul_cgl_l4h_c1c}
2. Select Disable risk reduction.  
   The remediation owner can't request risk reduction for the host vulnerable items related to this CVE or TPE. In other words, the [Request for Risk Reduction](https://servicenow-prod.fluidtopics.net/NwbB~7eEgCUv7AzZ5mK1_g#itr-ws-request-exception-form-rr__entry-risk-reduction) check box doesn't appear when the Reason is selected as <kbd class="ph userinput">Mitigating Control in Place</kbd> on the Request Exception modal.
3. To enable the risk reduction requests for host vulnerable items, select Enable risk reduction.
**Related concepts**   

* [Understanding compensating controls for risk reduction](https://servicenow-prod.fluidtopics.net/lfL1ilZ~cS~h1vU8BMI49g "Compensating controls are the measures taken to reduce the risk posed by vulnerabilities that can't be patched immediately. They can be used to mitigate the likelihood or impact of a successful exploit.")
* [Impact of the compensating controls on risk score and expiration date](https://servicenow-prod.fluidtopics.net/bTr0bwJDUG1RCOsW1oW0zA "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.")  
**Related tasks**   

* [Add a compensating control to the library](https://servicenow-prod.fluidtopics.net/CnRYfdkCzjQjmVMVX77y8A "As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.")
* [Associate compensating controls with CVEs or TPEs for risk reduction requests](https://servicenow-prod.fluidtopics.net/KpW4VxnroVuinqMJhAqS4A "As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace, which can be used for reducing the risk posed by a vulnerability.")

*[\>]: and then


