---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create Remediations

# Create Remediations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Create a remediation record to document a fix or workaround for a vulnerability affecting a specific product.

## Before you begin

Role required: sn_sec_tisc.analyst

## About this task

At least one vulnerability record and one product record must exist in the system before creating a remediation. Remediations are always created in the context of a vulnerability and product combination.

## Procedure

1. Navigate to AllWorkspacesThreat Intelligence LibraryVulnerability ArtifactsRemediations.
2. Select New.
3. Fill in the fields appropriately.  
   {#tisc-create-remediation-record__table_qjq_dlg_k3c__entry__2}

   | Field | Description |
   |-|-|
   | Remediation Id | A unique identifier for the remediation record. |
   | Products | The product or products to which this remediation applies. |
   | Vulnerability | The vulnerability that this remediation addresses. |
   | Type | The category of remediation being documented. * Mitigation: a workaround or partial fix. * Workaround: a temporary measure. * Vendor Fix: an official fix from the vendor. * First Fix: the initial fix available for the vulnerability. * None Available: no remediation is currently available. * No Fix Planned: the vendor does not plan to fix the vulnerability. {#tisc-create-remediation-record__ul_l5r_4lg_k3c} |
   | Description | Description of the remediation, including what it addresses and how it should be applied. |
   | Remediation Published Date | The date on which this remediation was officially published. |
   | Restart category | Indicates what category of restart is required by this remediation to become effective. Select one of the following values, as required: * Connected: a connected dependency requires a restart. * Dependencies: dependent services or components must be restarted. * Machine: the entire machine requires a restart. * Service: a specific service must be restarted. * System: the full system requires a restart. * None: no restart is required. {#tisc-create-remediation-record__ul_lh2_cmg_k3c} |
   | Action Link | A URL pointing to the remediation resource, advisory, or vendor patch page. Enter a fully qualified URL (for example, `https://vendor.com/advisory/CVE-2024-1234`). Use this field to direct users to external remediation guidance or download locations. |
   | Prerequisites | Lists the conditions that must be met for the vulnerability remediation to apply to this product. Use this field to document preparatory actions such as backing up data, stopping services, or verifying system compatibility. All prerequisite values are entered manually. |
   [Table 1. Vulnerability Remediation]

   {#tisc-create-remediation-record__table_qjq_dlg_k3c}
4. Click Save.
5. To also add Remediations, navigate to Threat Intel LibraryVulnerability Artifacts and open any vulnerability record or product record to which you want to add a remediation.
6. Go to the Related Records section.
7. Scroll to the Remediations related list and click Add.  
   Clicking Add opens the remediation form in a new tab. The parent context (vulnerability or product) is automatically populated in the corresponding field. Enter the required form details as explained in the previous steps.
8. Click Save.
{#tisc-create-remediation-record__steps_hvs_5jg_k3c}

## Result

The remediation record is created and appears in the Remediations related list of the associated vulnerability and product records. The Remediated Records Count field on the
vulnerability record is automatically incremented.

*[\>]: and then


