---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add a compensating control to the library

# Add a compensating control to the library {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.

## Before you begin

Role required: sn_vul.vulnerability_analyst, or sn_vul.vulnerability_admin

## About this task

Some commonly used compensating controls are shipped with the base system. You can view these compensating controls by navigating to WorkspacesVulnerability Manager WorkspaceListsLibrariesCompensating controls. You can activate or deactivate these compensating controls as per your requirement.  
Note:  
The compensating controls feature is available for host vulnerabilities only.

## Procedure

1. Navigate to WorkspacesVulnerability Manager Workspace.
2. On the List page under Libraries, select Compensating Controls.
3. Click New.
4. On the Create Compensating Controls form, fill in the fields.  
   {#create-compensatory-control__table_tvw_5qw_1zb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the compensating control, which appears as an option in the Compensating controls drop-down of the Request exception modal. |
   | Description | Brief information that provides details about the Compensating Control. |
   | Active | Status of the compensating control. Only active controls appear in the Compensating controls drop-down of the Request exception modal. |
   [Table 1. Create Compensating Controls form fields]

   {#create-compensatory-control__table_tvw_5qw_1zb}
5. Select Save.
6. On the Compensating Controls list under Libraries, select the desired compensating control and select Edit, activate or deactivate a compensating control and click Save to modify the compensating controls.  
   All the active compensating controls appear as an option in the Compensating controls drop-down of the Request exception modal for risk reduction requests.

## What to do next

Starting from v21.0 of Vulnerability Response, you can associate compensating controls with CVEs or TPEs after adding a compensating controls to the library. For more information on how to associate compensating controls, see [Associate compensating controls with CVEs or TPEs for risk reduction requests](https://servicenow-prod.fluidtopics.net/KpW4VxnroVuinqMJhAqS4A "As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace, which can be used for reducing the risk posed by a vulnerability.").
* **[Associate compensating controls with CVEs or TPEs for risk reduction requests](https://servicenow-prod.fluidtopics.net/KpW4VxnroVuinqMJhAqS4A)**   
  As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace, which can be used for reducing the risk posed by a vulnerability.
* **[Disable or enable risk reduction for a CVE or TPE](https://servicenow-prod.fluidtopics.net/PkBpor8ePECeKOr89863KA)**   
  As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.

**Related concepts**   

* [Understanding compensating controls for risk reduction](https://servicenow-prod.fluidtopics.net/lfL1ilZ~cS~h1vU8BMI49g "Compensating controls are the measures taken to reduce the risk posed by vulnerabilities that can't be patched immediately. They can be used to mitigate the likelihood or impact of a successful exploit.")
* [Impact of the compensating controls on risk score and expiration date](https://servicenow-prod.fluidtopics.net/bTr0bwJDUG1RCOsW1oW0zA "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.")  
**Related tasks**   

* [Disable or enable risk reduction for a CVE or TPE](https://servicenow-prod.fluidtopics.net/PkBpor8ePECeKOr89863KA "As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.")
* [Associate compensating controls with CVEs or TPEs for risk reduction requests](https://servicenow-prod.fluidtopics.net/KpW4VxnroVuinqMJhAqS4A "As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace, which can be used for reducing the risk posed by a vulnerability.")

*[\>]: and then


