---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Re-evaluating the exceptions for selected records in the Vulnerability Manager Workspace

# Re-evaluating the exceptions for selected records in the Vulnerability Manager Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Re-evaluating the Exceptions for Selected Records in the Vulnerability Manager Workspace

The Vulnerability Manager Workspace allows users to evaluate exception rules for records, updating their deferral status and until date based on the latest rules.
This process helps manage vulnerabilities effectively by ensuring records are accurately reflected according to their current status and related exception rules.
Show full answer Show less  

## Key Features

* **Scenario Handling:** Different scenarios dictate how records are updated when exception rules are evaluated:
  * Records already deferred remain unchanged if they match exception conditions.
  * Records in non-deferral states that match exception rules are deferred until the specified date.
  * Previously deferred records remain deferred under certain conditions, even if exception rules expire.
  * Changing exception rule conditions can transition records to the Open state and update associated fields.
* **Exception Rule Details:** Key aspects of exception rules include:
  * Name, valid dates, reason, assignment group, condition filters, and execution order.
  * Specific conditions like risk ratings determine which vulnerabilities are affected.

## Key Outcomes

Evaluating exceptions allows for precise management of vulnerability statuses, ensuring that critical vulnerabilities are deferred appropriately while maintaining compliance with organizational policies. This process leads to improved remediation tracking and effective resource allocation for handling vulnerabilities.  
In the Vulnerability Manager Workspace, when you evaluate the exception rules for a set of records in the Re-evaluate and update the remediation properties modal, their deferral status and until date of deferral are updated as per the latest
exception rules.

## Scenarios {#vmws-exception-rules-scenarios__section_of4_zyt_bdc}

You may come across the following scenarios, when you evaluate the exceptions for a selected set of records in the Re-evaluate and update the remediation properties modal in the Vulnerability Manager Workspace:

Scenario 1: When the selected records are already deferred manually and they match the condition of an exception rule, these records remain in the Deferred state without any changes.

Scenario 2: When the selected records match the condition in the exception rules and these records are in a non-deferral state (such as open, In Review, Under Investigation), then these records are deferred
until the date defined in the exception rule.  
Scenario 3: When the selected records are already in the Deferred state (that are deferred using the exception rule A), they remain in the Deferred state in the following scenarios:

* the exception rule expires and the records do not match the condition
* the exception rule expires and the records match the condition
* the exception rule A expires and records match the condition of another exception rule B.
{#vmws-exception-rules-scenarios__ul_fk1_fzt_bdc}  
Scenario 4: Consider that the records are deferred using an exception rule. When you change the exception rule condition such that the Deferred state of the records is no longer valid and then reevaluate the exception rules for these records:

* the records move to the Open state
* the Until date, Deferral date, Deferral count and other fields are updated.
{#vmws-exception-rules-scenarios__ul_otc_b15_bdc}  

## Consider that you are evaluating the exceptions for following host vulnerable items (VITs) {#vmws-exception-rules-scenarios__example_njx_35w_2dc}

Consider the exception rule with the following details:{#vmws-exception-rules-scenarios__table_tqk_fb3_4mb__entry__3}

| Field | Description | Value |
|-|-|-|
| Name | Name of the exception rule. | Deferring critical VITs |
| Valid from | Date from which this rule is active to defer the VIs. | 20-08-2024 |
| Valid to | Date from which the remediation task stops accepting new VIs. | 30-11-2024 |
| Reason | Reason to create this exception rule. | Risk Accepted |
| Assignment group | Group that the remediation task that was created for tracking the deferred VIs is assigned to. | Remediation Group 1 |
| Additional information | Additional information that the requester wants to provide to the approver. This information is populated in the description field of the remediation task. | This rule has been created to defer the critical VITs automatically. |
| Condition | Filter condition for the VIs that can be defined while processing the VIs. | Risk rating = 5 - Critical |
| Execute on existing data | Option that enables you to run this rule on existing data the first time that this rule is run. | Yes |
| State | State of the exception rule. | Approved |
| Execution order | Unique order for each exception rule. | 100 |
| Deferred until | Date until when the VULs and VIs are deferred. On this date, the created VUL is closed, all the VIs move out of the group, and group rules are reapplied. | 2024-12-23 16:10:29 |
[Table 1. Exception rule details]

{#vmws-exception-rules-scenarios__table_tqk_fb3_4mb}  
The following table shows how the state changes when the exception rules are reevaluated for multiple VITs simultaneously: {#vmws-exception-rules-scenarios__table_o3m_qvw_2dc__entry__5}

| VIT Number | State | Risk Rating | Updated state after reevaluating the exceptions -1 | Until date - 1 |
|-|-|-|-|-|
| VIT120067 | Open | 2 - Low | Open | - |
| VIT120068 | In Review | 3 - Medium | In Review | - |
| VIT120069 | Under Investigation | 5 - Critical | Deferred | 2024-12-23 16:10:29 |
| VIT120070 | Deferred | 5 - Critical | Deferred | 2024-12-23 16:10:29 |
| VIT120071 | Deferred | 2 - Low | Deferred | 2024-10-02 16:10:29 (Deferred manually) |
| VIT120072 | Closed | 5 - Critical | Closed | - |
[Table 2. Records for which exceptions are reevaluated]

{#vmws-exception-rules-scenarios__table_o3m_qvw_2dc}  
When the condition in the preceding exception rule is modified to <kbd class="ph userinput">Risk rating = 2 - Low</kbd> and Deferred until is modified to <kbd class="ph userinput">2024-12-31 14:10:23</kbd> the records are updated as follows:{#vmws-exception-rules-scenarios__table_iz5_n1x_2dc__entry__5}

| VIT Number | Updated state after reevaluating the exceptions -1 | Risk-rating | Updated state after reevaluating the exceptions - 2 | until date - 2 |
|-|-|-|-|-|
| VIT120067 | Open | 2 - Low | Deferred | 2024-12-31 14:10:23 |
| VIT120068 | In Review | 3 - Medium | In Review | - |
| VIT120069 | Deferred | 5 - Critical | Deferred | 2024-12-23 16:10:29 |
| VIT120070 | Deferred | 5 - Critical | Deferred | 2024-12-23 16:10:29 |
| VIT120071 | Deferred | 2 - Low | Deferred (No change in the state) | 2024-10-02 16:10:29 (No change in the until date) |
| VIT120072 | Closed | 5 - Critical | Closed | - |
[Table 3. Records for which exceptions are reevaluated]

{#vmws-exception-rules-scenarios__table_iz5_n1x_2dc}
**Related concepts**   

* [Exception rules overview](https://servicenow-prod.fluidtopics.net/fwAg9ANsKaueARJWUY3Oqg "Exception rules for Vulnerability Response enable you to automate the deferral process for vulnerable items (VIs). Request an exception for the vulnerable items (VIs) that can't be remediated or deferred immediately, by identifying the impacted vulnerabilities, configuration items (CIs), or VIs. Defer the matching VIs based on the rule when the system identifies them by automating the VI deferral process.")
* [Configuration Compliance Exception Management overview](https://servicenow-prod.fluidtopics.net/e~SV_zcAo5mGFmUjf3cUfQ "When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions for a remediation task that cannot be remediated according to the policy.")  
**Related tasks**   

* [Re-evaluate the remediation properties of the records in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/OepC9QWfPbJ7hX~pujy8SQ "Evaluate the assignments, remediation target date, remediation tasks, exceptions, and risk score for a set of records (VITs, AVITs, CVITs or TRs) in the Vulnerability Manager Workspace.")

