---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Automatically close vulnerable items related to retired CIs

# Automatically close vulnerable items related to retired CIs {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If the Configuration Management Database (CMDB) changes the life cycle stage status of a configuration item (CI) to retired, you can choose to automatically close the associated vulnerable items (VIs) and detections.

## Before you begin

Role required: sn_vul.admin

## About this task

Starting with v22.0 of Vulnerability Response, to automatically close the associated VIs and detections, you must enable the system property sn_vul_cmn.auto_close_vis_linked_retired_cis to auto-close VIs that are associated
with retired CIs. To enable the option, set the Value field to '1'. Conversely, to disable the option, set the Value field to '0'.

During an upgrade if the system property
sn_vul_cmn.auto_close_vis_linked_retired_cis is selected in v21.0 of Vulnerability Response, then the value remains as '1'. When this option is enabled, any new or existing VIs and detections reported for the same CI, are automatically created or updated with a status of 'Closed'. This is
based on the Asset ID in the scanner payload and status of the Discovered Items entry. For more information on the impact of retired CIs, see [Working with retired configuration items](https://servicenow-prod.fluidtopics.net/Pbh00S748eQXnzSHT75JLA "Decommissioned configuration items (CIs) are moved to retired, archived, or deleted state in the Configuration Management Database (CMDB). Vulnerability Response contains vulnerable items (VIs) that are made up of CIs. When the state of a CI is updated to retired, the associated VIs are closed with the substate 'CI decommissioned'.")
.  
Note:  
* The state of a DI is updated to 'CI decommissioned' whenever the life cycle state of a CI is updated. On the other hand, the state of a VI is updated to Closed only when the Auto-close VIs linked to retired CIs option is enabled.
* The information provided in the following procedure is only applicable to versions prior to v22.0 of Vulnerability Response. Starting from v22.0 of Vulnerability Response, you have the option to configure additional search options. See [Create auto-close rules](https://servicenow-prod.fluidtopics.net/l~nX339uV8ceYJ5et5lDFQ "Use auto-close rules to close older detections automatically based on the filter conditions that you set.") for more information.
{#auto-close-vis__ul_yvb_ylf_n2c}

## Procedure

1. Navigate to AllVulnerability ResponseAuto-Close ConfigurationConfiguration Item Lifecycle.
2. To automatically close vulnerable items associated with the retired CIs, select the Auto-close VIs linked to retired CIs check box.
3. Select Update.  
   Note:  
   If a CI is already retired before the Auto-close VIs linked to retired CIs option is enabled, VIs are created only for new detections from scanners. The state of these VIs is Closed and the substate is CI Decommissioned.

   You cannot manually reopen VIs whose state is CI decommissioned, using the Reopen or Bulk Edit options.

   Closed VIs with a substate of
   fixed or stale are reopened if a new detection is created and the VIs can be matched with the new vulnerability. See [Detections, remediation tasks, and vulnerable item states](https://servicenow-prod.fluidtopics.net/8UzWFlCLEh1yT6CUM6qR2g "Third-party integrations retrieve the vulnerable item detection data. Detections are distinct occurrences of vulnerabilities as reported by the scanners.") for more information.

*[\>]: and then


