---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a Vulnerability Response calculator

# Create a Vulnerability Response calculator {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

A vulnerability calculator is a pre-defined formula to calculate a target field when
certain criteria are met. Calculators, which calculate the vulnerable item Risk Score, can contain Risk Rules.

## Before you begin

Role required: sn_vul.vulnerability_admin or sn_vul.admin (deprecated)

Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://servicenow-prod.fluidtopics.net/msi8kaFkGNjyRib_XBHEzQ "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant."). For more information about managing granular roles, see [Manage persona and granular roles for Vulnerability Response](https://servicenow-prod.fluidtopics.net/WeKNf9YHNMJmJIA6yCsRvA "After you complete your initial assignment of persona roles using Setup Assistant, manage additional granular role assignments to users or groups from the User Administration module in your instance.").  
Note:  
You may notice performance degradation when running vulnerability calculators that contain scripts.

Order your rules to run the simplest rules first and only run
scripts on the items that cannot be handled with a condition and template value
or a risk rule.

## Procedure

1. Navigate to AllVulnerabilityAdministrationVulnerability Calculators.
2. Click New.
3. Fill in the fields on the form, as appropriate.  
   {#create-vul-calculator__table_t4d_4bd_5s__entry__2}

   | Field | Description |
   |-|-|
   | Name | The name of the vulnerability calculator. |
   | Table | Auto-filled with the name of the vulnerable item table. |
   | Application | Auto-filled with Vulnerability Response. |
   | Target field | Field to calculate. |
   | Description | Text description of the calculator. |
   | Active | Turn the calculator on or off. |
   [Table 1. Vulnerability calculator form]

   {#create-vul-calculator__table_t4d_4bd_5s}
4. Right-click in the header to Save.  
   The Vulnerability Calculator Rules section appears.
5. Create a rule for the calculator by clicking New.  
   Note:  
   For the New Risk Rules form (only available when the Target field is Risk Score) see step 10.
6. Fill in the fields, as appropriate.  
   {#create-vul-calculator__table_uf2_5w2_mhr__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the calculator rule. |
   | Order | The order in which to run the vulnerability calculator. A calculator with an order entry of 100 runs before a calculator with an order entry of 200. |
   | Calculator | Auto-filled with the calculator parent. |
   | Active | By default the Active check box is selected, which means the calculator rule is active. If you clear this check box, this rule does not apply to new vulnerable items created in the system. |
   | Advanced view | When selected, scripted conditions and scripted values can be selected from Condition type and Value type. |
   [Table 2. Vulnerability Calculator Rule form]

   {#create-vul-calculator__table_uf2_5w2_mhr}
7. Fill in the fields in the When this condition is met tab, as appropriate.  
   {#create-vul-calculator__table_xl5_43j_tw__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the calculator rule. |
   | Order | The order in which to run the vulnerability calculator. A calculator with an order entry of 100 runs before a calculator with an order entry of 200. |
   | Calculator | Auto-filled with the calculator parent. |
   | Active | By default the Active check box is selected, which means the calculator rule is active. If you clear this check box, this rule does not apply to vulnerable items created in the system. |
   | Advanced view | When selected, select scripted conditions and scripted values from Condition type and Value type. |
   | Condition type | Available when you select the Advanced view. Choices include: * Filter: Uses filter conditions. * Filter group: See [create a new filter group](https://servicenow-prod.fluidtopics.net/r5uDdmM_UX_B_rwi8GTPsA "Create and use filter groups to locate records from any table on your instance. For example, you can create a group of all computers by the same manufacturer. You can also filter configuration items (CIs) that have similar vulnerabilities or that fall within a particular subnet IP address range.") to define the calculator criteria. * Script: Script condition used to determine when to apply this calculator. Note: Before you write scripts for determining when to apply the calculators, return to the Vulnerability Calculators list. Explore the vulnerability calculator records shipped with the base system. {#create-vul-calculator__ul_fsf_ysn_zdb} |
   | Condition | Defines basic filter conditions for determining whether to use the calculator or not. Selecting either the Filter group or Script condition types, hides this field. Case sensitivity for the search text you enter in the condition builder is not supported on this record or form. |
   [Table 3. When this condition is met tab]

   {#create-vul-calculator__table_xl5_43j_tw}
8. Click the Set these values tab and fill in the fields on the form, as appropriate.  
   {#create-vul-calculator__table_p2z_4jj_tw__entry__2}

   | Field | Description |
   |-|-|
   | Value type | Available when you select the Advanced view. Choices include: * Template: Define the values to set on each field. * Script: Used to set the values on each field. {#create-vul-calculator__ul_sq2_25n_zdb} |
   | Script values | Available if you selected the Script value type. Defines what values to apply the calculations to. |
   | Template | Select the fields and values you want to use for the calculator. Selecting either the Script value type, hides this field. |
   [Table 4. Set these fields tab]

   {#create-vul-calculator__table_p2z_4jj_tw}
9. When you have completed all entries, click Submit.  
   Note:  
   When you edit an existing calculator, and you want to update all existing scores, you can use the Reapply Calculator button. It runs through all active vulnerable items (VIs), and if that calculator would be used to set its value, recalculates the value for those VIs. Since reapplying a calculator can take a long time, a scheduled job handles it.
10. For the New Risk Rules form, fill in the fields as appropriate.  
    Set each weight according to the percentage of the result that should come from that value. For any data that your scanner does not provide, or for data that should not be part of the risk score, set the weight to
    zero.

    You can add, delete, or update the fields. You can also configure the weightage percentage for the field values. For more information, see [Define fields and weights for the risk rule for Vulnerability Response Risk Calculators](https://servicenow-prod.fluidtopics.net/Emym5bSBOF1GcuDNoqGE5Q "Customize the parameters and weights for the risk rule so that you can generate risk scores that use the vulnerability and asset data that are unique to your organization. By selecting the fields that are included in the risk rule, you can define an effective risk scoring framework.").

    As you update the weights, scenarios display the weights remaining, as well as anticipated Risk Score results.
    {#create-vul-calculator__table_r41_lxq_lhz__entry__2}

    | Field | Description |
    |-|-|
    | Name | Name of the calculator rule. |
    | Order | The order in which to run the vulnerability calculator. A calculator with an order entry of 100 runs before a calculator with an order entry of 200. |
    | Calculator | Auto-filled with the calculator parent. |
    | Active | By default the Active check box is selected, which means the calculator rule is active. If you clear this check box, this rule does not apply to new vulnerable items created in the system. |
    | Condition | Defines basic filter conditions for determining whether to use the calculator. Selecting either the Filter group or Script condition types, hides this field. |
    | Weights ||
    | Vulnerability Severity | Percentage of the result that comes from severity. |
    | Vulnerability EPSS Score | Probability of the vulnerability being exploited. By default, the weight of this criteria is zero. If you want to use this for your risk score calculation, set an appropriate weight against this criteria. |
    | Exploit exists | Percentage of the result that comes from the existence of an exploit. If this information is not present in your vulnerabilities, set the weight to zero. |
    | Exploit skill level | Percentage of the result that comes from the skill level required by the exploit. If this information is not present in your vulnerabilities, set the weight to zero. |
    | Exploit attack vector | Percentage of the result that comes from where the attack is targeted. If this information is not present in your vulnerabilities, then set weight to zero. |
    | Service Business criticality | Percentage of the result that comes from business criticality. If you have not linked your CIs to business services, then set weight to zero. |
    | CI Exposure | Percentage of the result that comes from whether the CI is internet-facing. If the weight is non-zero, a condition filter appears to define which CI are internet-facing. Set the filter to select your Internet-facing configuration items. You can preview which records match the condition. |
    | Running total | Auto-computed percentage totals. When this value reaches 100, the Scenario preview shows you sample risk scores in different scenarios. |
    | Risk score scenarios | When all weights total 100%, risk score scenarios display, providing a preview of the risk score in some of the possible scenarios. |
    [ ]

    {#create-vul-calculator__table_r41_lxq_lhz}You can add or remove criteria, and adjust the weight of each criteria using the Embedded list. Figure 1. Risk Rule CI for Vulnerability Response v20.x
11. Click Submit.
{#create-vul-calculator__steps_ejr_xhy_w5}

*[\>]: and then


