---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Analytics and Reporting Solutions for Vulnerability Response

# Analytics and Reporting Solutions for Vulnerability Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Analytics and Reporting Solutions for Vulnerability Response

Analytics and Reporting Solutions for Vulnerability Response enables organizations to monitor vulnerability remediation effectively.
With tools and procedures designed to enhance productivity, users can track high-risk issues, assignment group workloads, and recurring vulnerabilities through dynamic data visualizations and dashboards.
Show full answer Show less  

## Key Features

* **Data Visualizations:** Access dynamic visualizations in the Vulnerability Response Workspaces to assess the threat level and track remediation progress based on active vulnerabilities.
* **Dashboards:** Default dashboards are available for vulnerability analysts, providing insights into remediation task aging and high-risk vulnerable items. Users can switch to the New Experience UI for an enhanced dashboard view.
* **Remediation Process:** Manage remediation tasks directly from the Vulnerability Response Workspaces, including creating change requests, adding notes, deferring tasks, and tracking compliance obligations.
* **Automated Scans:** Scanning is automated based on a configured schedule, with the system updating the status of vulnerable items based on scan results.
* **Deployment Metrics:** Comprehensive metrics within Vulnerability Solution Management help identify bottlenecks in remediation tasks and provide detailed insights into vulnerabilities.

## Key Outcomes

By utilizing these analytics and reporting solutions, ServiceNow customers can expect streamlined remediation processes, improved visibility into vulnerability status, and timely identification of compliance obligations. This ultimately helps organizations reduce risk and enhance overall security posture.  
Monitoring vulnerability remediation involves viewing trends, managing risk, and monitoring assignment groups. You can review high risk issues, assignment group workloads, deferrals and, reoccurring vulnerabilities. Vulnerability Response offers tools, reports, and procedures to make that process more productive and efficient.

## Data visualizations in the Vulnerability Response Workspaces {#monitor-vuln-rem-prog__section_iqs_djc_wqb}

The Vulnerability Response Workspaces include data visualizations that can help you monitor your remediation progress. You can determine the threat level to your organization by viewing the number and severity of active
vulnerabilities that are important to your organization on dynamic data visualizations that are updated as vulnerability data changes. See [Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/LLBmw_a5Cu0nzxorsbszKQ "The Vulnerability Manager Workspace enables vulnerability managers and analysts to monitor the vulnerabilities and misconfigurations that they care the most about and decide strategically which vulnerabilities they send to IT teams to fix.") and [Exploring the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/kl4_xDHEVmF1jpL7AeKbFw "The IT Remediation Workspace is intended for IT remediation owners and IT groups. It is composed of home and list views as well as data visualizations that you can click that let you see the remediation tasks you've been assigned and how many records assigned to you have solutions.") for more information about the dynamic data visualizations that are available.

Vulnerability analysts can also use default Vulnerability Response dashboards at AllVulnerability ResponseOverview.  
Important:  
Starting with version 19.0 of Vulnerability Response, this dashboard can also be viewed in the New Experience UI. To view the dashboard in the new UI, navigate to WorkspacesVulnerability Manager Workspace and click the Dashboards icon. Depending on your role, the default dashboard is displayed. To view other dashboards, click the drop-down next to the dashboard name. For more information, see [Dashboards in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/2xZMBwx48zDozvbNZJgOtQ "On the Dashboards page of the Vulnerability Manager Workspace, you can view the dashboards in the Next Experience UI and use these dashboards to track and analyze the vulnerabilities.") and [Dashboards in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/D8mVjNkutVKLD1vlxpTJaA "The Dashboards page in the IT Remediation Workspace provides the Vulnerability Remediation dashboard in the Next Experience UI which can be used to focus on the remediation tasks and vulnerable items.").  
Note:  
If you are on Tokyo, you can view the dashboards in the Next Experience UI but with some functional loss.

## Vulnerability Response remediation process {#monitor-vuln-rem-prog__section_jk2_s4q_2db}

Most vulnerability remediation is done from the remediation task record from within the Vulnerability Response Workspaces. From the remediation tasks (RTs) in the Under Investigation state, you can perform several tasks.

* Create change requests.
* Add work notes and descriptions of vulnerabilities within the remediation task.
* Defer the remediation task and the vulnerable items in it until a later date.
* Close the remediation task.
* Track new regulatory compliance obligations, which are usually time sensitive.
{#monitor-vuln-rem-prog__ul_i1y_3k5_b2b}

* Log in to your Vulnerability Response instance.
* Review your Vulnerability Management and third-party dashboards and reports to locate problem areas. For example, view dashboards that show remediation task (RT) aging by states or high risk vulnerable items (VIs) past their remediation target date.
* Review the state of remediation tasks, in order of risk.
* Revise the prioritization for the tasks by adjusting your risk score calculators if the risk score is not being calculated correctly or deferring VIs or RTs, as needed. See [Vulnerability Response calculators and vulnerability calculator rules](https://servicenow-prod.fluidtopics.net/3Hl03aogPFrru7chhJttaQ "Vulnerability calculators automate calculating initial values for the fields on vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used.") or [Defer a Remediation task](https://servicenow-prod.fluidtopics.net/Lm~gCnNyRhKdRT6AmVlYHQ "If you determine that the issue associated with a remediation task (VUL) is a low priority and can be immediately deferred without further analysis, you can use the Request Exception feature.") for more information on these options.
* Review deferred vulnerable items about to reopen and take further action as required. If you want to initiate and track change activities on your assets, remediation tasks, and their corresponding vulnerable items, for more information, see [Change management for Vulnerability Response](https://servicenow-prod.fluidtopics.net/rJLLQMfetmDSSTGbuH_CNw "As an IT remediation owner, you can create and manage change requests (CHG) directly from remediation tasks (RT) in the Vulnerability Response application. Change requests help you initiate and track change activities on your assets so that you can remediate your remediation tasks and their corresponding vulnerable items.")for further action.
* Review feedback from IT Operations.Once you are notified that a change request is resolved, wait for the next scan. Scans are triggered automatically by the third-party import schedule configured in the Setup
  Assistant.

* After a scan, if the state is Fixed, vulnerable items are automatically closed during import. The group closes when all vulnerable items in the group are fixed.
* After the scan, if the state is not Fixed, the VI is automatically moved back to Under Investigation.
* Vulnerable items set to 'Resolved' in your instance but not transitioned to 'Closed/Fixed' by the third party integration runs are reopened if they are detected during rescans.

  For Qualys detections, if the scanner continues to find VIs that were set to 'Resolved' but then not transitioned to 'Closed/Fixed' by subsequent scans, these VIs move back to 'Open' when the last found date is
  later than the Resolved date.

  For Rapid7 detections, an option is now available on the Rapid7 configuration page in your instance to reopen resolved VIs by age. If enabled, VIs set to 'Resolved' but then not transitioned to 'Closed/Fixed' by subsequent scans transition back to 'Open' after the
  number of days that you enter.
{#monitor-vuln-rem-prog__ul_ng1_dy2_ycb}

## Vulnerability Solution Management Deployment Progress {#monitor-vuln-rem-prog__section_idd_bnh_zhb}

Comprehensive deployment metrics for remediation tasks and vulnerability entries are included in Vulnerability Solution Management under Remediation Status in vulnerabilities, vulnerable items. Easily identify which remediation task or vulnerability is slowing resolution progress. Drill down into how the
vulnerability is identified, or what aspects of the affected assets may be causing the remediation issue. Update the status of your metrics using the Update status related link in the vulnerability, solutions,
and remediation task forms.

*[\>]: and then


