---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Mark as a false positive

# Mark as a false positive {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Mark a vulnerable item (VI) or remediation task (VUL) as a false positive if the
warning given by the scanner is not actually an issue. For example, if a configuration item
has been decommissioned but the scanner is still raising an issue related to it, mark it as
a false positive.

## Before you begin

Role required: remediation owner

You can request false positives from the Vulnerability Response Workspaces. See [Request a false positive for a vulnerable item or remediate task](https://servicenow-prod.fluidtopics.net/p4KWSnJ679hjoYagUtsFLw "Indicate a false positive request for host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT), or remediation task (VUL, AVUL, CVUL or CRG) in the IT Remediation Workspace. A false positive is a condition where a scanner incorrectly reports that a vulnerability exists in the system due to situations such as an incorrect classification, improper logic, or an algorithm in the scanner.").

You can also request false positives in the classic
environment:

## Procedure

1. Navigate to Vulnerability ResponseVulnerable Items (or Remediation Tasks)All.
2. Open the VI or VUL you want to mark as a false positive and click Mark as False Positive.  
   The VI or VUL must be in an Open state.
3. On the False Positive form, enter details in Additional information and click Request Approval.  
   The request is sent for approval and the State of the VI or VUL changes to In Review.
{#raise-fp-request__steps_m2d_md3_jlb}

*[\>]: and then


