---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Triage vulnerabilities automatically

# Triage vulnerabilities automatically {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Triage vulnerabilities automatically

The automated triage of vulnerabilities in ServiceNow Vulnerability Response streamlines the remediation process by transforming imported vulnerabilities into actionable remediation tasks.
This includes assigning vulnerable items (VIs), calculating risk, setting remediation targets, and grouping VIs.
The process ensures assets not found in the CMDB are reconciled, vulnerabilities prioritized, remediation activities assigned, and remediation confirmed through validation scans.
Show full answer Show less  

## Key Features

* **Automated Vulnerable Item Assignment:** Vulnerabilities are assigned to remediation tasks based on predefined rules, though manual intervention may be necessary for ungrouped or unmatched items.
* **Risk Score Revision:** Customers can adjust risk scores of vulnerable items within remediation tasks using vulnerability calculators and rules.
* **Remediation Target Rules:** These rules, created during initial setup, determine remediation targets and run upon vulnerability import to guide remediation efforts.
* **Ungrouped Vulnerable Items Handling:** Customers can review and manually group ungrouped VIs or revise group rules and perform rescans to improve grouping accuracy.
* **Automatic Closure of Older Vulnerable Items:** Items not recently detected can be closed automatically to maintain focus on current vulnerabilities.
* **Change Request Integration:** Remediation tasks can be linked to change requests assigned to IT operations for resolution. If Security Incident Response is enabled, security incidents can be created from remediation tasks.

## Practical Steps for Customers

* Log in to the Vulnerability Response instance and validate your CI Lookup and Assignment rules to ensure correct vulnerable item assignment.
* Verify remediation target rules to confirm they align with your remediation strategy.
* Review ungrouped vulnerable items and revise group rules or manually group items as needed.
* Adjust risk scores for vulnerable items to reflect current risk assessments.
* Close older vulnerabilities not detected recently by integrations to reduce noise.
* Research and prioritize remediation activities based on risk, affected systems, and patching schedules.
* Create and assign change requests for remediation tasks, moving tasks to an 'Under Investigation' state after submission.

## Why It Matters

This automated triage process helps ServiceNow customers efficiently manage and remediate vulnerabilities by reducing manual effort, improving prioritization, and ensuring that remediation tasks are clearly defined and assigned. It supports maintaining a secure IT environment by integrating vulnerability data with change and security incident management workflows.  
Reviewing and triaging new vulnerabilities is necessary to ensure successful
remediation. Transform vulnerability imports into remediation tasks with automated vulnerable
item (VI) assignment, risk calculation, remediation targets, and VI grouping.

Starting with imported vulnerabilities, reconcile the assets not found in the CMDB,
prioritize the results, translate that to remediation activities that are automatically
assigned, orchestrate the remediation process, and confirm completion with a validation
scan.

New vulnerable items are usually sorted into remediation tasks upon import, based on
remediation tasks rules. Sometimes, vulnerable items cannot be grouped or do not contain a
recognized configuration item.  
An overview of the vulnerability triage process:

* Log in to your Vulnerability Response instance.
* Validate that your rules (CI Lookup, Assignment) for vulnerable item are working as expected. For information on Assignment rules, see .  
  Note:  
  Due to the large volume in data imports, care should be taken with automated vulnerable item assignment.
* Validate that your remediation targets are correct. See [Vulnerability Response remediation target rules](https://servicenow-prod.fluidtopics.net/Rk0nNjDmu1fZ7GxcJJ20Jg "Remediation target rules define the expected time frame for remediating vulnerable items (VI), much like SLAs provide a time frame for remediating the vulnerability itself. For example, if an asset contains PCI data (credit card data) then the vulnerability on that item must be fixed within 30 days according to PCI DSS.") for information on how remediation target rules work and how to revise them.
* [View ungrouped vulnerable
  items](https://servicenow-prod.fluidtopics.net/RIaaWzRB9yp8opiXMBN7EQ "Vulnerable items that are not assigned to a group are placed in a viewable list.").
  * Looking at the ungrouped vulnerable items, consider revising your group rules and performing a rescan. See [Create or edit Vulnerability Response remediation task rules](https://servicenow-prod.fluidtopics.net/gjnIR~u_kUymvXKMt0Lqng "After you complete your initial assessment of remediation task rules using Setup Assistant, you can create rules to automatically group vulnerable items based on filter conditions. These rules automatically group vulnerable items as they are imported or manually created. Use the filter to limit the vulnerable items grouped by this rule, such as selecting all vulnerable items with exploits.") for more information.
  * Manually group the vulnerable items. [Manually create a remediation task in Vulnerability Response](https://servicenow-prod.fluidtopics.net/16Wxl5x6BP0pmlzjI_o~CA "Creating a remediation task manually is done when you want to group vulnerable items by something other than the Remediation Task Rules criteria. For example, you can create tasks for a particular manager, or for active, new exploits, such as ransomware that include different vulnerabilities. You can also use it to group ungrouped vulnerable items.") for more information.
  * Revise risk scores for the vulnerable items in your remediation tasks. See [Vulnerability Response calculators and vulnerability calculator rules](https://servicenow-prod.fluidtopics.net/3Hl03aogPFrru7chhJttaQ "Vulnerability calculators automate calculating initial values for the fields on vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used.") for more information.
  * Close older vulnerable items not recently detected by your third-party integrations. See [Automatic closing of vulnerable items and detections](https://servicenow-prod.fluidtopics.net/WS_04yLRKLSUS0KtzwXLuQ "You can automatically close stale detections and vulnerable items (VIs) associated with retired CIs using the Auto-Close rules module.") for more information.
  {#vuln-automated-triage__ul_jgd_gfy_hdb}
* [View and reclassify unmatched configuration items](https://servicenow-prod.fluidtopics.net/EaEAOf7Ltyr9QZ_PQwhXPA "Configuration items (CIs) that are not found in the Configuration Management Database (CMDB) are placed in a viewable list of discovered items. This list offers a convenient way to reclassify unmatched CIs.").
* Research what needs to be done for remediation. This step can include:

  * Determine what to deal with now and what you can defer. This determination is often based on risk score, affected systems, and patches with change windows.  
    Note:  
    Remediation target rules belong to vulnerable items. These rules are run when the vulnerable item is imported. These rules were created previously in the Setup Assistant.
  * [Refresh vulnerable items](https://servicenow-prod.fluidtopics.net/sdu4zd31w~LlEBWRRk3pbw "The Update status related link is used to have vulnerable items inspected to see if there are any additional vulnerable items that belong to a remediation task. Use it if an update is warranted outside the scheduled job."), if necessary, and [View the remediation target status of a Vulnerability Response vulnerable item](https://servicenow-prod.fluidtopics.net/MFZryKSxKXkkgmG2VwkSEA "When a vulnerable item has nearly reached (or passed) its remediation target date, as defined by a remediation target rule, the vulnerable item record is updated with a status. This information can help the analyst proactively monitor upcoming remediation activities.").
  * Create a Change Request and assign the remediation task to an assignment group (IT Operations) for remediation.  
    Note:  
    If the vulnerability constitutes a security incident and the Security Incident Response plugin (com.snc.security_incident) is activated, you can create security incident records from the remediation tasks instead.
  * After submitting one or more change requests, move the group state to Under Investigation.
  {#vuln-automated-triage__ul_ayz_bmy_hdb}
{#vuln-automated-triage__ul_plz_dz2_ycb}

