Join the #BuildWithBuildAgent Challenge! Get recognized, earn exclusive swag, and inspire the ServiceNow Community with what you can build using Build Agent.  Join the Challenge.

Request risk reduction for a vulnerable item do not work OOTB

Don Dom
Tera Contributor

Hello.

 

We have issue with OOTB - Request risk reduction for a vulnerable item.

When we request:

A. Request for Deferral

B. Request for Risk Reduction

 

DonDom_0-1763027629458.png
Two "State Change Approvals" are being created for A and B

DonDom_1-1763027759057.png

When we do all approvals A is going in to Approve and the VIT state get back to DEFFERED, but (B) is still in Draft and do not lower the RISK

 

DonDom_2-1763027819537.png

Where can be a problem that second (B) task is not going forward?

 

This is OOTB - nothing was changed.

 

Please advise.

THx

 

4 REPLIES 4

andy_ojha
ServiceNow Employee
ServiceNow Employee

Hey there,

 

In your testing - when you initiate the Exception request and check both boxes (risk reduction and deferral), and it creates the two VCAs (state change approvals)...

 > What is the Approval State on the two VCAs at that point in time?
 > Are they both showing as "In Review"?

 

On the 2nd VCA for the Risk Reduction (Desired value is 5 - None), what happens if you actually attempt to Approve that request as an Approval user even though it is in Draft (should be > In Review..)? 

 > Does it proceed to then reduce the Risk Rating on the target VIT record?

Hello Andy:


@andy_ojha wrote:

Hey there,

 

In your testing - when you initiate the Exception request and check both boxes (risk reduction and deferral), and it creates the two VCAs (state change approvals)...

 > What is the Approval State on the two VCAs at that point in time?
 > Are they both showing as "In Review"?

 

 


No. Second one is still in DRAFT and no assessment attached.

DonDom_0-1763112941459.png

in PDI both of them are in: "In Review" + to both assessment is attached:

Screen from my PDI:

DonDom_2-1763113125393.png


In the logs we found only - and we dig in that now:

DonDom_1-1763113052432.png

 


 

On the 2nd VCA for the Risk Reduction (Desired value is 5 - None), what happens if you actually attempt to Approve that request as an Approval user even though it is in Draft (should be > In Review..)? 

 > Does it proceed to then reduce the Risk Rating on the target VIT record?


After approval nothing is happening with this "task" still in Draft.

Ok I think we found the issue - "Exception Management Configuration" was the issue somehow... 

DonDom_0-1763119433957.png

 

Ok but now the Questionnaire is not being attached - so not able to see questionnaire answers .... uhh 

DonDom_1-1763124539027.png