---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response remediation tasks and remediation task rules overview

# Vulnerability Response remediation tasks and remediation task rules overview {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Vulnerability Response remediation tasks and remediation task rules overview

Vulnerability Response remediation tasks help ServiceNow customers efficiently organize and manage vulnerable items (VIs) by grouping and analyzing them in bulk.
Remediation task rules automate the grouping and assignment of these vulnerable items based on configurable criteria, reducing manual effort and enabling streamlined remediation workflows.
Show full answer Show less  

## Key Features

* **Automated Remediation Task Creation:** Remediation tasks are formed automatically based on defined filter criteria, grouping vulnerable items by attributes such as vulnerability severity, assignment group, or configuration item support group.
* **Deferral Tracking:** The system tracks the number of deferrals for vulnerable items and remediation tasks, updating counts daily to highlight items deferred multiple times for better prioritization.
* **Vulnerable Item Refresh Automation:** Remediation tasks created via condition filters or filter groups can automatically refresh their associated vulnerable items, adding new matches and removing those that no longer fit criteria. This automation is state-dependent and can be toggled manually.
* **Manual Refresh Option:** Users can manually refresh associated vulnerable items on remediation tasks at any time to immediately update the list based on filter criteria.
* **Remediation Task Rules Configuration:** Customers can create multiple remediation task rules with up to six grouping conditions to tailor how vulnerable items are grouped into tasks. Rules can be set to evaluate all matches or stop at the first match, controlling task creation behavior.
* **Automatic Rule Re-evaluation:** When key fields like Assignment group or Preferred solution change on a finding, remediation task rules can automatically re-evaluate and regroup findings without manual intervention by enabling a system property.
* **Reapply and Update Rules:** When remediation task rules are modified, customers can reapply rules to existing open tasks to reflect changes immediately, helping maintain alignment with evolving policies.

## Key Outcomes

* **Improved Efficiency:** Automated grouping and assignment reduce manual effort, enabling analysts and remediation specialists to focus on resolving vulnerabilities rather than organizing them.
* **Better Visibility and Tracking:** Deferral counts and real-time updates of vulnerable items in remediation tasks provide clearer insight into progress and outstanding risks.
* **Flexible and Scalable Management:** Customizable remediation task rules allow customers to align vulnerability management with organizational priorities, grouping items by severity, risk, asset attributes, or business units.
* **Dynamic Adaptation:** Automatic re-evaluation of task rules upon assignment changes ensures remediation tasks stay current as vulnerability contexts evolve.  
Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have
to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.

## Tracking deferral counts for vulnerable items and remediation tasks {#vulnerability-groups__section_o2z_zzb_35b}

Track the number of times a vulnerable item, application vulnerable item, a container vulnerable item, or a remediation task is deferred. A scheduled job, set deferral counts, runs daily to post counts for
the records that are deferred more than once in the Deferral count column. Records are displayed in the Multiple deferrals modules for VR, AVR, and CVR.

## Refreshing vulnerable items automatically {#vulnerability-groups__section_o5p_5nx_qcb}

Note:  
Vulnerable item refresh automation applies only to remediation tasks created using the condition filter or filter group. Automation does not apply to VIs that were added manually or grouped using Remediation Task Rules.

When the Automatically update related vulnerable items check box is selected, new VIs matching the remediation task
filter criteria are automatically added to the task. Vulnerable items in the remediation task that no longer match the filter criteria are automatically removed from the task.

By default, when the remediation task leaves the Open state, the
check box is cleared. If you want vulnerable items to continue being added to the
remediation task, regardless of state, disable the Set auto refresh vulnerable items business rule.  
You can select the check box again manually from the Under Investigation state. Automatically update related vulnerable items is not disabled when the remediation task moves into the Awaiting Implementation state. Once in the Awaiting Implementation state, no new vulnerable items can be added to the existing task, nor can existing vulnerable items be removed it.  
Note:  
When a remediation task is created manually, and VIs are added using the Condition filter or Filter Group, the check box is unchecked. You have the choice to select the box or not.

## Refreshing vulnerable items manually {#vulnerability-groups__section_v55_bxr_fdb}

For manually created remediation tasks with a Filter Group or Condition filter, when you click the Refresh associated vulnerable items related link on the
Remediation Task page, any vulnerable items that match the filter criteria are added. Items no longer matching the criteria are removed. This action allows an immediate update of the list of vulnerable items
and is used whether the Automatically update related vulnerable items check box is selected or not.

Manually created remediation tasks using Condition or
Filter Group filter types are refreshed once an hour.

## Understanding remediation task rules {#vulnerability-groups__VulGrpRules}

Remediation task rules allow you to define how vulnerable items are automatically grouped
and assigned. A default rule, Vulnerability, is included in the base
system that gathers vulnerable items based on their vulnerabilities. However, you can group
by any other set of values in columns accessible from the VI. These values could include
configuration item (CI) support group, vulnerability severity, and, so on.

You can create any number of conditions. Once you set a Group by selection, another row appears. You can have up to six Group by selections. You can automate group assignment, as well. See [Create or edit Vulnerability Response remediation task rules](https://www.servicenow.com/docs/gjnIR~u_kUymvXKMt0Lqng "After you complete your initial assessment of remediation task rules using Setup Assistant, you can create rules to automatically group vulnerable items based on filter conditions. These rules automatically group vulnerable items as they are imported or manually created. Use the filter to limit the vulnerable items grouped by this rule, such as selecting all vulnerable items with exploits.") and [Filtering within Vulnerability Response](https://www.servicenow.com/docs/Xuimut0h5JdR_s9oG0BCCQ "Remediation Task Rules, Calculators, and Assignment Rules use conditions during import, created using the Condition builder. Changes to their criteria can affect performance since each record is evaluated using these filters.") for more information.

You can control whether all matching rules are evaluated or only the first match is applied by setting the execution mode on the remediation task rules page. This setting is configured in the Security Exposure Management Workspace. For more information, see [Grouping multiple findings as remediation tasks for easy processing using remediation task rules](https://www.servicenow.com/docs/SrC~j4zCJFTLagGNPKL54g "Remediation tasks help vulnerability analysts and remediation teams manage findings in bulk. By configuring remediation task rules, you can automatically group findings into remediation tasks, eliminating the need for manual task creation and streamlining remediation efforts.").  
Note:  
To make Rapid7 InsightVM asset tags available for use in the Condition filter for Remediation Task Rules, you must run the Rapid7 InsightVM Asset List integration before the other Rapid7 InsightVM integrations.

For example, you can group your vulnerable items by the cost center of the vulnerable CI,
or by the attack vector of the vulnerability. You can have one task rule for low severity
vulnerabilities or low risk CIs. You can have another task rule for critical servers, and
vulnerabilities with exploits --- vulnerable items that expose the company to more risk.

A different set of rules can be used for vulnerable items that expose the company to more risk. The remediation task name is appended to the remediation task rule Group by values to make the short
description of the new record. See [Manually create a remediation task in Vulnerability Response](https://www.servicenow.com/docs/16Wxl5x6BP0pmlzjI_o~CA "Creating a remediation task manually is done when you want to group vulnerable items by something other than the Remediation Task Rules criteria. For example, you can create tasks for a particular manager, or for active, new exploits, such as ransomware that include different vulnerabilities. You can also use it to group ungrouped vulnerable items.") for more information on available fields.
Figure 1. Condition builder example for Group By entries

When a new vulnerable item is created, imported, or reopened after being closed, the vulnerability rules are evaluated against it.

The following process is used for each new or reopened VI:  
* For each remediation task rule, the VI is compared to the remediation task rule filter.
* For each rule where the remediation task rule condition matches, the rule pulls the data from the Group by selections on the VI. It builds a group name and field. In this case, High Risk: QID-32342:<var class="keyword varname">Summary of QID-3242</var> (Name: vulnerability ID:vulnerability summary).  
  Note:  
  The short description field is limited to 160 characters. Longer vulnerability summaries are truncated.
  The rule checks to see if there is a matching Open remediation task that is assigned to the same assignment group as the VI.
  * If the task is found, the VI is added to the existing task in the Open state.
  * If no task in the Open state is found, the rule creates a High Risk: QID-32342 task, assigns it to the same assignment group as the VI, and places the VI in the remediation task.
  {#vulnerability-groups__ul_k2v_4zv_rkb}
{#vulnerability-groups__ul_gg1_skv_rkb}

More than one remediation task rule can be defined, to group different kinds of vulnerabilities. Since each vulnerability is compared with the remediation task rule conditions before putting it in a remediation task, too many
rules may have a performance impact.

By default, remediation task rules use the assignment group set by the
Assignment Rules on the vulnerable item when grouping the items,
and assigns the remediation task to match the vulnerable items.

As part of the default task rule, the assignment of these remediation tasks is controlled
by the rules in the Assignment Rules module. For more information on
assignment rules, see .

When a task rule is deleted, from the form or list view, you have the option to delete all
Open tasks created by that rule. Tasks not in the
Open are excluded.

## Reapplying remediation task rules {#vulnerability-groups__section_z2n_bnj_5kb}

When you want to change a remediation task rule, use the Reapply
button on the remediation task rule page to rerun the changed rule on all active
Open remediation tasks created by that rule. It deletes and
recreates remediation tasks based on the changed rule automatically.  
Important:  
As a vulnerability admin and analyst, you can evaluate the remediation task rules for selected vulnerable items in the Vulnerability Manager Workspace. This method is more efficient than reapplying the Remediation Task Rules in the classic UI, which is a time-consuming process. For more information, see [Re-evaluate the remediation properties of the records in the Vulnerability Manager Workspace](https://www.servicenow.com/docs/OepC9QWfPbJ7hX~pujy8SQ "Evaluate the assignments, remediation target date, remediation tasks, exceptions, and risk score for a set of records (VITs, AVITs, CVITs or TRs) in the Vulnerability Manager Workspace.").

## Automatic re-evaluation of remediation task rules {#vulnerability-groups__section_autoreeval_nfc}

Remediation task rules are automatically re-evaluated when the Assignment group or Preferred solution changes on a finding. You don't need to manually reapply the rule. The finding is
unlinked from its current remediation task and regrouped under the task that matches its updated value.

To enable automatic re-evaluation, activate the sn_sec_rem.rerun_task_rules system property. This property is not activated by default. For steps to enable it, see [Assigning findings to remediation teams using assignment rules](https://www.servicenow.com/docs/eGNJ00gR1r0ney~~aTmnSg "Assignment rules automatically assign findings, such as vulnerable items, application vulnerabilities, container vulnerabilities, and configuration test results, to the appropriate groups for remediation. This streamlined triage ensures that tasks are directed to the appropriate teams, and enhances consistency and visibility across security and compliance programs.").

A change to any other Group by field doesn't trigger re-evaluation. To regroup findings based on changes to those fields, manually reapply the remediation task rule.

