---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability classification groups and rules

# Vulnerability classification groups and rules {#ariaid-title1}

Release version: Yokohama  
Updated January 30, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Classification groups automate classification of values of a table based on the
classification rules defined in the group. The condition for each rule is evaluated in order, and
the first matching rule is used.  
The Vulnerability Response base system includes the following two classification groups, which classify discovered items and vulnerabilities respectively:

* Discovered Items Classification
* Vulnerability Entry Classification

{#vulnerability-classification-rules__ul_kfx_h21_xsb}Whenever vulnerabilities and discovered items are imported, the vulnerability classification rules in the respective groups get executed. Based on the conditions set in the rule, the records get classified to the relevant classification group. You can create, edit, delete or reapply these rules to an existing vulnerability.  
Note:  
* For a selected table, there can only be one active classification group.
* Once you create a group, you cannot delete it.
{#vulnerability-classification-rules__ul_pm5_v21_xsb}
For more information, see [Create and edit a classification rule](https://www.servicenow.com/docs/Xl2FFh34y7Oq2PqSA6H3Hg "Create rules to automatically classify the incoming vulnerabilities to the correct teams for remediation."), [Apply a rule to an existing vulnerability](https://www.servicenow.com/docs/GE29Nv8jaM_~oGiHDINMzg "When you change a classification rule, rerun all the active rules on all the vulnerability entries. You can also retrofit the existing vulnerabilities, by applying the newly created classification rules to the existing vulnerabilities."), and [Deactivate or delete a classification rule](https://www.servicenow.com/docs/wcQg_gDtgy~EAhfTPMj78g "Deactivate or delete a classification rule if it is no longer needed or relevant.").

