---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response remediation tasks and remediation task rules overview

# Vulnerability Response remediation tasks and remediation task rules overview {#ariaid-title1}

Release version: Zurich  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read  
Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have
to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.

## Tracking deferral counts for vulnerable items and remediation tasks {#vulnerability-groups__section_o2z_zzb_35b}

Track the number of times a vulnerable item, application vulnerable item, a container vulnerable item, or a remediation task is deferred. A scheduled job, set deferral counts, runs daily to post counts for
the records that are deferred more than once in the Deferral count column. Records are displayed in the Multiple deferrals modules for VR, AVR, and CVR.

## Refreshing vulnerable items automatically {#vulnerability-groups__section_o5p_5nx_qcb}

Note:  
Vulnerable item refresh automation applies only to remediation tasks created using the condition filter or filter group. Automation does not apply to VIs that were added manually or grouped using Remediation Task Rules.

When the Automatically update related vulnerable items check box is selected, new VIs matching the remediation task
filter criteria are automatically added to the task. Vulnerable items in the remediation task that no longer match the filter criteria are automatically removed from the task.

By default, when the remediation task leaves the Open state, the
check box is cleared. If you want vulnerable items to continue being added to the
remediation task, regardless of state, disable the Set auto refresh vulnerable items business rule.  
You can select the check box again manually from the Under Investigation state. Automatically update related vulnerable items is not disabled when the remediation task moves into the Awaiting Implementation state. Once in the Awaiting Implementation state, no new vulnerable items can be added to the existing task, nor can existing vulnerable items be removed it.  
Note:  
When a remediation task is created manually, and VIs are added using the Condition filter or Filter Group, the check box is unchecked. You have the choice to select the box or not.

## Refreshing vulnerable items manually {#vulnerability-groups__section_v55_bxr_fdb}

For manually created remediation tasks with a Filter Group or Condition filter, when you click the Refresh associated vulnerable items related link on the
Remediation Task page, any vulnerable items that match the filter criteria are added. Items no longer matching the criteria are removed. This action allows an immediate update of the list of vulnerable items
and is used whether the Automatically update related vulnerable items check box is selected or not.

Manually created remediation tasks using Condition or
Filter Group filter types are refreshed once an hour.

## Understanding remediation task rules {#vulnerability-groups__VulGrpRules}

Remediation task rules allow you to define how vulnerable items are automatically grouped
and assigned. A default rule, Vulnerability, is included in the base
system that gathers vulnerable items based on their vulnerabilities. However, you can group
by any other set of values in columns accessible from the VI. These values could include
configuration item (CI) support group, vulnerability severity, and, so on.

You can create any number of conditions. Once you set a Group by selection, another row appears. You can have up to six Group by selections. You can automate group assignment, as well. See [Create or edit Vulnerability Response remediation task rules](https://www.servicenow.com/docs/dZaIsBkihCnzOQ1uNsHyag "After you complete your initial assessment of remediation task rules using Setup Assistant, you can create rules to automatically group vulnerable items based on filter conditions. These rules automatically group vulnerable items as they are imported or manually created. Use the filter to limit the vulnerable items grouped by this rule, such as selecting all vulnerable items with exploits.") and [Filtering within Vulnerability Response](https://www.servicenow.com/docs/BgywhSSlhHbX1PVO3k5QWw "Remediation Task Rules, Calculators, and Assignment Rules use conditions during import, created using the Condition builder. Changes to their criteria can affect performance since each record is evaluated using these filters.") for more information.

You can control whether all matching rules are evaluated or only the first match is applied by setting the execution mode on the remediation task rules page. This setting is configured in the Security Exposure Management Workspace. For more information, see [Grouping multiple findings as remediation tasks for easy processing using remediation task rules](https://www.servicenow.com/docs/F8p2fBJ7D3XA7wdF8RLVHg "Remediation tasks help vulnerability analysts and remediation teams manage findings in bulk. By configuring remediation task rules, you can automatically group findings into remediation tasks, eliminating the need for manual task creation and streamlining remediation efforts.").  
Note:  
To make Rapid7 InsightVM asset tags available for use in the Condition filter for Remediation Task Rules, you must run the Rapid7 InsightVM Asset List integration before the other Rapid7 InsightVM integrations.

For example, you can group your vulnerable items by the cost center of the vulnerable CI,
or by the attack vector of the vulnerability. You can have one task rule for low severity
vulnerabilities or low risk CIs. You can have another task rule for critical servers, and
vulnerabilities with exploits --- vulnerable items that expose the company to more risk.

A different set of rules can be used for vulnerable items that expose the company to more risk. The remediation task name is appended to the remediation task rule Group by values to make the short
description of the new record. See [Manually create a remediation task in Vulnerability Response](https://www.servicenow.com/docs/izhqPMAUewLZ7RLtVJsEjw "Creating a remediation task manually is done when you want to group vulnerable items by something other than the Remediation Task Rules criteria. For example, you can create tasks for a particular manager, or for active, new exploits, such as ransomware that include different vulnerabilities. You can also use it to group ungrouped vulnerable items.") for more information on available fields.
Figure 1. Condition builder example for Group By entries

When a new vulnerable item is created, imported, or reopened after being closed, the
vulnerability rules are evaluated against it. A VI is only evaluated once, automatically,
unless it is reopened after being closed or the rules are reapplied manually.

The following process is used for each new or reopened VI:  
* For each remediation task rule, the VI is compared to the remediation task rule filter.
* For each rule where the remediation task rule condition matches, the rule pulls the data from the Group by selections on the VI. It builds a group name and field. In this case, High Risk: QID-32342:<var class="keyword varname">Summary of QID-3242</var> (Name: vulnerability ID:vulnerability summary).  
  Note:  
  The short description field is limited to 160 characters. Longer vulnerability summaries are truncated.
  The rule checks to see if there is a matching Open remediation task that is assigned to the same assignment group as the VI.
  * If the task is found, the VI is added to the existing task in the Open state.
  * If no task in the Open state is found, the rule creates a High Risk: QID-32342 task, assigns it to the same assignment group as the VI, and places the VI in the remediation task.
  {#vulnerability-groups__ul_k2v_4zv_rkb}
{#vulnerability-groups__ul_gg1_skv_rkb}

More than one remediation task rule can be defined, to group different kinds of vulnerabilities. Since each vulnerability is compared with the remediation task rule conditions before putting it in a remediation task, too many
rules may have a performance impact.

By default, remediation task rules use the assignment group set by the
Assignment Rules on the vulnerable item when grouping the items,
and assigns the remediation task to match the vulnerable items.

As part of the default task rule, the assignment of these remediation tasks is controlled
by the rules in the Assignment Rules module. For more information on
assignment rules, see [Vulnerability Response assignment rules overview](https://www.servicenow.com/docs/dPwJSkv0RtwDysGI8YEtOA "Define the criteria by which vulnerable items (VITs) are automatically assigned to an assignment group for remediation.").

When a task rule is deleted, from the form or list view, you have the option to delete all
Open tasks created by that rule. Tasks not in the
Open are excluded.

## Reapplying remediation task rules {#vulnerability-groups__section_z2n_bnj_5kb}

When you want to change a remediation task rule, use the Reapply
button on the remediation task rule page to rerun the changed rule on all active
Open remediation tasks created by that rule. It deletes and
recreates remediation tasks based on the changed rule automatically.  
Important:  
As a vulnerability admin and analyst, you can evaluate the remediation task rules for selected vulnerable items in the Vulnerability Manager Workspace. This method is more efficient than reapplying the Remediation Task Rules in the classic UI, which is a time-consuming process. For more information, see [Re-evaluate the remediation properties of the records in the Vulnerability Manager Workspace](https://www.servicenow.com/docs/sAsbA7Mpt57oSxJqlQ2X9g "Evaluate the assignments, remediation target date, remediation tasks, exceptions, and risk score for a set of records (VITs, AVITs, CVITs or TRs) in the Vulnerability Manager Workspace.").

