Bulk edit for false positive in the Security Exposure Management Workspace
Mark one or more records (VITs, AVITs, CVITs, or TRs) as false positive concurrently using the bulk edit feature from the Security Exposure Management Workspace instead of manually selecting each item.
Before you begin
Role required:
- sn_vul.vulnerability_analyst, sn_vul.vulnerability_admin, or sn_vul.remediation_owner for host vulnerable items (VITs)
- sn_vul.app_sec_manager, sn_vul.app_security_champion for application vulnerable items (AVITs)
- sn_vul_container.vulnerability_analyst, sn_vul_container.vulnerability_admin, or sn_vul_container.remediation_owner for container vulnerable items (CVITs)
- sn_vulc.admin, sn_vulc.remediation_owner for configuration test results (CTRs)
About this task
When you raise a false positive request for one or more records from the Bulk edit modal, a remediation task is created with the selected records.
Note:
When you raise a false positive request for the Application Vulnerable
Items (AVITs) using the bulk edit feature, the AVITs from the scanners with the Manage False positive with Servicenow parameter set to false are not updated.
- If you select AVITs from various scanners, some with the Manage False positive with Servicenow parameter set to true and other set to false, the AVITs linked to the scanners with the Manage False positive with Servicenow parameter set to false are not updated.
- If you select AVITs from only the scanners with the Manage False positive with Servicenow parameter set to false, the False positive option does not appear in the Reason field in the Bulk Edit modal.
Procedure
Result
In the Security Exposure Management Workspace, on the List page, navigate to , open the corresponding state change approval record (VCA#) and check the status of your request in the Approval state column:
| Approval state | Result |
|---|---|
| Approved | The state of the Remediation Task transitions to Closed with the Reason as False positive. The state and reason are rolled down to the records. |
| Rejected | The state of the Remediation Task and its records doesn’t change. |
In the Activity stream of a record or remediation task, you can view the entire workflow of your request.