Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configuring roll-up calculator rules

Configure roll-up calculator rules to compute the cumulative risk score for remediation tasks and imported vulnerabilities.

Parent Topic:Configure rules to manage findings

Related topics

Prioritizing vulnerabilities and other findings using roll-up calculators

Create or edit roll-up calculator rules

Create rules to roll-up risk scores on imported findings and remediation tasks.

Before you begin

Role required: See Access control lists (ACLs) for administration rules

Procedure

  1. Navigate to Workspaces > Security Exposure Management Workspace.

  2. Select Administration in the navigation pane.

  3. Select Review on the Roll-up calculator rules tile.

  4. On the Rules page, select Roll-up calculator in the navigation pane.

  5. Select New and fill in the fields on the form:

FieldDescription
Details
NameName of the rule.
Target tableName of the table from which the risk score must be rolled-up.
Target fieldName of the field from the table that must be considered for risk roll-up.
ActiveIndicates whether the rule is active.
DescriptionDescription of the rule.
Source selection
Applies to

The finding table to which the risk score roll-up applies to.

The Applies to field is dependent on the selected target table, and its options are updated accordingly. For instance, choosing the Container remediation task [sn_vul_container_vulnerability] limits the Applies to field options to Container vulnerable item. This dynamic update ensures that only relevant options are available based on the target table selected.

IncludeDefines the conditions for roll-up on the finding table.
Roll-up calculations
BasicAssign weightage to specify the relative impact of each of the following factors on the rolled-up risk score:- Maximum risk score: Maximum risk score of the findings considered. - Average score: Aggregate of the risk scores of all the findings. - Count of records: Number of findings. A larger number of findings increases the overall score, while a smaller number lowers it.
Script \(Advanced option\)The scripting feature is an advanced feature to build a custom script that should return the risk score, which is an integer value ranging from 0 to 100.
  1. Select Save.