Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Disable or enable risk reduction for a CVE or TPE

As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.

Before you begin

Role required: admin

About this task

The risk reduction for a CVE and TPE is enabled by default.

Note: The compensating controls feature is available for host vulnerabilities only.

Procedure

  1. Navigate to Workspaces > Vulnerability Manager Workspace.

    On the Lists page, under Libraries, open one of the following for which you want to disable the risk reduction requests:

    • CVE from the CVEs list.
    • TPEs from the TPEs list.
    • Select Disable risk reduction.

    The remediation owner can’t request risk reduction for the host vulnerable items related to this CVE or TPE. In other words, the Request for Risk Reduction check box doesn’t appear when the Reason is selected as Mitigating Control in Place on the Request Exception modal.

  2. To enable the risk reduction requests for host vulnerable items, select Enable risk reduction.

Parent Topic:Add a compensating control to the library

Related topics

Understanding compensating controls for risk reduction

Add a compensating control to the library

Associate compensating controls with CVEs or TPEs for risk reduction requests

Impact of the compensating controls on risk score and expiration date