Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Remediation task state for Vulnerable Items (VITs) in multiple groups

When a VIT is in multiple remediation tasks, (RT in the following tables), and its own state has not been set, the higher precedence group state determines the state of that VIT, as shown in the following table.

Remediation task stateVulnerable item state
RT 1: Open > Under Investigation RT 2: OpenUnder Investigation When RT 1 is Under Investigation and RT 2 is Open, the VI changes to Under Investigation. After the search, between RT 1 and RT 2, RT 1 has the state with the highest precedence.
RT 1: Under Investigation RT 2: Open > Under InvestigationUnder Investigation When RT 2 is Under Investigation and RT 1 is Under Investigation, the VI stays as Under Investigation. After the search, between RT 1 and RT 2, they have the state with the same precedence.
RT 1: Under Investigation RT 2: Under Investigation > Awaiting ImplementationAwaiting Implementation When RT 2 is Awaiting Implementation and RT 1 is Under Investigation, the VI changes to Awaiting Implementation. After the search, between RT 1 and RT 2, RT 2 has the state with the highest precedence.
RT 1: Under Investigation > Deferred RT 2: Awaiting ImplementationDeferred When RT 1 is Deferred and RT 2 is Awaiting Implementation, the VI changes to Deferred. After the search, between RT 1 and RT 2, RT 1 has the state with the highest precedence.
Remediation task StateVulnerable Item State
RT 1: Under Investigation RT 2: Awaiting Implementation > Closed (Fixed or Cancelled)Under Investigation When RT 2 is Closed/Fixed or Closed/Cancelled, and RT 1 is Under Investigation, the VI changes from Awaiting Implementation (previously the highest precedence) to Under Investigation (currently the highest precedence).
RT 1: any stateRT 2: any stateIf the vulnerable item source status is Fixed \(updated by a scan or import\), then when the group changes its state, the vulnerable item changes its state to Closed/Fixed. This condition is true no matter what states the other associated groups are in. The vulnerable item search for the group state does not occur.

When a VI state is set individually, its state is considered when evaluating precedence, as with any other remediation task. When a VI belongs to more than one remediation task, the following table lists the updates that are made.

Vulnerability item state within a groupVulnerable item final state

RT 1 state: Under Investigation RT 2 state: Under Investigation > Awaiting Implementation

Original VI state: Under Investigation > (set on the VI)

Awaiting Implementation When RT 2 moved to Awaiting Implementation, and RT 1 remained Under Investigation, the VI changes to Awaiting Implementation (the highest precedence).

RT 1: Under Investigation RT 2: Under Investigation > Awaiting Implementation

Original VI state: Deferred > (set on the VI)

Deferred When RT 2 moved to Awaiting Implementation, and RT 1 remained Under Investigation, the VI remains in the Deferred state (the highest precedence).

The following table shows that when two remediation tasks with common vulnerable items are deferred, the state is deferred until the latest date is reached.

Vulnerability item state within a groupVulnerable item final state

RT 1 state: In Review (until April 10) RT 2 state: Under Investigation > In Review (until April 30)

Original VI state: In Review (until April 10) > (set on the VI)

Deferred (until April 30) When RT 2 moved to Deferred (until Apr-30), and RT 1 remains Deferred (until Apr-10), the VI changes from Deferred (until Apr-05) to Deferred state (until Apr-30).

RT 1: In Review (until July 15) RT 2: Under Investigation > In Review (until July 10

Original VI state: Deferred > (until July 15)

Deferred (until July 15) When RT 2 moved to Deferred (until Jul-10), and RT 1 remains Deferred (Jul-15), the VI remains in Deferred (until Jul-15).