Manual ingestion of vulnerabilities for Application Vulnerability Response
Summarize
Summary of Manual Ingestion of Vulnerabilities for Application Vulnerability Response
The Manual Ingestion of Vulnerabilities feature in ServiceNow allows security professionals and application testers to document penetration test findings within the Penetration Testing Workspace. Users can manually import findings from external sources using templates in Excel or CSV format, ensuring all vulnerabilities are available for management and review.
Show less
Key Features
- Penetration Testing Forms: Accessible within the Penetration Testing Workspace for documenting vulnerabilities.
- File Uploads: Each upload creates a new penetration test form associated with the respective application, consolidating findings under a single entry.
- Mandatory Fields: Key fields, including Application Name, Risk Rating, and others, must be completed in the template to avoid processing errors.
- Template Accessibility: Templates for uploading findings can be accessed via All > Manual AVIT Ingestion > Upload File UI.
Key Outcomes
By following the outlined process, users can effectively manage vulnerabilities identified during application penetration tests, ensuring that all necessary data is accurately captured and processed. Adhering to the mandatory fields in the template will facilitate smooth ingestion of vulnerability findings, enhancing overall security management within the ServiceNow platform.
Security professionals and application testers can create and manage the application penetration test findings within the Penetration Testing Workspace.
The Penetration testing forms are available in the Penetration Testing Workspace to document the vulnerabilities identified in the core business applications.
The security professionals and application testers can manually import findings from external sources and platforms using the provided templates in Excel or CSV format. All the vulnerability findings are made available in the Penetration Testing Workspace.
To access and download the template for uploading to Penetration testing workspace, navigate to .
- Application Table
- Business Application Table
- Scanned Application Table
| Column Name | Mandatory | Description | Available Options/ Max characters in strings |
|---|---|---|---|
| Risk rating | Mandatory | Severity of the application vulnerable item |
Critical High Medium Low None (Default) |
| Requested by | Mandatory | Requested by | 151 |
| CWE category | Mandatory(Fill only one column) | CWE ID | 255 |
| Vulnerability ID | Mandatory(Fill only one column) | Vulnerability ID | 255 |
| Application | Mandatory | Application Name | 255 |
| Purpose of application | Mandatory | Purpose of application | 4000 |
| Types of sensitive data | Mandatory | List types of sensitive data accessible from applications | 40 |
| List of compliance programs | Mandatory | List of compliance programs | 4000 |
| Technology stack details | Mandatory | Technology stack details | 4000 |
| Application team | Mandatory | Application team Name; group responsible for developing and maintaining software applications | 100 |
| URLs to test | Mandatory | URLs to test | 4000 |
| Steps to reproduce | Mandatory | Steps to reproduce | 1000 |
| Technical details | Mandatory | Technical details | 1000 |
| Assigned to | Mandatory | Assigned to (individual responsible for conducting penetration tests and generating security findings) | 151 |
| Assignment group | Mandatory | Assignment group (group responsible for conducting penetration tests and generating security findings) | 151 |