---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Prioritize high-profile vulnerabilities

# Prioritize high-profile vulnerabilities {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

When your network is attacked, typical questions asked include: "how do we determine our
risk exposure?" and more importantly, "how do we determine which systems to address
first?"  
In early 2018, two critical vulnerabilities were unleashed: Meltdown and Spectre. Figura 1. Prioritize high-profile vulnerabilities

Malicious programs can exploit Meltdown and Spectre to get access to secrets stored in the
memory of other running programs. Nearly three billion systems globally were potentially affected
by the vulnerabilities, as both hardware and software providers scrambled to get patches into the
hands of their customers.

## Ranking threats using scanned data in Vulnerability Response {#ensure-high-profile-vulns-are-prioritized__section_mwc_pqg_b3b}

Using the Security Operations
Vulnerability Response application,
numerous methods are available for performing [vulnerability
scans](https://servicenow-prod.fluidtopics.net/qeFxTZZqHSV_~~0WR~Ikew#c_VulnerabilityScans "Qualys vulnerability scans can be performed to find software vulnerabilities that affect your CIs. You can initiate scans from a vulnerable item record or by creating a scan record directly for configuration items (CIs) and IP addresses."). If the Security Incident Response application is
activated, you can also [initiate scans from the security incident catalog, a security incident record, or a security
scan request](https://servicenow-prod.fluidtopics.net/GpTNMeJHEhaezH7sy7Xp~A "You can perform lookups and vulnerability scans from security incidents and from the security incident catalog to identify potential threats and vulnerabilities.").  
Depending on the [third-party integration](https://servicenow-prod.fluidtopics.net/zQoHKjiBYFkRQWdwaz7MMw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") you use, vulnerability data is scanned and imported into the Vulnerability Response application using APIs. It is then matched against your assets in the ServiceNow Configuration Management Database (CMDB). The resulting vulnerable items are assigned a [risk score](https://servicenow-prod.fluidtopics.net/ofSexvZ9IMmHEfeGjQQdMw#c_SecIncCalculators "Security incident calculators are used to update record values when pre-defined conditions are met. The calculators are grouped based on the criteria used to determine how the records are updated.") based on multiple factors, including the severity of the vulnerability and the importance of the affected asset. Figura 2. Risk score  
The risk score is configurable and provides quick prioritization. All information about the vulnerability (for example, what it is, how it was exploited, and how to remediate the threat) is automatically pulled into Vulnerability Response from the National Vulnerability Database (NVD), eliminating the need for manual research. The solution's configurable dashboards instantly show your organization's overall vulnerability exposure.Figura 3. VR Dashboard

## Automating the next steps {#ensure-high-profile-vulns-are-prioritized__section_l5k_vrv_b3b}

After you have identified and prioritized the most critical vulnerable items, Security Operations workflows automate several of the next steps. Figura 4. State encoding workflow For business critical vulnerable items, requests to approve automatic patching are sent and the appropriate owners are notified. This eliminates the need to search for the on-call analyst or manually decide which items count as "critical."

Upon approval and completion of the patch, a second scan is automatically run to verify the
fix. Using prioritization, workflows, and automation, the most critical items are addressed
first.

