---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response remediation overview

# Vulnerability Response remediation overview {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Vulnerability Response remediation is a phased process consisting of verifying import
completion, triaging new vulnerabilities, and monitoring progress to completion. Approached in
this way, remediation becomes manageable, timely, and in many ways, automated.

Understanding your security posture across company assets helps you identify the most
critical vulnerabilities for remediation. This remediation process requires that Vulnerability Response and a third-party integration such as the Qualys Vulnerability Integration are installed and configured.
Figura 1. Vulnerability Response integration process flow

## Verify the successful completion of third-party integration imports {#cj-common-vuln-tasks__section_kxz_mgw_xcb}

The first phase in this process is to ensure that everything is working correctly. Vulnerability Response is preset to download National Vulnerability Database (NVD) and
Common Enumeration Weakness (CWE) vulnerabilities. Third-party imports provide you with the
data you need to create vulnerable items and remediation tasks. Successful remediation
depends on the consistent and successful import of vulnerabilities and vulnerable items.

During import CI Lookup Rules match third-party assets to assets in the Configuration Management Database (CMDB). All assets are stored in the Discovered Items
module. CI information is critical to solution implementation.  
Nota:  
Once a third-party integration has been installed and configured, there are few instances where an import can fail, for example, if the third-party vendor throttles their API calls. When imports do fail, they require prompt attention.

Integration status run reports for the supported third-party integrations are shipped with
the applications to give you a graphical overview of your imports. Use this report, or
create your own, to easily determine whether your latest import has succeeded. For more
information about supported integrations, see [Vulnerability Response integrations](https://servicenow-prod.fluidtopics.net/zQoHKjiBYFkRQWdwaz7MMw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.").

## Review and triage vulnerabilities and vulnerable items {#cj-common-vuln-tasks__section_yxv_pgw_xcb}

The next phase of remediation calls for the review of new vulnerabilities and vulnerable
items. A vulnerable item (VI) is a detected combination of vulnerability and configuration
item (CI). As vulnerable items are formed, various rules are run that assign VIs, determine
the risk they pose and set remediation targets. Adjust any rules, as necessary, to ensure
that the vulnerable items have been triaged successfully.

## Monitor the progress of existing vulnerability remediation {#cj-common-vuln-tasks__section_qtb_rgw_xcb}

The final phase of remediation consists of monitoring your progress.

* Review the status of imports for patch implementations that have not shown up and follow up with IT Operations.
* Track the progress of regulatory compliance obligations and ensure their completion.
* Review deferred item status and revise or implement fixes.
* Monitor Vulnerability Management dashboards. To review trends, view reports in real-time, and use metrics that track your remediation target attainment rates, you may prefer to monitor your processes with the Performance Analytics for Vulnerability Response application.{#cj-common-vuln-tasks__phContentPackAppName}
* [Closing stale detections in Vulnerability Response](https://servicenow-prod.fluidtopics.net/l9v7x50CQ2QTjcWj8CX30A "The Auto-Close Stale Detections module helps you automatically clean up older, stale vulnerable detections not recently found by your third-party integrations. Moving these detections to Closed reduces the number of active vulnerable items and remediation tasks in your ServiceNow AI Platform instance and helps you reconcile assets in your CMDB.").
{#cj-common-vuln-tasks__ul_txm_bqq_hdb}

