---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Application Vulnerability Management (PA) dashboard

# Application Vulnerability Management (PA) dashboard {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Application Vulnerability Management (PA) Dashboard

The Application Vulnerability Management (PA) dashboard enables organizations to track and manage application vulnerabilities from detection to remediation.
It provides insights into the volume and performance of application vulnerable items (AVIs) to aid vulnerability managers in prioritizing remediation efforts effectively.
Key performance indicators (KPIs) focus on critical applications and high-visibility vulnerabilities, helping organizations mitigate risks efficiently.
Show full answer Show less  

## Key Features

* **User Dashboard:** Accessible to users in Security Champion, App-Sec Manager, or Developer roles, allowing them to view and analyze AVIs.
* **Dashboard Tabs:** Includes tabs such as Security Posture, Exceptions, Remediation Trend, and Scoreboard to visualize different aspects of vulnerabilities.
* **Scan Type Filters:** Users can filter data based on manual or dynamic scans to tailor insights relevant to their needs.
* **Data Visualization:** The dashboard presents various visualizations like pie charts, heatmaps, and scorecards to illustrate AVIs by risk rating, age, and remediation progress.

## Key Outcomes

Customers can expect to:

* Identify and prioritize critical vulnerabilities effectively, improving overall security posture.
* Monitor remediation actions and assess their effectiveness through detailed trends and KPIs.
* Customize views and metrics to focus on specific applications or business units, aiding targeted remediation strategies.
* Access insights into overdue vulnerabilities and make informed decisions on risk management.  
Track the volume, performance and progress of application vulnerabilities from initial analysis and detection to containment or remediation.

## Use cases {#app-vuln-mgmnt-dashboard__section_n2w_k4q_3qb}

{#app-vuln-mgmnt-dashboard__table_o2w_k4q_3qb__entry__2}

| User | Dashboard use |
|-|-|
| Vulnerability managers | With the Application Vulnerability Management dashboard, vulnerability management can determine which application vulnerable items (AVIs) present the most risk to their organizations. These dashboards provide a graphical view into AVI activity to help them determine remediation plans and status progress. Focus on the KPIs associated with critical affected applications and high-visibility vulnerabilities. |
[ ]

{#app-vuln-mgmnt-dashboard__table_o2w_k4q_3qb}

## Required ServiceNow AI Platform roles, setup, and the dashboard tabs {#app-vuln-mgmnt-dashboard__section_y5f_qcf_jpb}

The Application Vulnerability Management (PA) dashboard is included as a part of the Performance Analytics for Vulnerability Response content pack. The Performance Analytics for Vulnerability Response content pack is not
automatically installed with the Vulnerability Response application. It is available on the ServiceNow® Store as a separate subscription.

For more information about setting up, installing, and configuring your Performance Analytics for Vulnerability Response application, see [Install and configure the Performance Analytics for Vulnerability Response \[PA\] application](5WivnbLr7vBqT11J8GK_Iw "Before you can use the Performance Analytics for Vulnerability Response application, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and complete a few installation and configuration steps. The PA application is not installed as part of the Vulnerability Response application. It is available as a separate subscription.").

To view the dashboard, as a user assigned to Security Champion, App-Sec Manager, or Developer user groups, navigate to Application Vulnerability ResponseOverview.  
Note:  
The My Application Vulnerabilities dashboard is a subset of the Overview dashboard and only available when a member of the Security Champion user group logs into an instance. For information on the My Application Vulnerabilities dashboard, see [My Application Vulnerabilities dashboard](https://servicenow-prod.fluidtopics.net/7eBeuK4Pb6Vv4TvjkF0KQA "This dashboard presents important metrics for analyzing your Application Vulnerability Management process, such as viewing remediation target attainment rates.").

Starting with version 19.0 of Application Vulnerability Response, this dashboard can also be viewed in the New Experience UI. To view the dashboard in the new UI, navigate to WorkspacesVulnerability Manager Workspace and click theDashboards icon. Depending on your role, the default dashboard is displayed. To view other dashboards, click the drop-down next to the dashboard name. For more information, see [Dashboards page in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/2xZMBwx48zDozvbNZJgOtQ "On the Dashboards page of the Vulnerability Manager Workspace, you can view the dashboards in the Next Experience UI and use these dashboards to track and analyze the vulnerabilities.") and [Dashboards page in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/D8mVjNkutVKLD1vlxpTJaA "The Dashboards page in the IT Remediation Workspace provides the Vulnerability Remediation dashboard in the Next Experience UI which can be used to focus on the remediation tasks and vulnerable items.").

The Overview dashboard communicates KPIs for vulnerability risk and prevalence, affected applications, remediation trends, and remediation progress. The default for trends is three months but can be changed to 7 day, one month,
3 months, 6 months, YTD, 1 year, or All.

Breakdown the data in the Application Vulnerability Management dashboard by Scan Type, Application or Business unit. Each of these choices has an additional filter,
Select elements, to refine your selections. Starting from Application Vulnerability Response v15.0, business and CI applications have been added to the choices for the Application filter.
Figure 1. Security Posture tab

The Security Posture tab helps you understand your security posture and the progress of your remediation actions.  
Starting from Application Vulnerability Response v15.0, you can view the penetration test findings reports. Penetration test findings are Application Vulnerable Items (AVIs) that are manually created based on the penetration test assessment requests.  
Note:  
The Scan Type for these widgets is Manual.
Figure 1. Security posture tab for the AVM Dashboard Figure 3. Exceptions tab

This dashboard helps you understand where your organization is taking risk due to potentially excessive deferrals and reconsider remediation options.

You can view Deferred Application Vulnerable items by Reason, Expiring Deferral Requests for AVIs, Exceptions for Critical Application Vulnerable Items by Assignment Group, AVI Exception Requests by Requester.
Figure 4. Remediation Trend tab

The Remediation Trend tab helps you understand the progress of your remediation actions.
Figure 5. Scoreboard tab

The Scoreboard tab helps you understand the progress of your remediation actions, and which AVIs need the most assistance with their completion.  
Scan Type elements:

* Dynamic: Use only metrics from dynamic data import
* Static: Use only metrics from static data import
{#app-vuln-mgmnt-dashboard__ul_a1q_ghq_dpb}

You can choose either or both.

## Indicators {#app-vuln-mgmnt-dashboard__section_cvf_qcf_jpb}

Mean time to remediate Low AVIs
:   \[\[Summed Duration of Closed Application Vulnerable Items \> Risk Rating = 4 - Low\]\] / \[\[Closed Application Vulnerable Items \> Risk Rating = 4 - Low\]\]. Goal is to minimize.

Application Releases
:   It is the count distinct on applications from AVI.Active, which is using the table: sn_vul_app_vulnerable_item. Goal is to minimize.

Application Vulnerable Items
:   It is the count on app vul items AVI.Active, which is using the table: sn_vul_app_vulnerable_item. Goal is to minimize.

Average AVIs per application
:   \[Active Application Vulnerable Items\]\] / \[\[Application Releases\]\]. Goal is to minimize.

Unassigned VIs
:   It is the count on indicator source AVI.Active, which is using the table: sn_vul_app_vulnerable_item. Goal is to minimize.

Mean time to remediate AVIs
:   \[\[Summed Duration of Closed Application Vulnerable Items\]\] / \[\[Closed Application Vulnerable Items\]\]. Goal is to minimize.

Mean time to remediate High AVIs
:   \[\[Summed Duration of Closed Application Vulnerable Items \> Risk Rating = 2 - High\]\] / \[\[Closed Application Vulnerable Items \> Risk Rating = 2 - High\]\]. Goal is to minimize.

Closed Application Vulnerable Items
:   It is the count on indicator source AVI.Closed, which is using the table: sn_vul_app_vulnerable_item. Goal is to maximize.

Mean time to remediate Critical AVIs
:   \[\[Summed Duration of Closed Application Vulnerable Items \> Risk Rating = 1 - Critical\]\] / \[\[Closed Application Vulnerable Items \> Risk Rating = 1 - Critical\]\]. Goal is to
    minimize.

New Application Vulnerable Items
:   It is the count on indicator source AVI.New, which is using the table: sn_vul_app_vulnerable_item. Goal is to minimize.

Mean time to remediate Medium AVIs
:   \[\[Summed Duration of Closed Application Vulnerable Items \> Risk Rating = 3 - Medium\]\] / \[\[Closed Application Vulnerable Items \> Risk Rating = 3 - Medium\]\]. Goal is to minimize.

Net change in VIs
:   \[\[New Application Vulnerable Items\]\] - \[\[Closed Application Vulnerable Items\]\]. Goal is to minimize.

Summed Duration of Closed Application Vulnerable Items
:   It is the count on indicator source AVI.Closed, which is using the table: sn_vul_app_vulnerable_item. Goal is to minimize.

Critical Overdue Application Vulnerable Items
:   It is the count on data source AVI.Active, which is using the table: sn_vul_app_vulnerable_item. Goal is to minimize.

Critical Application Vulnerable Items
:   It is the count on indicator source Applications with active AVIs, which is using the table: sn_vul_analytics_app_ci_dept_bu. Goal is to minimize.

## Breakdowns {#app-vuln-mgmnt-dashboard__section_dvf_qcf_jpb}

* Age
* Age Closed
* Application
* Business Unit
* Risk Rating
* Scan Type
{#app-vuln-mgmnt-dashboard__ul_qg5_4xd_jpb}  
Note:  
Customizing the Age and Age closed calculation for application vulnerable items (AVIs) may lead to a sharp rise or drop in the Performance Analytics (PA) reports that include these metrics. For more information on how to customize the calculation of Age and Age closed for AVIs, see the [KB1703270](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1703270) KB article.

## Data visualizations {#app-vuln-mgmnt-dashboard__section_fvf_qcf_jpb}

{#app-vuln-mgmnt-dashboard__table_mp5_kff_jpb__entry__3}

| Name | Type | Description |
|-|-|-|
| V15.0: Penetration Test Findings in Validation Pending State | Pie Chart ![Pie chart icon]() | Penetration test findings in Resolved state, but with validation pending, grouped by risk rating. |
| V15.0: Overdue Penetration Test Findings | Pie Chart ![Pie chart icon]() | Critical penetration test findings that have missed their remediation target date, grouped by risk rating. |
| Active Application Vulnerable Items (AVIs) | Single Score ![Single-score icon]() | Number of active (non-closed) application vulnerable items (AVIs). |
| Unassigned Application Vulnerable Items (AVIs) | Single Score ![Single-score icon]() | Number of active application vulnerable items (AVIs) without an assignment group. |
| Application Vulnerable Item (AVI) Distribution | Pie Chart ![Pie chart icon]() | Distribution of all active application vulnerable items (AVIs) grouped by risk rating. |
| Application Vulnerable Items (AVIs) by Age | Heatmap ![Heatmap icon]() | Number of active application vulnerable items (AVIs) grouped by risk rating and age (in days). Note: Customizing the Age and Age closed calculation for application vulnerable items (AVIs) may lead to a sharp rise or drop in the Performance Analytics (PA) reports that include these metrics. For more information on how to customize the calculation of Age and Age closed for AVIs, see the [KB1703270](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1703270) KB article. |
| AVI trends | Trend ![Bar icon]() | Trend of active application vulnerable items (AVIs) grouped by risk rating. |
| Average AVIs per application | Trend ![Bar icon]() | Trend of average application vulnerable items (AVIs) per application, grouped by risk rating. |
[Table 1. Security Posture]

{#app-vuln-mgmnt-dashboard__table_mp5_kff_jpb}  
{#app-vuln-mgmnt-dashboard__table_tp5_kff_jpb__entry__3}

| Name | Type | Description |
|-|-|-|
| Mean time to Remediate Application Vulnerable Items (AVIs) | Line ![Line icon]() | Trend of the average remediation time for application vulnerable items (AVIs) by risk rating. |
| Net change of AVIs | Trend ![Bar icon]() ![Line icon]() | Trend of new application vulnerable items (AVIs) detected vs closed by month. |
[Table 2. Remediation Trend]

{#app-vuln-mgmnt-dashboard__table_tp5_kff_jpb}  
{#app-vuln-mgmnt-dashboard__table_xp5_kff_jpb__entry__3}

| Name | Type | Description |
|-|-|-|
| Top 10 Applications with Most Critical Application Vulnerable Items (AVIs) | Score card and Distribution Bar ![Scorecard icon]() ![Distribution bar icon]() | Applications with most number of critical application vulnerable items (AVIs). |
| Top 10 Applications with Most Overdue Critical Application Vulnerable Items (AVIs) | Score card and Distribution Bar ![Scorecard icon]() ![Distribution bar icon]() | Applications with the most number of active application vulnerable items (AVIs) that are past their remediation target dates. |
[Table 3. Scoreboard]

{#app-vuln-mgmnt-dashboard__table_xp5_kff_jpb}

*[\>]: and then


