---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure Application Vulnerability Response

# Configure Application Vulnerability Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Do the following setup steps prior to configuration so that you can ensure that your configuration is complete.

## Before you begin

{#configure-avm__table_rv4_tpl_mcb__entry__2}

| Setup tasks | Description |
|-|-|
| Verify that the Vulnerability Response application is installed and activated. | To verify that it's activated, navigate to Subscription ManagementSubscriptions in your instance. The list displays the subscriptions that your organization has purchased. If the application isn't installed and activated, see [Install Vulnerability Response](https://servicenow-prod.fluidtopics.net/sB5D1~3XOF2DyOX7hmc5dA "Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it."). |
| Verify that the Performance Analytics for Vulnerability Response is installed and activated to see Application Vulnerability Response reports. | To verify that it's activated, navigate to Subscription ManagementSubscriptions in your instance. The list displays the subscriptions that your organization has purchased. If the application isn't installed and activated, see [Install and configure the Performance Analytics for Vulnerability Response \[PA\] application](5WivnbLr7vBqT11J8GK_Iw "Before you can use the Performance Analytics for Vulnerability Response application, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and complete a few installation and configuration steps. The PA application is not installed as part of the Vulnerability Response application. It is available as a separate subscription."). |
| Verify that the Veracode Vulnerability Integration is installed, activated, and configured. (Do not run the integrations at this point.) | To verify that it's activated, navigate to Subscription ManagementSubscriptions in your instance. The list displays the subscriptions that your organization has purchased. If the application isn't installed and activated, see [Install the ServiceNow Vulnerability Response Integration with Veracode](https://servicenow-prod.fluidtopics.net/VT7QKPT8AdrIFhShPfi4NA "Before you run the integration on your instance, the installation and configuration steps must be completed so the Veracode product properly integrates with Application Vulnerability Response. This application is available as a separate subscription."). |
| Verify that the CWE 2000 integration is running in Vulnerability Response. | To verify the integration, see [Verify that the scheduled job for updating NVD records is running](https://servicenow-prod.fluidtopics.net/Tvvhqz9xNLYu8X6_uBJJuQ "Identify the repositories that you want updated regularly. You can execute a scheduled job to update National Vulnerability Database (NVD) records on a nightly or weekly basis. If it is not already running, you can enable the job"). |
| \[Optional\] Verify that the NVD integration is running in Vulnerability Response. | To verify, see [Verify that the scheduled job for updating CWE records is running](https://servicenow-prod.fluidtopics.net/EtLxs6tpesm2tQfUmjJHpQ "Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Update common weakness records from the Common Weakness Enumeration database on a regularly scheduled basis. You can also update the default script or write your own scripts, as needed."). |
| Verify that you have the required ServiceNow roles for your instance. | The following roles are required for installation, configuration, and verification of expected results: * If not already assigned, the user with the admin role installs the application and assigns users to the following user groups: App-Sec Manager, Security Champion, and Developer. For information on Group roles, see [Application Vulnerability Response user groups and roles](https://servicenow-prod.fluidtopics.net/pNl52AMjKjWmG3S5Q_qwiA#avm-manage-roles "Before you can successfully remediate vulnerabilities with Application Vulnerability Response (AVR), you must assign users to user groups."). * The App-Sec Manager group oversees configuration and verifies expected results. Note: Application Vulnerability Response configuration isn't available from the Setup Assistant feature in Vulnerability Response. {#configure-avm__ul_wnc_15r_tcb} |
[ ]

{#configure-avm__table_rv4_tpl_mcb}Role required: App-Sec Manager user group

## Procedure

1. Navigate to Security OperationsCMDBLookup Rules.  
   See [Create a CI lookup rule](https://servicenow-prod.fluidtopics.net/cYesQhAYuo9aAtGPm342qA "The CI Lookup Rules module contains rules that define what fields have matching data in the Configuration Management Database (CMDB). These rules are used to identify applications and application releases and add them to the application vulnerable item (AVI) record to aid in remediation.") to create or modify CI Lookup Rules for your environment.
2. Navigate to Application Vulnerability ResponseAdministration.
3. Select Assignment Rules.  
   See [Create or edit Application Vulnerability Response assignment rules](https://servicenow-prod.fluidtopics.net/sPBpBjZmVdFLXJs8VAmDLA "You can create rules to automatically assign application vulnerable items (AVIs) based on filter conditions. These rules assign AVIs as they are imported or manually created.") to create or modify application assignment rules for your environment.
4. Select Vulnerability Calculators.  
   See [Calculate risk in Application Vulnerability Response automatically](https://servicenow-prod.fluidtopics.net/lh8BvObOHho_kLRstHZzcA "Application vulnerability calculators automate calculating initial risk values for the fields on application vulnerable items (AVIs). Risk calculations offer insight into prioritizing remediation. The condition for each calculator is evaluated in order, and the first matching calculator is used.") to create or modify application vulnerability calculators for your environment.
5. Select Remediation Target Rules.  
   See [Create or edit application remediation target rules](https://servicenow-prod.fluidtopics.net/IYz9hdvYvzbfu3qNdJca7Q "Drive the remediation of high-risk vulnerabilities in a timely manner by setting up a remediation target rule at the application vulnerable item (AVI) level.") to create or modify application remediation targets for your environment.
6. Select Normalized Severity Maps.  
   See [Map the severity of an application vulnerable item automatically](https://servicenow-prod.fluidtopics.net/NuRM3JHLq~b8ccyHg3~Bkg "Application Vulnerability Response severity mapping transforms third-party source severity fields to recognizable fields within Vulnerability Response.") to create or modify severity maps for your environment.
7. Navigate to either Veracode Vulnerability IntegrationIntegrations or Fortify Vulnerability IntegrationIntegrations.
8. Open the Veracode Application List Integration or the Fortify On Demand Application List Integration.
9. If it has not already run, select Execute Now.  
   Note:  
   The other Veracode or Fortify integrations are inactive by default.  
   For integration run statuses, see [View the Veracode Application Vulnerability Integration import run status](https://servicenow-prod.fluidtopics.net/CwUV_hryyRUyednNt~T0Ig "Use the Vulnerability Integration Runs related list to verify the success of your integration runs, locate any issues, and inform your remediation decisions.") or [View the Fortify Vulnerability Integration import run status](https://servicenow-prod.fluidtopics.net/Lp4p2YWSiTQSte3Gq1kOGg "Use the Vulnerability Integration Runs related list to verify the success of your integration runs, locate any issues, and inform your remediation decisions.").
10. After the Veracode or Fortify on Demand Application List Integration has completed its run, navigate to Application Vulnerability ResponseAdministrationApplications.
11. For each application, enter a value for Support Group (used by assignment rules) and for Department (used in reporting).  
    To update multiple entries, see [Edit multiple records in a list using the list editor](https://www.servicenow.com/docs/access?context=t_EditMultRecUsingListEditor&version=australia&pubname=australia-platform-user-interface&ft:locale=en-US) to complete the task in bulk.  
    Note:  
    To see the auto-updated Business Unit, refresh the page. For information on Scanned Application form fields, see [Scanned application fields](https://servicenow-prod.fluidtopics.net/UI7zFoB_h12IaguZIlz8ng "Applications are stored during import under Administration > Discovered Applications in Application Vulnerability Response.").
12. Return to the Integrations list, and activate the other Veracode or Fortify integrations.  
    See [Install Application Vulnerability Response Integrations](https://servicenow-prod.fluidtopics.net/_OGFsxTmoXHWVgGLym7dbw "Enable Application Vulnerability Response integrations to perform regular updates.") to set your delta data integration imports.  
    The Veracode and Fortify integrations are chained and will run consecutively when activated.
13. **Optional:** Navigate to Application Vulnerability ResponseAdministrationAssignment Rules.
    1. **Optional:** If you chose Configuration Item: Support group for User group field when creating or editing your assignment rules earlier, the values you added to the Scanned Applications list view are available to use now.  
       Your assignment rules are edited.
    2. Select Update.
    3. From the Vulnerability Assignment Rules list view, select Apply Changes to reapply the assignment rules to your AVIs.
    {#configure-avm__substeps_jl4_xvg_rlb}
{#configure-avm__steps_z5v_pq2_kcb}

## Result

Your Application Vulnerability Response configuration is now complete.

## What to do next

Navigate to Application Vulnerability ResponseOverview and see [Application Vulnerability Management \[PA\] dashboard](IJYWRy2pIB4TSwwazYqZ0Q "Track the volume, performance and progress of application vulnerabilities from initial analysis and detection to containment or remediation.") for information on your overall security posture.
* **[Verify that the scheduled job for updating CWE records is running](https://servicenow-prod.fluidtopics.net/EtLxs6tpesm2tQfUmjJHpQ)**   
  Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Update common weakness records from the Common Weakness Enumeration database on a regularly scheduled basis. You can also update the default script or write your own scripts, as needed.
* **[Verify that the scheduled job for updating NVD records is running](https://servicenow-prod.fluidtopics.net/Tvvhqz9xNLYu8X6_uBJJuQ)**   
  Identify the repositories that you want updated regularly. You can execute a scheduled job to update National Vulnerability Database (NVD) records on a nightly or weekly basis. If it is not already running, you can enable the job
* **[Install Application Vulnerability Response Integrations](https://servicenow-prod.fluidtopics.net/_OGFsxTmoXHWVgGLym7dbw)**   
  Enable Application Vulnerability Response integrations to perform regular updates.
* **[Define Application Vulnerability Response email notifications](https://servicenow-prod.fluidtopics.net/GBZgmdMK0qrH0yakEwSE9Q)**   
  Set up email notifications to share useful information about important updates and activities such as approval and rejection of false-positive requests. Creating an email notification involves specifying when to send it, who receives it, and what it contains.
* **[Exception Management in Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/DIYDRo0pBcmhnb8Zwolarg)**   
  When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to an application vulnerable item (AVIT) that cannot be remediated according to the policy.
* **[Application Vulnerability Response remediation tasks and task rules overview](https://servicenow-prod.fluidtopics.net/04vGngzlHZdIp~Z43var8Q)**   
  Configure remediation tasks (AVULs) to help analysts and remediation specialists organize application vulnerable items (AVI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that AVIs are automatically assigned into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.

*[\>]: and then


