---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure the Fortify Vulnerability Integration

# Configure the Fortify Vulnerability Integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Before you run the integration on your instance, the installation and configuration
steps must be completed so the Fortify product properly integrates with the
Application Vulnerability Response feature of Vulnerability Response. This
application is available as a separate subscription.

## Before you begin

Roles required: App-Sec Manager

Complete the following setup checklist prior to installation. These setup tasks are
required for a smooth installation and configuration.  
Note:  
This process applies only to applications that are downloaded to production instances. If you're downloading applications to non-production or development instances, it's not necessary to get entitlements. Proceed to [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances.").
{#configure-fortify__table_rv4_tpl_mcb__entry__2}

| Setup tasks | Description |
|-|-|
| Verify that the Vulnerability Response application is installed and activated. | To verify that this application is activated, navigate to Subscription ManagementSubscriptions in your instance. The list displays the subscriptions your organization has purchased. If the application is not installed and activated see, [Install Vulnerability Response](https://servicenow-prod.fluidtopics.net/sB5D1~3XOF2DyOX7hmc5dA "Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it."). |
| Verify that the Vulnerability Response Integration with Fortify application is installed and activated. | To verify that this application is activated, navigate to Subscription ManagementSubscriptions in your instance. The list displays the subscriptions your organization has purchased. If the application is not installed and activated see, [Install the ServiceNow Vulnerability Response Integration with Fortify](https://servicenow-prod.fluidtopics.net/ysgm1ZZXGSsYT1_K~nS5Xg "Before you run the integration on your instance, the installation and configuration steps must be completed so the Fortify product properly integrates with Application Vulnerability Response. This application is available as a separate subscription."). |
| Verify that you have the required ServiceNow roles for your instance. | The following roles are required for installation, configuration, and verification of expected results: * If not already assigned, the System Administrator \[admin\] installs the app and assigns users to the App-Sec Manager group. * The App-Sec Manager oversees configuration and verifies expected results. {#configure-fortify__ul_wnc_15r_tcb} |
| For the Fortify Vulnerability Integration, have your API id and API key ready. | Contact Fortify to obtain the API id and API key. |
[ ]

{#configure-fortify__table_rv4_tpl_mcb}

## Procedure

1. Log in to the instance you want to install the Fortify application vulnerability integrations on.
2. Navigate to the ServiceNow Store.
3. In the ServiceNow Store, search for the Vulnerability Response integration with Fortify application.
4. Click the application tile.  
   Detailed information about the application you are installing is displayed.  
   Note:  
   Consider reading the Other Requirements and Dependencies sections, as applicable.
5. Click Request App and enter your Now Support login credentials.
6. Click Get.
7. Enter the Instance Name and Reason for the Instance, and click Validate Instance.
8. Click Request.  
   You will receive an email with detailed installation instructions.
9. Navigate to System ApplicationsApplications.
10. Locate the application, select it, and click Install.  
    Your application is automatically installed on your instance.
11. Once the installation completes, navigate to Fortify Vulnerability IntegrationFoD Configuration.
12. On the form, fill in the fields.  
    {#configure-fortify__table_ghy_33p_ssb__entry__2}

    | Field | Description |
    |-|-|
    | API root URL | User's Fortify instance URL. |
    | API key | Unique identifier sent to the Fortify API. |
    | API secret | Client secret provided by Fortify. |
    | Include DAST | Option to include vulnerabilities from DAST scans. DAST scans identify vulnerabilities in the behavior of your overall application. |
    | Include SAST | Option to include vulnerabilities from SAST scans. SAST scans identify vulnerabilities in the code. |
    | Triaging exceptions and false positives in ServiceNow (starting with v20.0 of Vulnerability Response) | Select options to manage Exception management and False positive for AVIs with ServiceNow workflows automatically upon import. These options are activated by default. For an example use case, see [Managing state mapping for deferrals and false positives in Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/SrYl5PiJ0fjjplMCQxr8JQ "You can manage how the Source states on application vulnerable items (AVIs) imported by the Veracode Vulnerability Integration and Fortify Vulnerability Integration are mapped in your instance after import."). Manage exceptions in ServiceNow :   Leave this option activated if you want to triage imported AVIs marked for the Deferred state. AVIs with Source states that normally are mapped to a Deferred state in your instance are instead mapped to Open. You Request an exception from the AVI record. Manage false positives in ServiceNow :   Leave this option activated if you want to triage imported AVIs with Source states marked as False Positive or Potential False Positive. AVIs with these Source states that normally are mapped to a Closed state in your instance are mapped to Open. You request a False positive from the AVI record. * Deactivate one or both check boxes if you want to preserve the Source states imported from your scanner. * These AVIs are mapped to the Target states and Target reason states as they are imported but are not triaged by the exception and false positive workflows. The Request exception and False Positive actions are not visible on AVIs. {#configure-fortify__ul_fnm_4kt_dzb} |
    | Triaging in ServiceNow (prior to v20.0 of Vulnerability Response) | Manage your application vulnerability triaging in ServiceNow instance: * Select the check box to triage the AVIs within ServiceNow. If this option is selected, AVIs are imported in Open state. You can then request an exception or mark the AVI as a false positive. * To retain the source state, that is, the state imported from the scanner, ensure that the check box is not selected. {#configure-fortify__ul_uqk_5jp_ssb} Note: The Mark as False Positive and Request Exception options are available only for AVIs being triaged within ServiceNow. |
    [Table 1. Fortify on Demand configuration form]

    {#configure-fortify__table_ghy_33p_ssb}
13. Select Save and Test Credentials.
{#configure-fortify__steps_z5v_pq2_kcb}

## What to do next

If your environment requires domain-separated imports, see [Create domain-separated imports for an integration](https://servicenow-prod.fluidtopics.net/0N9JZHv_nZJYrkMbQYSBbQ "If you require imported data to be in a specific domain, the user assigned to run the integrations must belong to that domain.").

On initial installation, see [Configure Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/e9rJ2bGEEt9l2GSgAmOQKA "Do the following setup steps prior to configuration so that you can ensure that your configuration is complete.") for further instructions.

After initial installation, for modifications refer to [Fortify Vulnerability Integration modification and activities](https://servicenow-prod.fluidtopics.net/RPzZ2S~QBT4IZkNu1rnnSQ "Configure optional modifications specifically for the Fortify Vulnerability Integration.").

*[\>]: and then


