---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Data mapping

# Data mapping {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Data Mapping

This document outlines the integration of data from Prisma Cloud into the Configuration Compliance module within ServiceNow, effective from version 14.9.
Key terminology has been updated, enhancing clarity in the data mapping process.
Show full answer Show less  

## Key Features

* **Data Import:** Policies from Prisma Cloud are imported as tests in Configuration Compliance, while alerts are represented as test results.
* **Integration Jobs:** The Prisma Policy Integration and Prisma Alert Integration jobs facilitate data retrieval from Prisma Cloud, with the latter running daily to ensure timely updates.
* **Authoritative Sources:** Configuration Compliance utilizes industry standards like ISO 27001 for generating vulnerability alerts, with authoritative sources accessible via the application.
* **Asset Information:** The Prisma Alerts Integration captures related information, including cloud attributes and resource tags, enhancing visibility into discovered items.
* **CI Lookup Rules:** The base CI lookup rules are available to ensure accurate mapping of resources.

## Key Outcomes

By leveraging this integration, ServiceNow customers can efficiently manage compliance testing and remediation tasks, ensuring that vulnerability alerts align with authoritative standards. The continuous updates from Prisma Cloud help maintain an accurate view of the organization's security posture, enabling informed decision-making and streamlined compliance efforts.  
The data from Prisma Cloud is imported in the Configuration Compliance module of the ServiceNow instance.  
Note:  
Starting with v14.9 of Configuration Compliance, the following terms have been renamed:{#cc-prisma-import-data__entry__2}

| Terminology prior to v14.9 | Terminology v14.9 onwards |
|-|-|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
[Table 1. Changes in terminology]

The data from Prisma Cloud is imported with a different name in Configuration Compliance as mentioned in the table.  
{#cc-prisma-import-data__table_qby_jng_tlb__entry__2}

| Prisma Cloud | Configuration Compliance |
|-|-|
| Policy | Test |
| Alert | Test result |
| Compliance standard | Authoritative source |
| Sections | Citation |
| Asset | Discovery item/ Configuration item (CI) |
[Table 2. Mapping of Prisma Cloud data in Configuration Compliance]

{#cc-prisma-import-data__table_qby_jng_tlb}

## Tests {#cc-prisma-import-data__section_hbf_ptf_fsb}

A policy in Prisma Cloud is imported as a test in Configuration Compliance. Policies are related to authoritative documents and test records, and they can be modified to meet the needs of your organization. You can view the tests by navigating to Configuration ComplianceTests.

If Vulnerability Response Integration with Palo Alto Prisma Cloud is installed, the integration job, Prisma Policy Integration retrieves the tests. You can view this integration job by
navigating to AllPrisma Cloud IntegrationsPrisma Policy Integration.

## Test Results {#cc-prisma-import-data__section_zfx_b1t_kbb}

An alert in Prisma Cloud is imported as a test result in Configuration Compliance. Alerts are remediated using Remediation Tasks. You can view the test results by navigating to Configuration ComplianceTest Results.

The Configuration Compliance imports test results as part of a third-party integration. After they're viewable on the Configuration Compliance application, they are remediated using Remediation Tasks.

If Vulnerability Response Integration with Palo Alto Prisma Cloud is installed, the integration job Prisma Alert Integration retrieves the test results. You can view this integration
job by navigating to AllPrisma Cloud IntegrationIntegrationsPrisma Alert Integration.

The Prisma Alert Integration is an integration job that runs daily and pulls the test results with status change after the time that is defined in the Start Time field in the
Integration tab.  
Note:  
If you run the integration job, Prisma Alert Integration manually, run it after you run the integration job, Prisma Policy Integration.

When the Prisma Alert Integration completes importing the data, an event is started to trigger end-of-import calculations. If the alert fails continuously for the past few days, the integration won't fetch
the alerts as there's no status change for the alert. So, to keep the test results data up to date with the Prisma alerts, a new integration job, Prisma Comprehensive alert Integration is added which pulls
the alerts that are updated in the past seven days. It runs weekly and pulls all the test results, which aren't passed.

## Authoritative Sources {#cc-prisma-import-data__section_isy_nbs_kbb}

Configuration Compliance uses authoritative sources and citations when generating vulnerability alerts for tests. Authoritative sources usually map to sections of published industry standards, such as ISO 27001 and
PCI DSS 3.2.1.

These source records contain references to information about known software and hardware configuration issues from experts in the field of computer security. The references define requirements for security policies and
procedures. Navigate to Configuration ComplianceAuthoritative Sources to view the authoritative sources.

## Assets {#cc-prisma-import-data__section_vqb_nvl_mqb}

If the Vulnerability Response Integration with Palo Alto Prisma Cloud is installed, the scheduled job Prisma Alerts Integration captures the alert related information in the Discovered Items module or table. You can view this
scheduled job by navigating to Prisma Cloud IntegrationIntegrations.  
The Prisma Alerts integration imports additional types of information, such as resource tags and cloud attributes that are stored in tables. This information is displayed in the Discovered items form.  

* Host tags: A resource can have multiple tags. The host tags are available in key value pair format. For example, the operating system is Windows 10 and the Java version is 1.8.
* Cloud attributes for assets: The following cloud attributes are available:
  * Cloud account: Provides the account ID from the integration. The information is populated from the Cloud Accounts \[sn_sec_cmn_cloud_account.LIST\] table.
  * Cloud region: Provides the location where the resource has been hosted. The information is populated from the Cloud Regions \[sn_sec_cmn_region.LIST\] table.
  * Cloud resource type: Provides information on the type of resource such as whether it is a virtual machine or a database instance, and so on. The information is populated from the Cloud Resource Type \[sn_sec_cmn_cloud_resource_type.LIST\] table.
  * Cloud service provider: Provides information on the cloud service provider whether it's Amazon Web Services (AWS), Oracle Cloud, and so on. The information is populated from the Cloud Service Provider \[sn_sec_cmn_cloud_service_provider.LIST\] table.
  * Cloud account groups: Provides information on the account groups. The information is populated from the Cloud Account Groups \[sn_vul_prismacloud_account_group.list\] table.  
    Note:  
    The Cloud account groups attribute is available only for Prisma.
  {#cc-prisma-import-data__ul_vmk_14c_htb}
{#cc-prisma-import-data__ul_mpg_nz2_ktb}

## CI lookup rules {#cc-prisma-import-data__section_cg3_dwv_hvb}

The base system CI lookup rules are available for Resource ID, Name, and S3 Bucket. For more information on the CI lookup rules, see [CI lookup rules for Microsoft Defender for Cloud Integration for Security Operations and Palo Alto Prisma Cloud](https://servicenow-prod.fluidtopics.net/7W7Pa1VyBniZv9Y9HQrDLQ "You can use the configuration item (CI) lookup rules for the Microsoft Defender for Cloud Integration and Palo Alto Prisma Cloud integrations to find a correct match to commonly used resource types in the Configuration Management Database (CMDB).").

*[\>]: and then


