---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Integrate with other applications

# Configuration Compliance integrations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Third-party integrations import configuration assessment findings, policies, tests, technologies, authoritative sources, test results along with other vulnerability data into the Configuration Compliance application.  
Note:  
Starting with v14.9 of Configuration Compliance, the following terms have been renamed:{#vuln-config-compl-integrations__entry__2}

| Terminology prior to v14.9 | Terminology v14.9 onwards |
|-|-|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
[Table 1. Changes in terminology]

The Configuration Compliance application supports the following third-party integrations:

* Starting with v14.11, drive remediation for security gaps in your enterprise assets identified by the Security Posture Control application by publishing findings as test results in the Configuration Compliance application. The Security Posture Control application and its supported applications are available with separate subscriptions from the ServiceNow® Store. See [Security Posture Control](https://servicenow-prod.fluidtopics.net/W5AAIQAtM~aFACI5JIjOgw "Gain visibility into your enterprise asset inventory and security tool coverage. Use policies provided with the product or create your own to identify assets missing key security tools, such as endpoint protection, configuration management, and vulnerability scanning. Monitor assets for security tool configurations specific to your environment and automate the remediation workflow for security gaps in the Configuration Compliance application.") for more information.
* [Understanding the Microsoft Defender for Cloud integrations for Security Exposure Management](https://servicenow-prod.fluidtopics.net/jU7BeWoduINzGBT6eWdW8A "The Microsoft Defender for Cloud integrations included with the Microsoft Defender Integration for Security Exposure Management application import cloud misconfiguration findings, compliance data, and container image vulnerabilities.")
* [Palo Alto Prisma Cloud Vulnerability Integration](https://servicenow-prod.fluidtopics.net/feo76oCpZ9k2a_r4hRZS4Q "The Prisma Cloud Compute integration enables you to scan container images to detect vulnerabilities.")
* [Qualys integration with Configuration Compliance](https://servicenow-prod.fluidtopics.net/bUb_bXtlfalvZI2LbIyoeA "The Qualys Policy Compliance collects the data and automatically sends it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates as the Qualys Integration for Security Operations to map configuration findings to CIs and business services to determine the impact and priority of potential misconfigurations.")
* The Tenable.io product of the [Tenable Vulnerability Integration](https://servicenow-prod.fluidtopics.net/LBEiVzZ9snj0he1KfeiBpw "The Vulnerability Response Integration with Tenable application developed by ServiceNow engineering for the Tenable Vulnerability Integration uses data imported from the Tenable.io, Tenable.sc, and Tenable.cs products to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.")

{#vuln-config-compl-integrations__ul_mp5_gwf_s5b}

## Additional notes for integrations {#vuln-config-compl-integrations__section_aw5_cnz_wvb}

During integration execution, multiple processes are generated, and data is received in the form of pages. Each process can contain one or more import queue entries with attached data in pages. These entries must process the data within the one-hour time limit. However, if the payload size is large, the processing time may exceed one hour or get stuck, resulting in an integration timeout error. The integration continues to process the data despite the timeout error. To avoid this miscommunication, starting from version 14.8.5 of Configuration Compliance, timestamps (heartbeats) are sent periodically to indicate if the queue is active and processing data. The Last Record Processed field in the Import Queue Entry page is updated based on the count of records the import queue creates or updates. In case an import queue entry exceeds the one-hour time limit, the system checks the Last Record Processed field to see if it is also older than one hour. If it is, this indicates that the import queue entry is stuck, and it is timed out to prevent any further delays in processing.  
Note:  
The Last Record Processed field is updated based on what is defined in the following system properties:

* sn_sec_cmn.record_threshold_heartbeat: Defines the number of processed records, after which the heartbeat (timestamp) is sent to the import queue entry.
* sn_sec_cmn.maximum_heartbeat_delay: Defines the time after which the import queue entry must be timed out.
{#vuln-config-compl-integrations__ul_g23_sgw_dyb}

