---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exploring Fix Intelligence for SEM

# Exploring Fix Intelligence for Security Exposure Management {#ariaid-title1}

* Release version: Australia
* 
* Updated July 29, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Fix Intelligence for Security Exposure Management

Fix Intelligence for Security Exposure Management (SEM) enhances Unified Security Exposure Management (USEM) by providing a de-duplicated catalog of remediation actions (Fix records).
Each fix links to multiple findings and assets it resolves, accompanied by a risk score that quantifies the exposure reduction.
This approach allows vulnerability teams to prioritize and manage remediation efforts by fix rather than individual findings, streamlining vulnerability management across the enterprise.
Show full answer Show less  

## Key Features

* **De-duplicated Fix Catalog:** Each unique remediation action is stored once, regardless of how many scanners or detections report it. Fix records include remediation categories (e.g., Patch Update, OS Update, Configuration Change), affected software, and aggregate risk scores.
* **Finding and Asset Linkage:** Fixes link directly to the vulnerable items they resolve, with findings maintaining a read-only reference to their corresponding fix.
* **Per-Fix Risk Rollup:** A risk rollup calculator aggregates risk scores from all active findings linked to a fix, also counting affected findings and distinct assets to aid impact assessment.
* **Automated Integration with Armis Centrix™ for ViPR:** USEM automatically exports detection data to Armis Centrix™ for Vulnerability Prioritization and Remediation (ViPR) and imports identified fixes on a schedule, ensuring the fix catalog stays current without manual effort.
* **Workspace and Dashboard Visibility:** Fixes are accessible as lists and forms within USEM Workspace and displayed as widgets on Findings and Remediation Views, enabling users to quickly identify top fixes by finding count and prioritize remediation.
* **Supported Integrations:** Fix Intelligence currently supports host vulnerability data from Qualys, Rapid7, Tenable.io, Wiz, and Microsoft Defender Vulnerability Management.

## Key Outcomes

* **Efficient Remediation:** Enables remediation by fix instead of individual findings, reducing redundant efforts since one fix may resolve multiple findings across many assets.
* **Risk-Based Prioritization:** The per-fix risk rollup helps teams focus on fixes that mitigate the highest risk, improving exposure reduction effectiveness.
* **Continuous Currency:** Automated synchronization with Armis Centrix™ for ViPR ensures that fix data is always up to date, minimizing manual maintenance.
* **Role-Specific Utility:** Vulnerability analysts can identify and act on the highest-impact fixes; vulnerability managers can coordinate remediation across assets and teams; remediation owners can track assigned fixes and related findings.

## Practical Use for ServiceNow Customers

ServiceNow customers using USEM with Fix Intelligence for SEM can transform large volumes of vulnerability findings into actionable, prioritized remediation plans. By consolidating fixes across multiple scanners and assets, teams can streamline workflows, reduce duplication, and improve remediation effectiveness through risk-focused decisions. The integration with Armis Centrix™ for ViPR automates fix identification and updates, enabling customers to maintain an accurate and actionable fix catalog without extra administrative overhead. This functionality supports coordinated vulnerability management across roles and teams within the ServiceNow platform.  
Fix Intelligence for Security Exposure Management enriches USEM with a de-duplicated catalog of remediation actions,
each linked to the findings and assets it resolves and scored by the risk it removes.

Vulnerability teams often work finding by finding, even when a single patch or configuration change resolves many findings across many assets. Fix Intelligence for Security Exposure Management identifies fix information for your detections and turns it
into Fix records. These records group findings under the action that resolves them, so you can plan and prioritize remediation by fix.

Vulnerability detections that USEM ingests from your scanners are processed by Armis Centrix™ for Vulnerability Prioritization and Remediation (ViPR), which identifies and normalizes a fix for each
detection. Because fixes are normalized and de-duplicated, a single Fix record can represent the
same remediation action across many detections, assets, and scanners.

## Supported integrations {#exploring-fix-intel__section_supported-integrations}

In this release, Fix Intelligence for SEM identifies fixes for host vulnerabilities (host vulnerable
items) ingested from the following integrations:

* Qualys
* Rapid7
* Tenable.io
* Wiz
* Microsoft Defender Vulnerability Management

## Features {#exploring-fix-intel__section_features}

De-duplicated fix catalog
:   Each remediation action is stored once as a Fix record, no matter how many detections or scanners report it, with its
    remediation category (for example, Patch Update, OS Update, or Configuration Change), affected software, and a rolled-up risk score.

Finding and asset linkage
:   Every fix is linked to the vulnerable items it resolves, and each finding carries a
    read-only reference back to its fix.

Per-fix risk rollup
:   A rollup calculator scores each fix from the active findings that share it, and maintains a findings
    count and a distinct-assets count so you can size the impact of applying the fix.

Automated exchange with Armis Centrix™ for ViPR
:   USEM exports detection data to Armis Centrix™ for ViPR and retrieves the identified fixes on a
    schedule, keeping the catalog current without manual imports.

Workspace and dashboard visibility
:   Fixes appear as a list and form in Unified Security Exposure Management Workspace, and as widgets on the Findings View and the Remediation View --- for example,
    Findings with fix identified and Top fixes by finding count.

## Who uses Fix Intelligence for SEM {#exploring-fix-intel__section_who-uses-it}

{#exploring-fix-intel__table_fix_intel_users__entry__2}

| User | Goal |
|-|-|
| Vulnerability analyst | Find the fixes that resolve the most findings and highest risk, then act on them first. |
| Vulnerability manager | See which assets a fix covers, and coordinate the patch or configuration change across the assigned remediation teams. |
| Remediation Owner | Navigate to the fix list and see other findings if they are assigned to them. |
[Table 1. Fix Intelligence for SEM users and goals]

{#exploring-fix-intel__table_fix_intel_users}

## Benefits {#exploring-fix-intel__section_benefits}

* Remediate by fix, not by finding: One fix can clear many findings across many assets, reducing repetitive work.
* Prioritize by risk removed: The per-fix risk rollup surfaces the fixes that reduce the most exposure.
* Stay current automatically: Scheduled exchanges keep the fix catalog aligned with Armis Centrix™ for ViPR.

## What next {#exploring-fix-intel__section_what-next}

* [How Fix Intelligence for Security Exposure Management works](https://servicenow-prod.fluidtopics.net/uaJ97XaydsRJIMvCxabcVg "Fix Intelligence for Security Exposure Management enriches your host findings with normalized fix information and stores each unique fix as a Fix record. The feature links every fix to the findings it resolves and rolls up a risk score per fix. Your team can remediate by fix instead of one finding at a time.")

* [Install Fix Intelligence for Security Exposure Management](https://servicenow-prod.fluidtopics.net/xX~VQsjG03tQHddeyEsOhA "Activate the Fix Intelligence for Security Exposure Management plugin (sn_vul_fix) to add the Fix tables, role, and integration to your USEM environment.")

* **[How Fix Intelligence for Security Exposure Management works](https://servicenow-prod.fluidtopics.net/uaJ97XaydsRJIMvCxabcVg)**   
  Fix Intelligence for Security Exposure Management enriches your host findings with normalized fix information and stores each unique fix as a Fix record. The feature links every fix to the findings it resolves and rolls up a risk score per fix. Your team can remediate by fix instead of one finding at a time.

**Related concepts**   

* [Exploring Unified Security Exposure Management (USEM)](https://servicenow-prod.fluidtopics.net/nh8euOf2Nld2H7safP9Z~A "Unified Security Exposure Management (USEM) is a platform that brings together infrastructure, application, container, and configuration exposures into one unified experience.")

