---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Patch orchestration with Vulnerability Response

# Patch orchestration with Vulnerability Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Patch orchestration with Vulnerability Response

Patch orchestration with Vulnerability Response enables ServiceNow customers to manage patch deployment for critical vulnerabilities across large asset groups efficiently.
It leverages data imported from third-party patch vendors, scanners, and integrations, correlating this information within the Vulnerability Response application.
This integrated approach supports the full vulnerability remediation lifecycle---from identifying vulnerabilities to applying patches and closing them---directly within the ServiceNow AI Platform® instance.
Show full answer Show less  
This capability is available in both the classic environment and Vulnerability Response workspaces, allowing vulnerability managers, analysts, and IT remediation specialists to coordinate remediation tasks, monitor patch deployment progress, and ensure timely vulnerability resolution.

## Key Features

* **Data Integration and Correlation:** Combines vulnerability and patch data from third-party scanners and patch vendors (including Windows, CentOS, macOS, Oracle) to provide comprehensive visibility.
* **Patch Scheduling and Deployment:** Supports scheduling patches during off-hours to minimize disruption and allows initiating patches directly from Vulnerability Response records such as Patch Update, Remediation Task, and Discovered Item.
* **Monitoring and Approval:** Enables monitoring of patch deployment status with an optional approval workflow to control patch scheduling and avoid conflicts with business hours.
* **Role-Based Access:** Utilizes specific roles like snvulpatchorch.readpatch, snvul.remediationowner, and snvuln.vulnerabilityanalyst to control viewing and scheduling capabilities, with integration-specific roles required for configuration.
* **Bulk Editing:** Allows bulk editing of vulnerable items with preferred patches in the classic environment to streamline remediation tasks.
* **Patch Management Data Model:** Introduces a standalone plugin encapsulating key patch management tables (e.g., Collection, Patch Update, Patch Deployment) to support enhanced data ingestion and integration with ITSM and Vulnerability Response workflows.

## Practical Application for ServiceNow Customers

ServiceNow customers can expect to:

* Streamline vulnerability remediation by orchestrating patch deployment across multiple asset types and vendors within a unified platform.
* Improve visibility and control over patch status and remediation progress using both the classic environment and the Vulnerability Response workspaces.
* Leverage scheduled patch deployments with optional approval workflows to minimize business disruption.
* Integrate with supported third-party patch vendors such as HCL BigFix and Microsoft SCCM seamlessly, with defined roles ensuring secure and appropriate access.
* Utilize the Patch Management Data Model plugin to enhance data organization and support extended workflows across ITSM and security operations.

## Next Steps

* Configure integrations with supported third-party patch vendors and scanners according to your environment and roles.
* Manage and schedule patches directly from Vulnerability Response records to maintain up-to-date remediation efforts.
* Consider enabling or disabling the patch approval process based on your organization's operational needs.
* Explore bulk editing capabilities to efficiently assign patches across multiple vulnerabilities.
* Implement the Patch Management Data Model plugin to optimize patch data management and workflow integration.  
You can manage patches and patch deployments for critical vulnerabilities for large
groups of your assets with Patch orchestration with Vulnerability Response. Vulnerability Response Patch Orchestration and the patch orchestration integrations are
available on the ServiceNow® Store.

## Understanding patch orchestration with Vulnerability Response {#patch-orch-legacy-overview__section_xfk_lxc_rsb}

Patch orchestration with Vulnerability Response uses data from scheduled imports from
third-party solution integrations, patch vendors, and vulnerability scanners. This data is
correlated in the Vulnerability Response application. This organization of data permits
you to complete the steps of the vulnerability remediation cycle. Start with identifying
vulnerabilities, then apply patches and updates, and finally close vulnerable items using
third-party scanner data all from within your ServiceNow AI Platform® instance.

Patch orchestration with Vulnerability Response is supported in both the classic environment and
the Vulnerability Response workspaces.

For information about patch orchestration in the workspaces, see [Patch orchestration with the Vulnerability Response Workspaces](https://servicenow-prod.fluidtopics.net/qhYi4lIn5cGt2G5ombcCNw "You can manage patches and patch deployments for critical vulnerabilities for large groups of your assets with Patch orchestration with Vulnerability Response.").  
With patch orchestration in Vulnerability Response, vulnerability managers and analysts and IT remediation specialists can perform the following remediation tasks:

* See more context and information about the types of patches and vendors that make up their solutions (patches).
* View and monitor vulnerability and solution data, as well as vulnerability remediation progress from records in the Vulnerability Response Workspaces or in the classic environment.
* Deploy patches supported by third-party solution vendors for their Windows, CentOS, macOS, Oracle, and other assets at regular, scheduled intervals. You can schedule patches during off-hours to avoid conflicts with those at work.
* Using imported detection data provided by third-party scanners, identify assets that have vulnerabilities and are not patched or are not successfully updated by scheduled patches.
* Initiate and schedule available patches for assets that require updates from Patch Update, remediation task, and discovered item records in the Vulnerability Response application.
* Monitor patch deployments with an optional approval process for patch requests submitted by your remediation specialists.
{#patch-orch-legacy-overview__ul_agk_vyc_rsb}

## Key terms {#patch-orch-legacy-overview__section_nn1_2zc_rsb}

Configuration item (CI)
:   CIs are the existing assets that are listed in your Configuration Management
    Database (CMDB).

Vulnerable item (VI)
:   An imported vulnerability that matches an existing asset in your CMDB. Vulnerable
    items (VITs) are grouped into remediation tasks, or lists, according to certain
    criteria that specify remediation actions for VIs.

Instance
:   Refers to a distinct account of a solution vendor application. For example, each
    user account can be an instance in the HCL BigFix application. This term also refers
    to a unique, secure web address for a ServiceNow AI Platform® instance.

Solution
:   There are two types of solutions in the context of this integration, potential and
    preferred. A potential solution is one that might address a vulnerability.
    Vulnerabilities often have many potential solutions.  A preferred solution matches the
    most effective solution for a specific, detected vulnerability.

Patch
:   Software updates that fix vulnerabilities. Patch vendors use their own names for
    patches, for example, In the HCL BigFix application, patches are called, Fixlets.

Preferred patch
:   Preferred patches are software updates that are intended to fix specific
    vulnerabilities. Patches, once deployed, map to the vulnerable items that are related
    to specific vulnerabilities and fix them.

Deployment

:   Deployment for the purposes of this integration refers to when you apply, initiate, or schedule a patch to a machine. Deployment in the ServiceNow AI Platform can
    also refer to an integration that supports multi-source. A single integration
    existence is referred to as a deployment of your integration. A deployment refers to
    the integrations and products across your environment. For example, you might have
    multiple deployments of a third-party scanner or a solution vendor integration in
    your environment.

## Available versions of applications and dependencies required for the patch
orchestration integration {#patch-orch-legacy-overview__section_wpp_mf1_tsb}

* [The Vulnerability Response](https://servicenow-prod.fluidtopics.net/i~5sS5NUEapcBcvBJRVFfg "The ServiceNow Vulnerability Response application imports and automatically groups vulnerable items according to rules that permit you to remediate vulnerabilities quickly. Vulnerability data is pulled from external sources, such as the National Vulnerability Database (NVD) and third-party integrations, and processed with applications developed by ServiceNow.") application and the dependency plugins, Security Support Common and Security Support Orchestration.
* [Vulnerability Solution Management](https://servicenow-prod.fluidtopics.net/4~jL5ap2RRdZ3gYosfm3rg "Vulnerability Solution Management automates the correlation of vulnerabilities in your environment with the solutions that can remediate them. It identifies the patches, configuration updates, and controls with the highest impact for your organization, eliminating the need for manual research.").
* Vulnerability Response Patch Orchestration application available in the ServiceNow® Store.
* A supported third-party patch vendor application, such as [The
  Vulnerability Response patch orchestration integration with HCL BigFix](https://servicenow-prod.fluidtopics.net/h73nSOqPqd59_wefnz5Itg "You can manage patches and patch deployments for critical vulnerabilities for large groups of assets with the Vulnerability Response patch orchestration integration with the HCL BigFix product.") or the [The Vulnerability Response patch orchestration integration with Microsoft
  SCCM](https://servicenow-prod.fluidtopics.net/PZV21C07W_aS_du2IqIsmA "The Vulnerability Response integration with the Microsoft System Center Configuration Manager (SCCM) supports patch management and deployment for critical vulnerabilities across your assets.").
* [Supported third-party scanner integrations with
  Vulnerability Response.](https://servicenow-prod.fluidtopics.net/5tRtjEBZLs~2Uym3WljEBw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.")
{#patch-orch-legacy-overview__ul_mrq_cww_wsb}

## Roles required {#patch-orch-legacy-overview__section_orz_kby_rsb}

Users need roles that are specific to the patch orchestration integration you are using to
view data and schedule patches from the Vulnerability Response application. See the
configuration information for the supported integrations you are using listed below for more
information.

* [Understanding the HCL BigFix patch orchestration integration with Vulnerability Response](https://servicenow-prod.fluidtopics.net/h73nSOqPqd59_wefnz5Itg "You can manage patches and patch deployments for critical vulnerabilities for large groups of assets with the Vulnerability Response patch orchestration integration with the HCL BigFix product.") and [The Vulnerability Response patch orchestration integration with Microsoft
  SCCM](https://servicenow-prod.fluidtopics.net/PZV21C07W_aS_du2IqIsmA "The Vulnerability Response integration with the Microsoft System Center Configuration Manager (SCCM) supports patch management and deployment for critical vulnerabilities across your assets.").
* In the Vulnerability Response workspaces and the classic environment, the sn_vul_patch_orch.read_patch role, which permits users to view but not edit data, is inherited with the sn_vul.remediation_owner and sn_vuln.vulnerability_analyst roles.

  The roles you need to assign that are required to configure the connections to the
  patch vendors and schedule patches are integration-specific. See [Configure the Vulnerability Response patch orchestration integration with HCL BigFix](https://servicenow-prod.fluidtopics.net/EIfWPYbhd1ZSKfY1PLUw7g "After you have installed the application, configure it with your BigFix account information and validate your credentials.") and [Configure the Vulnerability Response Patch Orchestration with MS SCCM for more
  information](https://servicenow-prod.fluidtopics.net/rxJBu_NcDqoGzXuLrMlJRw "Configure the Microsoft SCCM Patch Orchestration integration with your account credentials to enable data ingestion and patch deployment.").

{#patch-orch-legacy-overview__ul_czq_hvq_psb}

There is a submission and approval process for patch requests included with the
applications. By default, a system property is activated
\[sn_vul_patch_orch.patch_approval_required\] in the Vulnerability
Response Patch Orchestration application in your ServiceNow AI Platform instance.

This system property is activated so that when patch deployments are scheduled, they are
submitted for review and approval to users assigned to the Level 1 - Patch update approval
group. If you want users with the sn_vul_patch_orch.configure_patch role to schedule patches
without approval, you can deactivate the
\[sn_vul_patch_orch.patch_approval_required\] property. You might
prefer to leave approvals activated so that scheduled patches do not conflict with normal
working hours. If you deactivate the approval system property, any user with the
sn_vul_patch_orch.configure_patch role can schedule and deploy patches without review and
approval.

For more information, and how to deactivate this system property, see the configuration
topic for your supported integration.

* [Configure the Vulnerability Response patch orchestration integration with HCL BigFix](https://servicenow-prod.fluidtopics.net/EIfWPYbhd1ZSKfY1PLUw7g "After you have installed the application, configure it with your BigFix account information and validate your credentials.").
* [Configure Microsoft SCCM Patch Orchestration](https://servicenow-prod.fluidtopics.net/rxJBu_NcDqoGzXuLrMlJRw "Configure the Microsoft SCCM Patch Orchestration integration with your account credentials to enable data ingestion and patch deployment.").
{#patch-orch-legacy-overview__ul_qpk_wzt_ssb}

## Schedule patches from Vulnerability Response records {#patch-orch-legacy-overview__section_pkj_vmx_rsb}

Remediation specialists can schedule patch updates to resolve vulnerable items and monitor
remediation progress all from records in the Vulnerability Response application.

You can schedule patches from the following records:

* Patch Update
* Remediation task
* Discovered item
{#patch-orch-legacy-overview__ul_lms_dby_rsb}

## Records that roll up active VI counts in Vulnerability Response {#patch-orch-legacy-overview__section_yc5_tlj_rsb}

To avoid potential performance issues with rolling up all the patches to all the
vulnerabilities, the scheduled job that picks up changes only modifies the active VI count.
These count changes and related data are rolled up to the following records in the Vulnerability Response application:

* VIT (vulnerable item)
* RT (remediation task)
* Vulnerability solution
* Patch Update

{#patch-orch-legacy-overview__ul_nrx_vlj_rsb}

For more information about viewing patch data and patch data roll up to records, and
viewing patches without solutions, see the following topics.

* [Patch data and state rollup for patch orchestration in Vulnerability Response](https://servicenow-prod.fluidtopics.net/aHV5JfQdovyUrcgpYUJ39w "Starting with v16.1 of Vulnerability Response patch data and states are rolled up to Patch Update and other records in the Vulnerability Response application.").
* [Viewing patch data and scheduling patches in Vulnerability Response](https://servicenow-prod.fluidtopics.net/emRVWJ81uLy7YevK1SuPrg "Starting with v16.1 of Vulnerability Response, you can schedule patches and view patch data along with solution and other vulnerability information on records in both the classic environment and the Vulnerability Response Workspaces in your ServiceNow AI Platform instance.").
* [View patches without solutions in Vulnerability Response](https://servicenow-prod.fluidtopics.net/hr4XKhmE3zraJ1QgDndJfg "Starting with v16.0 of Vulnerability Response, for patches that have no solutions after an import, the system then searches for patch IDs in the vulnerability reference data so that you can view these patches on vulnerability records.").
{#patch-orch-legacy-overview__ul_a4r_2hp_rsb}

## Bulk edit vulnerable items with patches {#patch-orch-legacy-overview__section_kqz_smy_rsb}

You can bulk edit vulnerable items in the classic environment that have patches from the classic environment.
For more information about how bulk editing works, see [Edit vulnerable items in bulk in Vulnerability Response](https://servicenow-prod.fluidtopics.net/k4YNXsPtp1Z6nk4jFFUjxw "Edit vulnerable items in bulk to save time by selecting fields and running an asynchronous bulk edit job in the background."). The preferred patches for all the VIs selected for
bulk edit. This option for edit only works if there are preferred patches mapped to all the
VIs selected.

## Patch Management Data Model Enhancements {#patch-orch-legacy-overview__section_ztc_35x_bfc}

The Patch Management Data Model plugin --- a standalone, free plugin that encapsulates the data model currently used in the VR Patch Orchestration application. This includes key tables such as Collection, Patch Update, Patch
Deployment, and others.

This plugin can be used by patch management tools to ingest the Patch Management data to be used by applications such as ITSM, Vulnerability Response and so on for the existing workflows.  
Key Enhancements:

* Tables such as, collection device, patch update, patch deployment tables in the existing patch orchestration plugin will be moved to the new data model plugin.
* The data from the old table will be migrated to the new tables for the existing VR patch orchestration feature.
{#patch-orch-legacy-overview__ul_tng_q5x_bfc}

