---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Preparing the Common Security Advisory Framework (CSAF) solution integration

# Preparing the Common Security Advisory Framework (CSAF) solution integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the Setup Assistant to prepare for implementing a solution intelligence integration for all the vendors that support the Common Security Advisory Framework (CSAF) data format.

## Before you begin {#prepare-csaf-solution-integration__section_dsn_4dz_slb}

To integrate with the vendors that provide the solutions, ensure you perform the tasks in the following checklist. You can print the checklist and verify the items listed are completed before you install the application.
{#prepare-csaf-solution-integration__table_qby_jng_tlb__entry__2}

| Task | Description |
|-|-|
| Figure 1. Dependent applications ![Checkbox image.]() | Verify that the following applications are installed from the ServiceNow Store: * Vulnerability Solution Management: For more information about installing Vulnerability Solution Management, see [Install Vulnerability Response third-party applications using Setup Assistant](https://servicenow-prod.fluidtopics.net/4SVUHu2n7I65KBpfqP4EBg "Install the third-party integration applications you have entitlement for in Vulnerability Response using the Setup Assistant.") and [Install the Solution Management for Vulnerability Response application](https://servicenow-prod.fluidtopics.net/y_INCI~k10rb44Ipf472Ew "Before you can use the Solution Management for Vulnerability Response feature of Vulnerability Response in your instance, you must complete the installation of the Vulnerability Solution Management application. This application is available as a separate subscription in the ServiceNow Store."). * Vulnerability Response: For more information about installing and activating the Vulnerability Response application, see [Install Vulnerability Response](https://servicenow-prod.fluidtopics.net/sB5D1~3XOF2DyOX7hmc5dA "Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it."). This integration requires version 16.1 of Vulnerability Response or later. {#prepare-csaf-solution-integration__ul_tz4_lb2_tpb} |
| Figure 2. Third-party account credentials ![Checkbox image.]() | Verify you have any third-party account credentials available. They are required to edit some solution integrations. |
| Figure 3. Vendor authentication ![Checkbox image.]() | Verify that you have authenticated the vendors for import of solutions using the APIs. For more information on how to authenticate vendors, see [Configure Connection and Credential aliases for the Common Security Advisory Framework (CSAF)](https://servicenow-prod.fluidtopics.net/thtQM~xqnO_t_YG2ZYP1Ig "Configure Connection and Credential aliases to authenticate vendors. In advisory parsing, third-party vendors are authenticated."). If you do not want to configure an API-based vendor, you can skip this step. |
| Figure 4. Customization of flow and flow action ![Checkbox image.]() | If you want to configure an API-based vendor other than Red Hat, then you must customize the flow and flow action for extracting a unique key and CSAF URL from the response of an advisory. Note: Publishing CSAF URL is not standard across vendors. To customize the flow for vendors other than Red Hat, see [Configure a Common Security Advisory Framework vendor other than Red Hat](https://servicenow-prod.fluidtopics.net/ge0svDvjKNr2qqw3pGmvyA "Configure a Common Security Advisory Framework (CSAF) vendor other than Red Hat with API support."). You can skip this step if they do not want to configure vendors other than Red Hat. By default, the flow for Red Hat has been shipped with the application. |
| Figure 5. Roles ![Checkbox image.]() | Verify that you have an admin group or user who can manage the integration. If not assigned, the admin assigns the vulnerability admin (sn_vul.vulnerability_admin) and other roles. |
[Table 1. Integration preparation checklist]

{#prepare-csaf-solution-integration__table_qby_jng_tlb}

