---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Understanding the Tenable Vulnerability Integration

# Understanding the Tenable Vulnerability Integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 11 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Understanding the Tenable Vulnerability Integration

The Vulnerability Response Integration with Tenable application enables ServiceNow customers to import and manage vulnerability data from Tenable.io, Tenable.sc, and Tenable.cs products.
This integration helps prioritize and remediate vulnerabilities on your assets by matching imported vulnerabilities to your Configuration Management Database (CMDB) assets.
Show full answer Show less  
This application requires a separate subscription and is available on the ServiceNow Store. It supports multiple Tenable products: Tenable.io (cloud-based), Tenable.sc (on-premises), and Tenable.cs (cloud-based). Depending on your environment, the integration may use a MID Server for communication.

## Key Features

* **Vulnerable Items and Remediation:** Vulnerabilities imported from Tenable products create vulnerable items linked to existing or newly created configuration items (CIs) in your CMDB. Unmatched assets can be reconciled using the Identification and Reconciliation Engine (IRE).
* **Third-Party Vulnerability Entries:** These entries, known as Plugins in Tenable, are imported and matched to your CMDB assets to provide comprehensive vulnerability visibility.
* **CI Lookup Rules:** Automated rules identify and link assets to vulnerabilities by matching host data such as IP addresses, MAC addresses, and DNS names. Different rules exist for Tenable.io, Tenable.sc, and Tenable.cs integrations, facilitating accurate asset reconciliation.
* **Rescan and Remediation Scans:** You can initiate targeted rescans directly from vulnerable item, remediation task, or third-party vulnerability entry records to verify remediation status.
* **Auto-Close Stale Vulnerable Items:** This feature helps maintain data hygiene by automatically closing older vulnerable items not recently detected, reducing active remediation workload.
* **Asset Tags:** Asset tags from Tenable.io can be imported and used to organize and filter assets in your CMDB, aiding in targeted scans and assignment rules. Tags are case-insensitive and controlled by a global system property.
* **Data Retrieval Filters:** You can configure data import scope and filters to control which vulnerabilities and assets are imported into ServiceNow.
* **Vulnerability Priority Rating (VPR):** VPR values imported from Tenable products can be enabled in a dedicated risk calculator to enhance risk scoring of vulnerable items, combining VPR with asset and business criticality factors.
* **Scheduled and On-Demand Jobs:** Asset and vulnerability data imports can be scheduled or run manually as needed to keep your vulnerability data current.

## Roles and Permissions

* **admin:** Responsible for installation and assigning necessary roles via Setup Assistant.
* **snvul.vulnerabilityadmin:** Manages configuration and administration of the integration and Vulnerability Response applications.
* **snvultenable.configureintegration:** Allows configuration of the Tenable integration.
* **snvultenable.readintegration:** Provides read-only access to integration records.
* **Vulnerability Response Group:** Default group with read and remediation ownership roles for users managing vulnerabilities.

## Practical Benefits for ServiceNow Customers

* Centralizes vulnerability data from multiple Tenable products within ServiceNow for comprehensive visibility and management.
* Automates matching of vulnerabilities to CMDB assets, improving accuracy in vulnerability tracking and remediation prioritization.
* Enables targeted rescans and remediation verification directly from the platform, facilitating efficient vulnerability lifecycle management.
* Helps maintain a clean and manageable vulnerability backlog through auto-closing stale items.
* Supports flexible configuration for data imports, asset tagging, and risk scoring to align vulnerability management with organizational priorities.
* Leverages ServiceNow's Setup Assistant for streamlined installation and configuration.

## Next Steps

To deploy this integration, download the Vulnerability Response Integration with Tenable from the ServiceNow Store and follow the Setup Assistant for installation and configuration. Assign appropriate roles to administrators and vulnerability managers to enable full functionality. Configure CI lookup rules, asset tags, and data filters to tailor the integration to your environment and security policies.

Regularly schedule or manually run import jobs to keep vulnerability data up to date and use rescans to validate remediation efforts. Consider enabling the Tenable risk calculator if you want to incorporate VPR into your risk assessments, keeping in mind potential performance impacts.  
The Vulnerability Response Integration with Tenable application developed by ServiceNow engineering for the Tenable Vulnerability Integration uses data imported from the Tenable.io, Tenable.sc, and Tenable.cs products to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow® Store.  
Note:  
Starting with v14.9 of Configuration Compliance, the following terms have been renamed:{#tenableIntegration__entry__2}

| Terminology prior to v14.9 | Terminology v14.9 onwards |
|-|-|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
[Table 1. Changes in terminology]

The Tenable Vulnerability Integration employs three Tenable integrations, Tenable.io, Tenable.sc and Tenable.cs, to import third-party scanner data about your assets and vulnerabilities. The Vulnerability Response Integration with Tenable application supports the Tenable.sc product starting with version 5.13 and Tenable.cs product starting with version 5.0.1.

* Tenable.io is a cloud-based enterprise integration.
* Tenable.sc is an on-premises integration that gives you the option to use a MID Server if the Tenable.sc product and your ServiceNow AI Platform instance are in the same environment.
* If the Tenable.sc product and your ServiceNow AI Platform instance aren't in the same environment, you're required to use a MID Server.
* Tenable.cs is a cloud-based enterprise integration.
{#tenableIntegration__ul_zxz_l1f_qnb}

The Vulnerability Response Integration with Tenable application is available on the ServiceNow Store
with a separate subscription.

For lists and descriptions of the integrations in the Tenable Vulnerability Integration, see [Tenable.io integrations with the Vulnerability Response and Configuration Compliance applications](https://servicenow-prod.fluidtopics.net/6BxlZozybHf0R934pi7S6g "The Tenable.io integrations in the Vulnerability Response Integration with Tenable with Tenable application are available for use with both the Vulnerability Response and Configuration Compliance applications.") and [Tenable.sc integrations with the Vulnerability Response application](https://servicenow-prod.fluidtopics.net/YXAvtyDmWSRP3TusabFNiw "The Tenable.sc integrations in the Vulnerability Response Integration with Tenable application.").
Figure 1. Tenable Vulnerability Integration

## Available versions for Australia {#tenableIntegration__section_fkf_kcx_gnb}

{#tenableIntegration__table_k3h_mcx_gnb__entry__2}

| Release version | Release notes |
|-|-|
| Vulnerability Response Integration with Tenable v3.13.1, v4.1, v5.0.1 | For compatibility information, see [KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes](https://support.servicenow.com/kb_view.do?sysparm_article=KB0856498) |
[ ]

{#tenableIntegration__table_k3h_mcx_gnb}

## Terms and Key features of the integrations {#tenableIntegration__section_gt5_xfv_wmb}

Vulnerable items and vulnerabilities
:   A vulnerable item is created in your ServiceNow AI Platform instance when:

    * An imported vulnerability from a third-party scanner is matched to an existing asset (a configuration item in your CMDB). The Tenable product refers to these matches as vulnerabilities.
    * An imported vulnerability from a third-party scanner isn't matched to an existing asset in your CMDB. In this case, an unmatched CI is also created along with a vulnerable item.

      For unmatched CIs, you can also use the Identification and Reconciliation Engine (IRE)
      to create CIs in two new classes when an existing CI can't be matched with a host. Otherwise, unmatched CIs are created in the Unmatched CI classes. For more information, see [Creating CIs using the Identification and Reconciliation engine](https://servicenow-prod.fluidtopics.net/DbogQZg9imYEow6lfHeXHQ "You can create configuration items (CIs) in the Configuration Management Database (CMDB) using the Identification and Reconciliation engine (IRE) API. By using the IRE API to create CIs, you can prevent duplicate CIs from being created and you can reconcile CI attributes by allowing only authoritative data sources to write to CMDB.").
    {#tenableIntegration__ul_nh4_kr3_3nb}

Third-party vulnerability entries and plugins
:   Third-party vulnerability entries are imported from third-party scanners and listed in the Third-Party Vulnerability Entries table in your ServiceNow AI Platform instance. Starting with v24.0 of Vulnerability Response, the Softwares column in the Third-Party Vulnerability Entries table populates the Common Platform Enumerations (CPEs) associated with a third-party
    entry. Third-party vulnerability entries from Tenable are ingested into Vulnerability Response and matched to existing assets listed in your CMDB. Tenable refers to third-party vulnerability entries as Plugins.

Configuration item (CI)
:   Configuration items are the existing assets listed in your CMDB.

Discovered item
:   Assets ingested from the Tenable asset import are matched to existing configuration items in your CMDB. Imported assets are updated.

    If a match isn't found, a CI is created in the Unmatched CI class of the CMDB. If the CMDB CI Class Models plugin is enabled, the Identification and Reconciliation Engine (IRE) creates CIs using new classes. For more information, see [Creating CIs using the Identification and Reconciliation engine](https://servicenow-prod.fluidtopics.net/DbogQZg9imYEow6lfHeXHQ "You can create configuration items (CIs) in the Configuration Management Database (CMDB) using the Identification and Reconciliation engine (IRE) API. By using the IRE API to create CIs, you can prevent duplicate CIs from being created and you can reconcile CI attributes by allowing only authoritative data sources to write to CMDB."). If the original, unmatched CI is reclassified, discovered item records are updated to reflect the state. Discovered items give you visibility into how assets are identified and
    mapped to CIs in the CMDB.

CI lookup rules
:   When data is imported from a third-party integration, Vulnerability Response automatically uses host (asset) data to search for matches in the Configuration Management Database (CMDB). CI lookup rules are used to identify CIs and add them to VI records when VITs are created to aid you with remediation.

Rescan and remediation scan
:   You can initiate a targeted rescan command on a specific configuration item, remediation task, or third-party entry directly from vulnerable item, remediation task, and third-party vulnerability entry records in your ServiceNow AI Platform instance. Tenable refers to this rescan as a remediation scan.

Automatically close older VIs
:   With the Auto-Close Stale Vulnerable Items module in your ServiceNow AI Platform, you can clean up older, stale vulnerable items (VI)s not recently found by your third-party integrations. Moving these VIs to Closed helps you reduce the number of
    active vulnerable items and remediation tasks and reconcile assets in your CMDB. You can use all the integrations with the Vulnerability Response Integration with Tenable to close stale VIs automatically.

Instance
:   This term refers to a distinct occurrence of your ServiceNow AI Platform®
    application.

Integration
:   An integration is a product-specific reference to an integration, such as the Tenable.io Assets Integration, or the Tenable.sc Plugin Integration.
    These are the separate integrations that belong to specific Tenable products in the Tenable
    Vulnerability Integration in your instance.

Integration instance
:   This term refers to the separate Tenable integrations listed by their Tenable.io and Tenable.sc products.

Deployment
:   When an integration supports multi-source, a single, distinct integration existence is referred to as a deployment of your integration. The term is used to refer to the integration(s) and products across your
    environment. For example, you might have multiple deployments of various integrations of the Tenable.io and Tenable.sc products in your environment.

The Tenable.io, Tenable.sc, and Tenable.cs integrations also include the following key features:

* Configuration assessment findings, that is, test results along with policies, configuration tests (controls), and citations with authoritative sources can be imported into the Configuration Compliance application with the Tenable.io product. See [Tenable.io integrations with the Vulnerability Response and Configuration Compliance applications](https://servicenow-prod.fluidtopics.net/6BxlZozybHf0R934pi7S6g "The Tenable.io integrations in the Vulnerability Response Integration with Tenable with Tenable application are available for use with both the Vulnerability Response and Configuration Compliance applications.") and [Exploring Configuration Compliance](https://servicenow-prod.fluidtopics.net/mcVx8uzRm8~upAeQa8EAwg "Use test results obtained from third-party Secure Configuration Assessment (SCA) integrations to verify compliance with security or corporate policies. Identify, prioritize, and remediate non-compliant configuration items.") for more information about how this integration works with the Configuration Compliance application.
* Starting with v2.1 of the Tenable Vulnerability Integration, create unique configuration items (CIs) that include different network partition identifiers for assets in your environment that share the same IP address. Identify the distinct assets across your environment and update the CIs on your existing discovered item, vulnerable item, and detection records to give you more details about your vulnerabilities.
* You can schedule when you want the jobs to run for all the Tenable.io, Tenable.sc and Tenable.cs integrations. You can also execute scheduled jobs manually on-demand.
* For asset imports with Tenable.io, you can enable asset tags to organize and track the assets listed in your CMDB in the Tenable.io environment.
* The Tenable.io, Tenable.sc and Tenable.cs integrations permit you to configure CI Lookup Rules to define how asset data from third-party sources are used to identify Configuration Items (CIs) in your ServiceNow AI Platform CMDB.
* The Tenable.io, Tenable.sc and Tenable.cs integrations permit you to set import filters on the vulnerabilities import so that you import only the vulnerabilities from Tenable that you want. For Tenable.io, you have the option to import Fixed vulnerabilities from Tenable with the vulnerabilities import.
* For Tenable.sc, you have the option to initiate rescans on-demand directly from a vulnerable item, remediation task, and third-party entry records in your ServiceNow AI Platform instance. If VIs have been transitioned to Closed/Fixed but aren't yet updated in your instance, you can verify vulnerabilities on specific configuration items have been remediated. See [Initiate rescan for the Tenable.sc integration](https://servicenow-prod.fluidtopics.net/P1GL28n_EGCliy9ILS~9Hg "Verify your vulnerable items have been remediated between scheduled scanning cycles by initiating rescans in the Tenable platform. You can initiate a rescan on-demand for vulnerable items for the Tenable.sc product from your ServiceNow AI Platform instance.").

{#tenableIntegration__ul_hs1_f3v_wmb}

The following sections list more details about the Tenable integrations.

## Required ServiceNow AI Platform roles {#tenableIntegration__section_plr_nfg_tlb}

The integration tasks require the following roles in your ServiceNow AI Platform
instance.

admin
:   The system admin uses Setup Assistant to install the Vulnerability Response Integration with Tenable
    application. If not assigned, the admin assigns the vulnerability admin
    (sn_vul.vulnerability_admin) and other roles in Setup Assistant.

sn_vul.vulnerability_admin
:   Once assigned, the vulnerability admin completes the configuration of the Tenable
    integrations in Setup Assistant. This role has complete access to the Vulnerability Response
    (VR) application and its records. The vulnerability admin configures all VR applications and
    rules for installed third-party integrations.

sn_vul_tenable.configure_integration
:   This role contains the sn_vul_tenable.read_integration granular role and users with this
    role can configure the Vulnerability Response Integration with Tenable application.

sn_vul_tenable.read_integration
:   Users with this roles can view (read) but not edit records of the Vulnerability Response Integration with Tenable application.

Vulnerability Response group
:   By default, the Vulnerability Response group is available in Setup Assistant. Users
    assigned to the Vulnerability Response group inherit the sn_vul.read_all and
    sn_vul.remediation_owner roles automatically.

## Vulnerable items {#tenableIntegration__section_xzx_lgj_ppb}

Vulnerable items are grouped into remediation tasks according to remediation task rules and assigned for remediation based on your assignment rules. For more information, see [Vulnerability Response remediation tasks and remediation task rules overview](https://servicenow-prod.fluidtopics.net/a7Z9DVk5024DYfVdfELq8A "Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.") and .

## Configuration item (CI) lookup rules {#tenableIntegration__section_otj_5hz_2mb}

CI Lookup Rules identify CIs and determine when to add them to a vulnerable item. For more information on how CI lookup rules work, see [CI Lookup Rules for identifying configuration items from Configuration Compliance third-party vulnerability integrations](https://servicenow-prod.fluidtopics.net/kNHr72W2lpGyXDtlpjDSQg "When data is imported from a third-party integration, Configuration Compliance automatically uses host data to search for matches in the Configuration Management Database (CMDB). It does this using CI Lookup Rules. These rules are used to identify configuration items (CIs) and add them to the test result record to aid in remediation.").  
Note:  
Rules, once removed, can't be recovered. Rather than removing existing rules, disable them when creating ones.  
The following Tenable.io lookup rules are shipped with the base system.

* MAC_ADDRESS
* FQDN
* NetBIOS
* HostName
* DNS
* IP

{#tenableIntegration__ul_l1g_r3z_2mb}  
Note:  
The Tenable.io CI lookup rules prioritize and populate the non-empty network interface values (FDQN, IPV4, and MacAddress) over the regular FDQN, IPV4, and MacAddress values for a discovered item. When these network interface values are empty, the regular FDQN, IPV4, and MacAddress values are populated for a discovered item.  
The following Tenable.sc lookup rules are shipped with the base system.

* MAC_ADDRESS
* FQDN
* NetBIOS
* IP
{#tenableIntegration__ul_c1s_cjz_2mb}  
Note:  
Multiple values for ip_address, mac_address, fqdns and network_interfaces are used for an asset. All values are considered in CI lookup rules for matching. All values are used to create multiple network adapters using IRE.

The Tenable.cs lookup rule Cloud Resource Id is shipped with the base system.

For more information on how to configure the categorization of unmatched cloud resources into your preferred CI class, see [Updating CI class for unmatched cloud assets](https://servicenow-prod.fluidtopics.net/r84JXzrzNzpRsbVHPyZQBQ "Starting with Vulnerability Response v20.0, you can categorize the unmatched cloud assets from Qualys, Rapid7 and Tenable scanners into Unclassed Hardware by using the sn_sec_cmn.unmatched_cloud_resource_enabled system property.").

## New properties to ignore IP addresses {#tenableIntegration__section_dsz_yxf_4nb}

In Tenable.io, there are two properties available if you want to ignore multiple IP addresses or multiple Mac addresses as part of your CI lookup rules:

ignoreIPAddress
:   A list of IP addresses to be ignored for CI lookup and CI creation.

ignoreMacAddress
:   A list of MAC addresses to be ignored for CI lookup or CI creation.

## Discovered items {#tenableIntegration__section_p24_2jz_2mb}

This module lists configuration items detected during import from the Tenable Vulnerable Item integrations and the Tenable Asset integrations.  
Note:  
The default filter for this list is set to Unmatched. You can view all discovered items from an import by removing the filter.
For more information on the Discovered Items module, see [Discovered Items](https://servicenow-prod.fluidtopics.net/eCeTriYKp1Wkq_Ym33tczQ "Assets are automatically matched to configuration items (CIs) in the Configuration Management Database (CMDB) when they are imported using CI Lookup Rules. Discovered Items give you visibility into how asset identification is mapped to CIs in the CMDB.").

## Asset tags {#tenableIntegration__section_ddd_vjz_2mb}

Asset tags (also referred to as host tags) are used for organizing and tracking the assets in your organization. You can assign tags to your assets. Then, when launching the scans, you can select tags associated with the assets
you want to scan. The Asset Tags module enables you to download asset tag data from Tenable.io to your instance on a scheduled basis. Asset data that includes asset tags is pulled from Tenable.io and transformed using the [Tenable.io Asset Transform](https://servicenow-prod.fluidtopics.net/IXK~qqUrdQEb3cq1cvWPRQ "After you identify the data to import, it’s retrieved from the Tenable product and processed through a set of data sources and transforms in your instance.") integration transformation maps.  
All Asset tags are imported as part of the Tenable.io Asset integration. Asset tags are used for filtering in Vulnerability Response assignment rules and Remediation Task Rules. The tags are displayed in the Discovered Item form.  
Note:  
Run the Tenable.io Asset Integration prior to creating Vulnerability Response assignment rules or remediation task rules in the Vulnerability Response application so that all tags are available for these rules before vulnerable items are imported and grouped. Also note the following points about tags:

* Tag storage isn't case-sensitive. For example, if you create a tag to describe assets in your San Diego location, and you create the <kbd class="ph userinput">San Diego</kbd> tag, you can't also create a <kbd class="ph userinput">SAN DIEGO</kbd> tag and store it in the Asset tag table. <kbd class="ph userinput">San Diego</kbd> and <kbd class="ph userinput">SAN DIEGO</kbd> are considered to be the same asset tag by the system. Whichever tag is imported first is the tag that is stored and recognized going forward.
* Using asset tags as a Group Key in a remediation task rule may have unexpected results. Asset tags are intended for use only in the condition builder.
* Asset tags are controlled by the global system property sn_vul.import_asset_tags. This property is set to true by default. Disabling tags disables them across all ServiceNow AI Platform® instances.
{#tenableIntegration__ul_xfb_pkz_2mb}

## Data retrieval filters {#tenableIntegration__section_lyn_ylz_2mb}

Data retrieval settings help you determine specifically the type and scope of data you want to import from the Tenable application to your ServiceNow AI Platform® instance. For a list of the most commonly used settings, see [Data retrieval settings for the Tenable Vulnerability Integration](https://servicenow-prod.fluidtopics.net/C2PcE1zhAFDx95GhNWDhKA "The following data retrieval settings help you determine specifically the type and scope of data you want to import from the ServiceNow Tenable Vulnerability Integration to your ServiceNow AI Platform instance.").

## Vulnerability Priority Rating (VPR) {#tenableIntegration__section_hbz_mcx_wmb}

The Vulnerability Priority Rating (VPR) is an attribute from the Tenable product that is
imported and used with a new default risk calculator in Vulnerability Response. The Tenable
Risk Rule is installed with the Vulnerability Response Integration with Tenable application as part of the
Default Risk Calculator in the Vulnerability Calculators from Vulnerability Response.

This risk rule is inactive by default.

By enabling the Tenable risk calculator rule, the imported VPR values are used to calculate
the Risk Score for vulnerable items. The default weight distribution for this risk calculator:
VPR = 70%, Asset=15%, and Business Criticality=15%. Enabling this Tenable Risk Calculator rule
may impact your data ingestion performance. For more information about Vulnerability Response
calculators and the Tenable risk calculator rule, see [Vulnerability Response calculators and vulnerability calculator rules](https://servicenow-prod.fluidtopics.net/3Hl03aogPFrru7chhJttaQ "Vulnerability calculators automate calculating initial values for the fields on vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used.").

## Installation and configuration {#tenableIntegration__section_yz3_vdg_4nb}

After you download the Vulnerability Response Integration with Tenable from the ServiceNow® Store, installation and configuration is supported by the Setup
Assistant in Vulnerability Response. See [Configuring Vulnerability Response using the Setup Assistant](https://servicenow-prod.fluidtopics.net/8JZbr3YS3g9s8JFGaKtKpQ "Setup Assistant walks you through setting up Vulnerability Response and certain third-party integrations for your environment. Setup Assistant provides almost everything you need to install and set up your environment so that you can use Vulnerability Response.") for more
information.

