---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Implementation checklist for the Vulnerability Response application

# Implementation checklist for the Vulnerability Response application {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

This checklist lists the steps required for a basic implementation of the Vulnerability Response application on your ServiceNow AI Platform® instance. When
you have completed these tasks, the base system is ready for operation and verification.

## Before you begin

Roles required: admin for downloading and activating applications and assigning
roles, sn_vul.vulnerability_admin for configuring Vulnerability Response.

## Procedure

1. Consider creating and printing a PDF of this checklist so that you can check off tasks as you complete them.
2. To generate a PDF, click the Save As PDF icon (![Save as PDF icon]()) at the top of the topic and click Selected topic.  
   {#vr-implement-chklist__table_tvq_qvw_nhb__entry__2}

   | Item | Description |
   |-|-|
   | ![Checkbox]() | As a user with the admin role, verify that you have the obtained any entitlements and downloaded (Install) the following applications from the ServiceNow® Store onto your ServiceNow AI Platform instance: * Vulnerability Response * Vulnerability Response Integration with the NIST National Vulnerability Database * Qualys Integration for Security Operations {#vr-implement-chklist__ul_wqs_yv2_5vb} 1. To verify the applications are available on your instance, navigate to AllSystem ApplicationsAll Available ApplicationsAll and search for \[sn_vul\], \[sn_vul_nvd\], and \[sn_vul_qualys\]. 2. If you can't locate the applications, see [Security Operations and the ServiceNow Store](https://servicenow-prod.fluidtopics.net/jBa~11BcDnkn~s9DxBYDkw "Starting with Madrid, all Security Operations applications and supported integrations are available for download from the ServiceNow Store. This allows you to obtain new and updated features more rapidly. Before you can use any Security Operations applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them), download them from the ServiceNow Store, and activate them.") for more information about getting entitlement and downloading the applications. {#vr-implement-chklist__ol_s3w_qyz_c3b} |
   | ![Checkbox]() | As a user with the admin role, navigate AllVulnerability ResponseAdministrationSetup AssistantIntegration Application Installation and activate (Install) the Vulnerability Response application along with its dependencies on your ServiceNow AI Platform instance. Note: During installation of the Vulnerability Response application, you have the option to install demo data. Demo data is required if you want to run automated tests to confirm that your instance works after installation. Run tests only on development, test, and other non-production instances to avoid data corruption and outage. If demo data or demo accounts are created, all demo data should be removed prior to using the instance in non-production or production. The Setup Assistant for Vulnerability Response is installed automatically along with the application. The Setup Assistant is required to configure the Vulnerability Response application. Additionally, it is used to install and configure the Qualys Integration for Security Operations application used in this example, as well as other applications that support and are compatible with Vulnerability Response. For more information about installing the Vulnerability Response application, see [Install Vulnerability Response](https://servicenow-prod.fluidtopics.net/sB5D1~3XOF2DyOX7hmc5dA "Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it."). |
   | ![Checkbox]() | As a user with the admin role, in Setup Assistant, navigate to AllVulnerability Response Users and Groups and assign users with the required Vulnerability Response persona roles. 1. From within Setup Assistant, view existing users and any roles that are already assigned by clicking the User Administration module link. 2. From the list, click a user name to open the record and click the Roles related list. All the roles assigned to this user are displayed. 3. Navigate back to Vulnerability Response Users and Groups in Setup Assistant and follow the prompts to assign the sn_vul.vulnerability_admin role. {#vr-implement-chklist__ul_ogs_4pz_yhb} Note: The sn_vul.vulnerability_admin role is required to continue with the configuration. Alternatively, you can continue with the configuration as a user with the admin role. (Optional) You can also assign the Configuration Item (CI) Manager \[sn_vul.ci_manager\] and Exception Approver \[sn_vul.exception_approver\] roles, but these personas are not required for the remaining setup tasks. For more information about assigning the persona roles using the Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://servicenow-prod.fluidtopics.net/msi8kaFkGNjyRib_XBHEzQ "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant."). For more information on users and assigning roles to users and groups, see [User administration](https://www.servicenow.com/docs/access?context=c_UserAdministration&version=australia&pubname=australia-platform-administration&ft:locale=en-US). |
   | ![Checkbox]() | 1. Navigate to AllAdministrationIntegrations and verify the CWE Comprehensive 2000 Integration is activated and run the scheduled job to import data. 2. As a user with the admin role, navigate to System ApplicationsAll Available Applications and activate (Install) the Vulnerability Response Integration with NVD application. {#vr-implement-chklist__ol_hq3_ry2_5vb} Run the NVD and CWE integrations as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product. See [Importing data with the NVD and CWE integrations and managing third-party libraries](https://servicenow-prod.fluidtopics.net/SDp7vDWErXHrLtUOsZ_~qw "If not already installed, download and run the NVD integration and run the CWE scheduled job as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product. The Vulnerability Response Integration with NVD is available on the ServiceNow Store.") and [Configure and run the scheduled job for updating CWE records](https://servicenow-prod.fluidtopics.net/eW08j7C7hKeJNiT7jgbPMg "Data imports from the CWE further enrich the vulnerability data in your instance. Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.") for more information about installing, configuring, and viewing the NVD and CWE libraries. |
   | ![Checkbox]() | As a user with the admin role, navigate AllVulnerability ResponseAdministrationSetup AssistantIntegration Application Installation and activate the Qualys Integration for Security Operations application. Before you install and run a third-party scanner product like Qualys that has a library, you must first install and run the NVD and CWE Integrations to ingest vulnerability data. For more information, see [Install Vulnerability Response third-party applications using Setup Assistant](https://servicenow-prod.fluidtopics.net/4SVUHu2n7I65KBpfqP4EBg "Install the third-party integration applications you have entitlement for in Vulnerability Response using the Setup Assistant."). |
   | ![Checkbox]() | (Optional) As a user with the admin role, if you installed demo data with the Vulnerability Response application, you can run the Vulnerability Response ATF Test Suite to verify the applications successfully installed. Note: Run tests only on development, test, and other non-production instances to avoid data corruption and outage. For more information, see [Run the Automated Test Framework (ATF) test suite for Vulnerability Response](https://servicenow-prod.fluidtopics.net/CSdV~HPQNrMH3FpGtcPi3w "Run the Automated Test Framework (ATF) test suite after you install or upgrade the Vulnerability Response application."). For more information about automated tests, see [Automated Test Framework (ATF)](https://www.servicenow.com/docs/access?context=automated-test-framework&version=australia&pubname=australia-application-development&ft:locale=en-US). |
   [Table 1. Vulnerability Response basic implementation checklist tasks for admin]

   {#vr-implement-chklist__table_tvq_qvw_nhb}
3. Continue with the configuration of the applications starting in the Vulnerability Response Settings section.  
   Reviewing these settings helps you understand how Vulnerability Response
   works as you continue to set up your environment. For the scanner
   integration used in this example, you are required to edit the settings.

   The concepts you use in this configuration example for the Qualys product apply to other scanner applications.

   Your Qualys credentials are required to configure the
   application. Verify you have any account names, passwords, and other service
   information required by Qualys products so that you have
   access to them.

   Roles required: sn_vul.vulnerability_admin or, alternatively, admin.  
   {#vr-implement-chklist__table_qby_jng_tlb__entry__2}

   | Task | Description |
   |-|-|
   | ![Checkbox]() | Review the Vulnerability Assignment Rules. Assignment rules automatically assign vulnerable items (VIs) to the appropriate assignment group. For more information, see, . For more information about configuring Vulnerability Response using the Setup Assistant, see [Configuring Vulnerability Response using the Setup Assistant](https://servicenow-prod.fluidtopics.net/8JZbr3YS3g9s8JFGaKtKpQ "Setup Assistant walks you through setting up Vulnerability Response and certain third-party integrations for your environment. Setup Assistant provides almost everything you need to install and set up your environment so that you can use Vulnerability Response."). |
   | ![Checkbox]() | Review the remediation task rules. Remediation task rules automatically group vulnerable items (VIs) as they are imported based on certain conditions. For more information, see [Vulnerability Response remediation tasks and remediation task rules overview](https://servicenow-prod.fluidtopics.net/a7Z9DVk5024DYfVdfELq8A "Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently."). |
   | ![Checkbox]() | Review the Risk Calculators. Risk calculators score vulnerable items for prioritization. You can configure calculators to incorporate characteristics of the configuration item (CI), exploit availability, and vulnerability severity reported by your vulnerability assessment (scanner) vendor. For more information, see [Vulnerability Response calculators and vulnerability calculator rules](https://servicenow-prod.fluidtopics.net/3Hl03aogPFrru7chhJttaQ "Vulnerability calculators automate calculating initial values for the fields on vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used."). |
   | ![Checkbox]() | Review the Remediation Target Rules. Remediation Target Rules define remediation time lines for VIs and remediation tasks. For more information, see [Vulnerability Response remediation target rules](https://servicenow-prod.fluidtopics.net/Rk0nNjDmu1fZ7GxcJJ20Jg "Remediation target rules define the expected time frame for remediating vulnerable items (VI), much like SLAs provide a time frame for remediating the vulnerability itself. For example, if an asset contains PCI data (credit card data) then the vulnerability on that item must be fixed within 30 days according to PCI DSS."). |
   | ![Checkbox]() | In the Integration Configuration section, review the Qualys application settings and define and schedule your data imports. 1. Click Scanner Integrations. 2. On the Installed Applications page, click Edit. 3. Enter your credentials and click Next. 4. Read the descriptions for the KnowledgeBase Configuration. 5. Review the Host Detection Configuration page for Import Settings, CI Lookup Rules, and Import Schedules. 6. After you are satisfied with the settings on this page, click Execute Now to import data. Click the View details link that is displayed to view vulnerability integration run status. 7. (Optional) Continue to edit configuration settings. 8. Click Finish to complete the installation and configuration in Setup Assistant. {#vr-implement-chklist__ol_hh3_lpj_wnb} For more information about configuring the Qualys application, see [Configure the Qualys Vulnerability Integration using Setup Assistant](https://servicenow-prod.fluidtopics.net/1mnmgPggLnXLaG1d~OZ8CQ "After you have installed the Qualys application, configure it using the Setup Assistant."). |
   [Table 2. Vulnerability Response basic implementation checklist tasks for vulnerability admin]

   {#vr-implement-chklist__table_qby_jng_tlb}
{#vr-implement-chklist__steps_qct_pw3_vvb}

## What to do next

Congratulations! You successfully installed the Vulnerability Response application and configured it and a scanner application using the Setup Assistant. The base system is now ready for operation.

To download, install,
and configure other applications for Vulnerability Response, follow the same steps
and concepts you completed for the preceding checklist. Refer to specific topics
provided for each application for more information.

For more information about
supported applications available that are available to you from the ServiceNow Store for Vulnerability Response, see [Installation of Vulnerability Response and supported applications](https://servicenow-prod.fluidtopics.net/GzpmA3jC6SarZ6vCvXGm4g "The Vulnerability Response application is available from the ServiceNow Store. The application supports other ServiceNow applications and third-party integrations that you also download from the ServiceNow Store. More options also are available to extend the basic setup.").

For more information about how to
use Vulnerability Response, see [Exploring the Vulnerability Response application](https://servicenow-prod.fluidtopics.net/i~5sS5NUEapcBcvBJRVFfg "The ServiceNow Vulnerability Response application imports and automatically groups vulnerable items according to rules that permit you to remediate vulnerabilities quickly. Vulnerability data is pulled from external sources, such as the National Vulnerability Database (NVD) and third-party integrations, and processed with applications developed by ServiceNow.").

*[\>]: and then


