Triage vulnerabilities automatically
Summarize
Summary of Triage vulnerabilities automatically
The automated triage of vulnerabilities in ServiceNow Vulnerability Response streamlines the remediation process by transforming imported vulnerabilities into actionable remediation tasks. This includes assigning vulnerable items (VIs), calculating risk, setting remediation targets, and grouping VIs. The process ensures assets not found in the CMDB are reconciled, vulnerabilities prioritized, remediation activities assigned, and remediation confirmed through validation scans.
Show less
Key Features
- Automated Vulnerable Item Assignment: Vulnerabilities are assigned to remediation tasks based on predefined rules, though manual intervention may be necessary for ungrouped or unmatched items.
- Risk Score Revision: Customers can adjust risk scores of vulnerable items within remediation tasks using vulnerability calculators and rules.
- Remediation Target Rules: These rules, created during initial setup, determine remediation targets and run upon vulnerability import to guide remediation efforts.
- Ungrouped Vulnerable Items Handling: Customers can review and manually group ungrouped VIs or revise group rules and perform rescans to improve grouping accuracy.
- Automatic Closure of Older Vulnerable Items: Items not recently detected can be closed automatically to maintain focus on current vulnerabilities.
- Change Request Integration: Remediation tasks can be linked to change requests assigned to IT operations for resolution. If Security Incident Response is enabled, security incidents can be created from remediation tasks.
Practical Steps for Customers
- Log in to the Vulnerability Response instance and validate your CI Lookup and Assignment rules to ensure correct vulnerable item assignment.
- Verify remediation target rules to confirm they align with your remediation strategy.
- Review ungrouped vulnerable items and revise group rules or manually group items as needed.
- Adjust risk scores for vulnerable items to reflect current risk assessments.
- Close older vulnerabilities not detected recently by integrations to reduce noise.
- Research and prioritize remediation activities based on risk, affected systems, and patching schedules.
- Create and assign change requests for remediation tasks, moving tasks to an 'Under Investigation' state after submission.
Why It Matters
This automated triage process helps ServiceNow customers efficiently manage and remediate vulnerabilities by reducing manual effort, improving prioritization, and ensuring that remediation tasks are clearly defined and assigned. It supports maintaining a secure IT environment by integrating vulnerability data with change and security incident management workflows.
Reviewing and triaging new vulnerabilities is necessary to ensure successful remediation. Transform vulnerability imports into remediation tasks with automated vulnerable item (VI) assignment, risk calculation, remediation targets, and VI grouping.
Starting with imported vulnerabilities, reconcile the assets not found in the CMDB, prioritize the results, translate that to remediation activities that are automatically assigned, orchestrate the remediation process, and confirm completion with a validation scan.
New vulnerable items are usually sorted into remediation tasks upon import, based on remediation tasks rules. Sometimes, vulnerable items cannot be grouped or do not contain a recognized configuration item.
- Log in to your Vulnerability Response instance.
- Validate that your rules (CI Lookup, Assignment) for vulnerable item are working as expected. For information on Assignment rules,
see .Note:Due to the large volume in data imports, care should be taken with automated vulnerable item assignment.
- Validate that your remediation targets are correct. See Vulnerability Response remediation target rules for information on how remediation target rules work and how to revise them.
- View ungrouped vulnerable
items.
- Looking at the ungrouped vulnerable items, consider revising your group rules and performing a rescan. See Create or edit Vulnerability Response remediation task rules for more information.
- Manually group the vulnerable items. Manually create a remediation task in Vulnerability Response for more information.
- Revise risk scores for the vulnerable items in your remediation tasks. See Vulnerability Response calculators and vulnerability calculator rules for more information.
- Close older vulnerable items not recently detected by your third-party integrations. See Automatic closing of vulnerable items and detections for more information.
- View and reclassify unmatched configuration items.
- Research what needs to be done for remediation.
This step can include:
- Determine what to deal with now and what you can defer. This determination is often
based on risk score, affected systems, and patches with change
windows.Note:Remediation target rules belong to vulnerable items. These rules are run when the vulnerable item is imported. These rules were created previously in the Setup Assistant.
- Refresh vulnerable items, if necessary, and View the remediation target status of a Vulnerability Response vulnerable item.
- Create a Change Request and assign the remediation task to an
assignment group (IT Operations) for remediation.Note:If the vulnerability constitutes a security incident and the Security Incident Response plugin (com.snc.security_incident) is activated, you can create security incident records from the remediation tasks instead.
- After submitting one or more change requests, move the group state to Under Investigation.
- Determine what to deal with now and what you can defer. This determination is often
based on risk score, affected systems, and patches with change
windows.