Configuring Vulnerability Response using the Setup Assistant
Summarize
Summary of Configuring Vulnerability Response using the Setup Assistant
The Setup Assistant in ServiceNow guides you through configuring Vulnerability Response and certain third-party integrations efficiently. It streamlines the installation, role assignment, rule creation, and integration setup processes, enabling you to effectively manage vulnerabilities, automate remediation, and prioritize risk within your environment.
Show less
System Administration and Role Management
To use the Setup Assistant, you need two key roles: admin and vulnerability admin. Initially, obtain a list of users and integrations from your Vulnerability Manager. Through the Setup Assistant, an admin assigns appropriate Vulnerability Response personas and granular roles to users and groups, controlling access and permissions:
- snvul.admin: For administration and configuration of Vulnerability Response, including integrations and remediation rules.
- snvulvulnerabilitywrite: To create and update remediation tasks and vulnerable items.
- snvulvulnerabilityread: For viewing remediation tasks and vulnerability information.
- Users with the itil role automatically receive remediation owner access without additional assignment.
The Setup Assistant also facilitates installing supported third-party vulnerability integration applications to expand your environment's capabilities.
Vulnerability Response Settings
Users with the snvul.vulnerabilityadmin or snvul.admin (deprecated) role, or admin, can configure application-wide settings and rules, including:
- Vulnerability Assignment Rules: Automate assignment of remediation tasks. Activate the scheduled job to reapply these rules across your open vulnerabilities to maintain consistent task assignment. Scheduling frequency should be adjusted based on your environment size to avoid performance issues.
- Remediation Task Rules: Define automatic creation of remediation tasks. Deleting a group rule optionally removes all open groups created by that rule.
- Risk Calculators: Enable and customize calculators that score vulnerabilities to prioritize remediation efforts effectively.
- Remediation Target Rules: Set rules for remediation categories to streamline workflows.
Integration Configuration
The Setup Assistant enables configuration, scheduling, and management of third-party vulnerability scanner integrations and solution providers, requiring the snvul.vulnerabilityadmin or admin role. Supported integrations include:
- Qualys Vulnerability Integration
- Tenable Vulnerability Integration
- Solution providers like Red Hat and Microsoft Security Response Center, available upon installing the Solution Management for Vulnerability Response application.
Multiple deployments of the same third-party integration are supported by using the original integration settings as templates. Instead of deleting integrations, consider disabling them to preserve templates and prevent unintended disruption. Note that multiple Rapid7 InsightVM integrations require special domain-separated configuration outside of Setup Assistant.
Additional Considerations
For setup and configuration tasks not covered by the Setup Assistant, refer to additional Vulnerability Response setup documentation to ensure comprehensive environment configuration.
Setup Assistant walks you through setting up Vulnerability Response and certain third-party integrations for your environment. Setup Assistant provides almost everything you need to install and set up your environment so that you can use Vulnerability Response.
Using Setup Assistant requires two different ServiceNow AI Platform® roles: admin and vulnerability admin.
Refer to the following sections to supplement the instructions and prompts provided in Setup Assistant.
System Administration - assign users and groups and install integration applications
Role required: admin
A list of users and integrations should be obtained from the Vulnerability Manager prior to beginning these tasks.
- Navigate to .
- In the first section, System Administration, the admin the assigns roles to users and groups and installs supported integrations.
Assign Vulnerability Response personas and roles to users and groups in Setup Assistant.
Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.
- Assign roles in Setup Assistant.
- Assign the role of sn_vul.admin to users or groups.
- Assign the sn_vul.admin role for Vulnerability Response administration and configuration including vulnerability integrations, remediation task rules, calculators, and time-to-remediate rules.
- Assign the sn_vul_vulnerability_write role for the creation and update of remediation tasks and vulnerable items.Note:All other users automatically receive Write access only to remediation tasks that are assigned to them.
- Assign the sn_vul_vulnerability_read role to view remediation tasks, vulnerable items, and other vulnerability information.Note:Users with the itil role are automatically granted the sn_vul.remediation_owner role allowing them to see remediation tasks and vulnerable items assigned to them, vulnerability entries, and, solutions in the Vulnerability Response application on their instance and in the Mobile Agent application. No additional assignment is needed.
- Install third-party integration applications.
- See Installation of Vulnerability Response and supported applications and Vulnerability Response integrations for more information about applications that are supported by Vulnerability Response.
- For more information about using setup assistant to install supported apps, see Install Vulnerability Response third-party applications using Setup Assistant.
Vulnerability Response Settings
Role required: sn_vul.vulnerability_admin or sn_vul.admin (deprecated), or admin
In Vulnerability Response Settings, the vulnerability administrator defines application-wide settings and defines rules for Vulnerability Response. Alternatively, the admin can perform these tasks.
- Create Vulnerability Assignment Rules.
Create rules that define the automatic assignment of remediation tasks for resolution. At least one rule is shipped with the base system. See Vulnerability Response assignment rules overview for more information.
Note:The reapply feature requires a baseline application of the rules. Once your rules are created, activate the Reapply all vulnerability assignment rules scheduled job to execute, at your convenience. Otherwise, you will be required to reapply all rules to all Open VIs prior to changing them.
When the job is complete, set the Run field in the scheduled job to fit your environment. Depending on the number of active VIs you have, evaluating and updating them daily can have non-trivial performance impact. For larger environments, consider updating once a week or even once a month.
Reapplying assignment rules does not regroup the vulnerable items.
- Create remediation task rules.
Create rules that define the automatic creation of remediation tasks for resolution. At least one rule, Vulnerability, is shipped with the base system. You can reapply the rules from the form or list view.
- When a group rule is deleted, from the form or list view, you have the option to delete all Open groups created by that rule. Groups not in the Open state are excluded.
- See CI lookup rules for identifying configuration items from Vulnerability Response third-party vulnerability integrations for more information on creating rules for your environment.
- See Exploring the Vulnerability Response application for more information on using Vulnerability Response to remediate vulnerabilities.
- Create and enable Risk Calculators.
Enable risk calculators that define how vulnerable items are scored for prioritization. Several risk calculators are shipped with the base system. See Vulnerability Response calculators and vulnerability calculator rules information on creating or editing risk calculators for your environment.
- Create Remediation Target Rules.
Create remediation target rules for categories of remediation. At least one rule is shipped with the base system. See Vulnerability Response remediation target rules for more information on creating rules for your environment.
Integration Configuration
Role required: sn_vul.vulnerability_admin or sn_vul.admin (deprecated), or admin.
In the Integration Configuration section, configure, schedule, edit, and launch on-demand the following third-party vulnerability scanner integrations and, if the Solution Management for Vulnerability Response application is installed, solution providers.
- See Configure the Qualys Vulnerability Integration using Setup Assistant for more information about configuring the Qualys Vulnerability Integration.
- Configuration of the Vulnerability Response Integration with Tenable application is supported. See Configure the Tenable Vulnerability Integration using Setup Assistant.
- After you install the Vulnerability Solution Management application, the Solution Integrations option is displayed below Scanner Integrations. Click Solution Integrations to
configure your installed vulnerability solution providers from this section of Setup Assistant. The Red Hat Solution Integration and Microsoft Security Response Center Solution Integration are supported.
See Vulnerability Solution Management for more information about installed solutions. See Install the Solution Management for Vulnerability Response application for more information about installation.
See Configure installed solution integrations for Vulnerability Solution Management using Setup Assistant for more information about configuring your installed solutions.
- If an integration is multi-sourced, you can have multiple deployments of the same third-party integration.
- The settings from your original third-party integration are used as a template for the settings of each new integration. Note:If you delete the original vulnerability integration, you have to select another integration to use as your template. Consider disabling the integration instead of deleting it. Integrations created from disabled templates are disabled by default.
Data from each third-party integration is uniquely identified and available in a single instance of Vulnerability Response.
Additional tasks
See Additional Vulnerability Response setup and configuration tasks for more information on setup tasks not included in Setup Assistant.