Vulnerability Response remediation overview
Summarize
Summary of Vulnerability Response remediation overview
Vulnerability Response remediation is a structured, phased process designed to make vulnerability management manageable, timely, and partially automated. It involves verifying third-party vulnerability data imports, triaging new vulnerabilities, and monitoring remediation progress. This process helps ServiceNow customers understand their security posture across assets and prioritize critical vulnerabilities for remediation.
Show less
To use this remediation process, customers must have Vulnerability Response and a compatible third-party integration (e.g., Qualys Vulnerability Integration) installed and configured.
Key Features
- Verification of Third-Party Imports: Ensures successful import of vulnerability data from sources like the National Vulnerability Database (NVD) and third-party vendors. This data is essential for creating vulnerable items and remediation tasks.
- Asset Matching: Uses CI Lookup Rules to correlate imported assets with Configuration Management Database (CMDB) records, storing them in the Discovered Items module. Accurate asset information is critical for effective remediation.
- Import Monitoring: Provides integration status reports to graphically display import success, allowing quick identification and resolution of failed imports, which may occur due to issues like API throttling.
- Vulnerability and Vulnerable Item Triage: Reviews new vulnerabilities and vulnerable items, applies rules to assign ownership, assess risk, and set remediation targets, with flexibility to adjust these rules as needed.
- Remediation Progress Monitoring: Tracks patch implementation status, regulatory compliance progress, and deferred vulnerabilities. Customers can leverage Vulnerability Management dashboards and Performance Analytics for real-time reporting and trend analysis.
Key Outcomes
- Improved ability to identify and prioritize critical vulnerabilities across company assets.
- Automated and consistent import of vulnerability data reduces manual effort and errors.
- Clear visibility into remediation progress, facilitating timely patch deployment and compliance adherence.
- Enhanced collaboration between security and IT operations through status tracking and reporting.
- Capability to close stale detections and maintain an up-to-date vulnerability posture.
Vulnerability Response remediation is a phased process consisting of verifying import completion, triaging new vulnerabilities, and monitoring progress to completion. Approached in this way, remediation becomes manageable, timely, and in many ways, automated.
Understanding your security posture across company assets helps you identify the most critical vulnerabilities for remediation. This remediation process requires that Vulnerability Response and a third-party integration such as the Qualys Vulnerability Integration are installed and configured.
Verify the successful completion of third-party integration imports
The first phase in this process is to ensure that everything is working correctly. Vulnerability Response is preset to download National Vulnerability Database (NVD) and Common Enumeration Weakness (CWE) vulnerabilities. Third-party imports provide you with the data you need to create vulnerable items and remediation tasks. Successful remediation depends on the consistent and successful import of vulnerabilities and vulnerable items.
During import CI Lookup Rules match third-party assets to assets in the Configuration Management Database (CMDB). All assets are stored in the Discovered Items module. CI information is critical to solution implementation.
Integration status run reports for the supported third-party integrations are shipped with the applications to give you a graphical overview of your imports. Use this report, or create your own, to easily determine whether your latest import has succeeded. For more information about supported integrations, see Vulnerability Response integrations.
Review and triage vulnerabilities and vulnerable items
The next phase of remediation calls for the review of new vulnerabilities and vulnerable items. A vulnerable item (VI) is a detected combination of vulnerability and configuration item (CI). As vulnerable items are formed, various rules are run that assign VIs, determine the risk they pose and set remediation targets. Adjust any rules, as necessary, to ensure that the vulnerable items have been triaged successfully.
Monitor the progress of existing vulnerability remediation
- Review the status of imports for patch implementations that have not shown up and follow up with IT Operations.
- Track the progress of regulatory compliance obligations and ensure their completion.
- Review deferred item status and revise or implement fixes.
- Monitor Vulnerability Management dashboards. To review trends, view reports in real-time, and use metrics that track your remediation target attainment rates, you may prefer to monitor your processes with the Performance Analytics for Vulnerability Response application.
- Closing stale detections in Vulnerability Response.