Best Practice for Flagging Recurring False Positive VITs by QID + CI (Qualys Integration)
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 hours ago
Hi all,
Looking for advice from the community on handling recurring false positives in Vulnerability Response/USEM.
Context:
- We're using ServiceNow Vulnerability Response / USEM (Australia Release) integrated with Qualys (Host Detection).
- Our team has identified certain QID + CI combinations that are confirmed false positives
- These VITs keep reappearing or reopening on subsequent Qualys scan imports, creating noise for the remediation teams.
- Bulk load of currently approved false positives
What we're trying to achieve:
- A repeatable way to flag specific QID + CI combinations as known false positives.
- Prevent them from reopening or generating new VITs on future imports.
- Maintain proper governance — approval, justification, evidence, and periodic review.
- Ideally keep ServiceNow and Qualys aligned so the suppression is reflected on both sides.
Questions:
- What approach have you found works best — deferral with a False Positive substate, exception rules, closing at the Vulnerability Group level, or something else?
- How are you preventing re-opening on re-import from Qualys? Any specific integration properties or reconciliation settings we should look at?
- Are you pushing the false positive status back to Qualys, or managing it purely in ServiceNow?
- Any lessons learned around governance (approvals, expiration/review cadence, reporting)?
Happy to hear both OOB approaches and any customizations you've implemented. Please also mention which VR release you're on, as I know behavior has evolved across versions.
Thanks in advance!
Richard
Labels:
- Labels:
-
Enterprise Architecture
0 REPLIES 0
