Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Best Practice for Flagging Recurring False Positive VITs by QID + CI (Qualys Integration)

RichardG8808753
Tera Contributor

Hi all,

Looking for advice from the community on handling recurring false positives in Vulnerability Response/USEM.

Context:

  • We're using ServiceNow Vulnerability Response / USEM (Australia Release) integrated with Qualys (Host Detection).
  • Our team has identified certain QID + CI combinations that are confirmed false positives 
  • These VITs keep reappearing or reopening on subsequent Qualys scan imports, creating noise for the remediation teams.
  • Bulk load of currently approved false positives

What we're trying to achieve:

  1. A repeatable way to flag specific QID + CI combinations as known false positives.
  2. Prevent them from reopening or generating new VITs on future imports.
  3. Maintain proper governance — approval, justification, evidence, and periodic review.
  4. Ideally keep ServiceNow and Qualys aligned so the suppression is reflected on both sides.

Questions:

  • What approach have you found works best — deferral with a False Positive substate, exception rules, closing at the Vulnerability Group level, or something else?
  • How are you preventing re-opening on re-import from Qualys? Any specific integration properties or reconciliation settings we should look at?
  • Are you pushing the false positive status back to Qualys, or managing it purely in ServiceNow?
  • Any lessons learned around governance (approvals, expiration/review cadence, reporting)?

Happy to hear both OOB approaches and any customizations you've implemented. Please also mention which VR release you're on, as I know behavior has evolved across versions.

Thanks in advance!

 

Richard

0 REPLIES 0