These are complex questions, so this answer is; It depends.

"Did the solution that your team provided enable the full management of the imported Penetration Testing vulnerabilities in ServiceNow?"

- How does your organization define "full management"?

One thing that comes to mind; The pentest result became a Vulnerable Item and then follow the VR lifecycle. Except..... Normally a VR scanner is the final judge on whether or not something was truly resolved. Manually generating pentest results does not have the same mechanism. This part will need to be worked out.

"Did the solution provide the ability to provide full in-depth reports on vulnerability statistics from within ServiceNow?"

- How does your organization define "full in-depth reports"? Does your organization have Performance Analytics? As the data matures does your organization have the skill set to enhance the reporting?

 

 

View solution in original post