<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting in SecOps forum</title>
    <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328845#M8708</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is there an approach to integrating a third party's Penetration Testing vulnerabilities into ServiceNow to provide vulnerabilities management and reporting please?&lt;/P&gt;
&lt;P&gt;The Penetration Test results are not from an automated vulnerability scanning system they are from a third party Penetration testing consultancy that has performed exploitative tests to assess systems security status.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Mar 2021 10:26:14 GMT</pubDate>
    <dc:creator>Richbrowne</dc:creator>
    <dc:date>2021-03-10T10:26:14Z</dc:date>
    <item>
      <title>Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328845#M8708</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is there an approach to integrating a third party's Penetration Testing vulnerabilities into ServiceNow to provide vulnerabilities management and reporting please?&lt;/P&gt;
&lt;P&gt;The Penetration Test results are not from an automated vulnerability scanning system they are from a third party Penetration testing consultancy that has performed exploitative tests to assess systems security status.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 10:26:14 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328845#M8708</guid>
      <dc:creator>Richbrowne</dc:creator>
      <dc:date>2021-03-10T10:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328846#M8709</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I was on a team of people who just implemented this for a Customer. We designed a standard format that the findings would be in (we settled on JSON as the data container). The customer's Pentesting teams (internal and external) will provide their result in this standard JSON format.&lt;BR /&gt;We then created a Record Producer that parses the data (Attachment to the Record Producer form) and creates the Vulnerabilities leveraging the VR framework.&lt;/P&gt;
&lt;P&gt;We also added NIST and PCI to the Thrid-Party Libraries (you will need to decide on a standard format that will be identified in the Pentest finding)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;It would be nice if the Pentest community would come up with a standard... if you come across one, I would love to hear about it!&lt;BR /&gt;Hopes this helps.&lt;/P&gt;
&lt;DIV id="mstr_highlight_precard" style="position: absolute; left: 0px; top: 0px;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Mar 2021 13:59:28 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328846#M8709</guid>
      <dc:creator>chrismcdevi</dc:creator>
      <dc:date>2021-03-10T13:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328847#M8710</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;
&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;How long did this solution take from design to implementation please and was this a bespoke module developed for the client? I assume this is not possible with an existing ServiceNow module?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 15:56:31 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328847#M8710</guid>
      <dc:creator>Richbrowne</dc:creator>
      <dc:date>2021-03-10T15:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328848#M8711</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It took us about +/-80 hours to do this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, we used the Vulnerability Response module.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the key: T&lt;SPAN style="text-decoration: underline;"&gt;he Pentest owner needs to agree that Pentest findings need to fit into the VR framework and NOT&amp;nbsp;try and make the&amp;nbsp;VR Framework fit Pentest.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New components:&lt;/P&gt;
&lt;P&gt;Record Producer&lt;/P&gt;
&lt;P&gt;Custom fields (on VR)&lt;/P&gt;
&lt;P&gt;UI Policies&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ACL's&lt;/P&gt;
&lt;P&gt;Custom script include&lt;/P&gt;
&lt;P&gt;Third-Party Integration Record&lt;/P&gt;
&lt;P&gt;CI Lookup Rules&lt;/P&gt;
&lt;P&gt;Transform Scripts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Record Producer (Attachment with json) -&amp;gt; Transform Map (CI Lookup Rules + Match one or create Third-Party) Create VI. From there, Assignment Rules, Risk, and Grouping rules run.&lt;/P&gt;
&lt;DIV id="mstr_highlight_precard" style="position: absolute; left: 0px; top: 0px;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Mar 2021 19:57:51 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328848#M8711</guid>
      <dc:creator>chrismcdevi</dc:creator>
      <dc:date>2021-03-10T19:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328849#M8712</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;
&lt;P&gt;Thank you again for the reply, much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regards the circa 80 hours timeframe to provide this service, was that 80 man hours or was that how long it took a team working in parallel please?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition, were the resource(s) that provided the solution skilled ServiceNow developers/engineers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 09:58:25 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328849#M8712</guid>
      <dc:creator>Richbrowne</dc:creator>
      <dc:date>2021-03-11T09:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328850#M8713</link>
      <description>&lt;P&gt;There were three of us working in parallel.&lt;/P&gt;
&lt;P&gt;Skilled? Well... the more I learn about ServiceNow, the more I realize there is a lot more to learn. &lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I would say you will need someone who has worked building customization integration into the Vulnerability Framework before. The rest of the team needs to have good ServiceNow development skills.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As I mentioned before, all this depends on your design fitting into Vulnerability Response and not the other way around. This is a critical point to figuring out how long things will take to do.&lt;/P&gt;
&lt;DIV id="mstr_highlight_precard" style="position: absolute; left: 0px; top: 0px;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Mar 2021 12:56:55 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328850#M8713</guid>
      <dc:creator>chrismcdevi</dc:creator>
      <dc:date>2021-03-11T12:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328851#M8714</link>
      <description>&lt;P&gt;Thank you Chris, very helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 10:52:39 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328851#M8714</guid>
      <dc:creator>Richbrowne</dc:creator>
      <dc:date>2021-03-12T10:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328852#M8715</link>
      <description>&lt;P&gt;Apologies Chris, a few more queries...&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Did the solution that your team provided enable the full management of the imported Penetration Testing vulnerabilities in ServiceNow?&lt;/LI&gt;
&lt;LI&gt;Did the solution provide the ability to provide full in-depth reports on vulnerability statistics from within ServiceNow?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 13:26:51 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328852#M8715</guid>
      <dc:creator>Richbrowne</dc:creator>
      <dc:date>2021-03-12T13:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328853#M8716</link>
      <description>&lt;P&gt;These are complex questions, so this answer is; It depends.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Did the solution that your team provided enable the full management of the imported Penetration Testing vulnerabilities in ServiceNow?"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;- How does your organization define "&lt;EM&gt;full management"?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;One thing that comes to mind; The pentest result became a Vulnerable Item and then follow the VR lifecycle. Except..... Normally a VR scanner is the final judge on whether or not something was truly resolved. Manually generating pentest results does not have the same mechanism. This part will need to be worked out.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;Did the solution provide the ability to provide full in-depth reports on vulnerability statistics from within ServiceNow?&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;- How does your organization define "&lt;EM&gt;full in-depth reports"?&amp;nbsp;&lt;/EM&gt;Does your organization have Performance Analytics? As the data matures does your organization have the skill set to enhance the reporting?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="mstr_highlight_precard" style="position: absolute; left: 0px; top: 0px;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 12 Mar 2021 20:18:01 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328853#M8716</guid>
      <dc:creator>chrismcdevi</dc:creator>
      <dc:date>2021-03-12T20:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328854#M8717</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have an update for this.... I took everything I built, and I have extended it to now be brought in via an Import Set through the Import Set API.&lt;/P&gt;
&lt;P&gt;https://docs.servicenow.com/bundle/tokyo-application-development/page/integrate/inbound-rest/concept/c_ImportSetAPI.html&lt;/P&gt;
&lt;P&gt;Baby steps... I tell all my customers, "let's take baby steps first."&lt;/P&gt;
&lt;P&gt;First, they were doing a low volume of Pentest into VR using the Record Producer. Once the process was successful... guess what? The customer wanted more...&lt;/P&gt;
&lt;P&gt;We shifted left in their process, and now the Pentest teams push their findings into SN VR via the Import Set API.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 20:21:39 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/1328854#M8717</guid>
      <dc:creator>chrismcdevi</dc:creator>
      <dc:date>2022-08-09T20:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pen test Vulnerabilities Integrated into ServiceNow for Vulnerability Management and Reporting</title>
      <link>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/2804440#M11175</link>
      <description>&lt;P&gt;Certainly! Integrating a third party's Penetration Testing vulnerabilities into ServiceNow for robust management and reporting is possible. Utilize ServiceNow's integration capabilities or custom scripts to import exploitative test results. Design a custom data model, map relevant fields, and automate ticketing for remediation workflows. For expert guidance, consider consulting a specialized &lt;A href="https://securelayer7.net/" target="_self"&gt;Penetration Testing service&lt;/A&gt; to optimize the integration within ServiceNow, ensuring a seamless and efficient vulnerabilities management process.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 07:35:55 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/pen-test-vulnerabilities-integrated-into-servicenow-for/m-p/2804440#M11175</guid>
      <dc:creator>Rohitkumar01</dc:creator>
      <dc:date>2024-01-25T07:35:55Z</dc:date>
    </item>
  </channel>
</rss>

