Creation on Multiple Remediation Task for a Single Host based on the number of Application running in the host
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā08-24-2022 02:29 AM
In Vulnerability Response Application how to create different Remediation Task for an Vulnerability Items based on the different Application present in the host.
- Labels:
-
Vulnerability Response

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā08-25-2022 06:25 AM
Hi,
VR has a concept called granularity:
https://docs.servicenow.com/bundle/tokyo-security-management/page/product/vulnerability-response/task/vr-configure-vi-key.html
OOB, you can choose to create a vulnerable item for each unique port for a given host and vulnerability.
In theory, a Port represents an application.
Past that, you would need to customize what constitutes the "key" (not recommended).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā08-25-2022 04:35 PM
Along with Granularity that Chris mentioned above, you may also want to look into using Vulnerability Classification Rules. They would allow you to identify Vulnerable Entries that are associated with Applications and the specific Application that each is associated with. Vulnerable Item Assignment rules can use that information to assign a VI to the group responsible for a given Application. Remediation Task Rules will then group the VI's by Assignment Group.
Here are some basic details:
a. Define Vulnerability Classification Rules to set the Classification and Classification Type for each Vulnerable Entry. You can use a condition builder or a script to determine what values you wish to assign. Some examples of what they could be are:
Classification | Classification Type |
Application | Java |
Application | Chrome |
Application | Browser |
Platform | Linux |
Platform | Windows Server |
Platform | VMWare |
b. Configure VI Assignment Rules to consider Vulnerability.Classification and Vulnerability.Classification Type when a VI is assigned.
c. Remediation Task grouping Rules are most likely already using VI.Assignment Group when creating Remediation Tasks.
Classification Rules are a relatively recent addition to VR (within the past year). The great thing about them is that they are run once, when a Vulnerability Entry is created. Often, this type of logic is duplicated in multiple Assignment Rules that are run each time a VI is assigned. Here is some documentation:
⢠https://docs.servicenow.com/bundle/tokyo-security-management/page/product/vulnerability-response/concept/vulnerability-classification-rules.html
⢠https://docs.servicenow.com/bundle/tokyo-security-management/page/product/vulnerability-response/task/create-classification-rule.html
I hope that this helps,
--Joe