Join the #BuildWithBuildAgent Challenge! Get recognized, earn exclusive swag, and inspire the ServiceNow Community with what you can build using Build Agent.  Join the Challenge.

Remediation tasks not created when VIT risk rating/score increases

Aaron Molenaar
Mega Guru

We use Rapid7's Active Risk score as one of the primary drivers of the normalized risk rating of third-party vulnerability entry records in VR, which then drives the risk score/rating of vulnerable items. As Active Risk is driven by threat intelligence, if the threat increases, the corresponding active risk score flowing in to Vulnerability Response increases, and we get an increased normalized risk rating on the TPVE record. We can get this increase to flow all the way through the system to the VIT records, which change rating from, for instance, a 4 - Low to a 2 - High or 1 - Critical, as desired.

 

However, if a VIT was not previously in a remediation task as it was a low rating, if the risk rating on the VIT increases because the underlying Active Risk score changes, the system is not picking up the new higher VIT risk rating/score change and issuing that VIT out in a remediation task. We currently have remediation task rules designed to issue tasks for critical/high rated VIT, which work perfectly on new VIT coming in to the system, but the rules do not pick up existing VIT if their risk rating/score changes to something that makes them fit the remediation task rule criteria.

 

I have been through all the business rules and related code that I think relates on both the VIT and VUL tables, but can not seem to find the right trigger. Can anyone provide guidance on what needs to be changes so that the change in risk score or risk rating on the VIT record will trigger a reconsideration of remediation task rules?

0 REPLIES 0