Vulnerability Response implementation

  • Release version: Yokohama
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Vulnerability Response implementation

    This guide outlines the process for ServiceNow customers to download, install, and configure the Vulnerability Response application on their ServiceNow AI Platform® instance. It includes an example of installing the core Vulnerability Response system along with a third-party scanner (Qualys application), highlighting required roles, mandatory tasks, and optional steps.

    Show full answer Show less

    The admin role is essential for downloading and installing the applications and for assigning the Vulnerability admin [snvul.vulnerabilityadmin] persona and other relevant roles to users and groups. The Vulnerability admin role is responsible for configuring the applications through the Setup Assistant, which guides users through the setup starting with Vulnerability Response Settings.

    Key Features

    • Setup Assistant: Provides step-by-step configuration, helping verify Vulnerability Response processes during setup.
    • Administration console (from v30.0): Centralizes configuration for all Unified Security Exposure Management applications, including assignment rules, classification rules, and remediation targets. It supports consistent workflows across Vulnerability Response, Application Vulnerability Response, Container Vulnerability Response, and Configuration Compliance applications.
    • Automated rules and calculators:
      • Vulnerability Assignment Rules: Automatically assign vulnerable items to appropriate groups.
      • Remediation Task Rules: Automatically group vulnerable items based on conditions.
      • Risk Calculators: Default risk calculator enabled for vulnerability assessment.
      • Remediation Target Rules: Define remediation timelines for vulnerabilities and tasks.
    • Third-party integrations: Configure and manage third-party scanner applications like Qualys by entering account information, import settings, schedules, and CI lookup rules.

    Practical Application

    By following this implementation sequence, ServiceNow customers can efficiently set up a comprehensive vulnerability response environment. The process enables automation of vulnerability assignments, risk evaluation, and remediation management, which streamlines security operations and reduces manual overhead.

    Customers are encouraged to consult the Implementation checklist for detailed steps and supporting documentation, and review best practices outlined in the Knowledge Base article KB1157979 to optimize performance and configuration.

    Use the steps illustrated in the following images to download the Vulnerability Response application from the ServiceNow Store, install it on your ServiceNow AI Platform® instance, and configure it using the Setup Assistant.

    An installation and configuration example for installing the base system, the Vulnerability Response application and a third-party scanner application, the Qualys application, is illustrated in the following images. Required roles and mandatory tasks, as well as optional steps, are also listed.

    • For more information about each step illustrated in the following images and a checklist with links to supporting documentation, see Implementation checklist for the Vulnerability Response application.
    • You can extend the concepts and sequence of steps presented in this example to installing and configuring other supported applications for Vulnerability Response. For a list of support applications, see Installation of Vulnerability Response and supported applications.
    • The admin role is required to download and install the Vulnerability Response application and the Qualys Vulnerability application used for this example.
    • The admin role also assigns the Vulnerability admin [sn_vul.vulnerability_admin] persona and other Vulnerability Response persona roles to users and groups.
    Figure 1. Admin tasks
    Refer to the first section for links and a description of how to download, activate, and configure apps from within the Setup Assistant.

    The sn_vul.vulnerability_admin role configures the Vulnerability Response and Qualys applications in Setup Assistant and verifies expected results.

    Follow the steps and prompts in Setup Assistant starting with the Vulnerability Response Settings section to continue with the installation and configuration. Reviewing these settings helps you understand and verify the processes of Vulnerability Response as you continue to set up your environment.

    Role required: sn_vul.vulnerability_admin or, alternatively, admin.

    Figure 2. Vulnerability admin tasks
    Vulnerability admin tasks in the Setup Assistant under the Vulnerability Response Settings module and the Integration Configuration module.

    Starting with v30.0 of Vulnerability Response, the Administration console in the Security Exposure Management Workspace enables one-stop configuration for all Unified Security Exposure Management applications, including assignment rules, classification rules, and remediation targets. It provides consistent workflows across Vulnerability ResponseApplication Vulnerability ResponseContainer Vulnerability Response, and Configuration Compliance applications. For more information, see Configure rules to manage findings.

    Review the descriptions, default settings, and demo data that you installed with the applications in the following sections:

    • Vulnerability Assignment Rules - automatically assign vulnerable items (VIs) to the appropriate assignment group.
    • Remediation Task Rules - automatically group vulnerable items (VIs) as they are imported based on certain conditions.
    • Risk Calculators - Default Risk Calculator is enabled.
    • Remediation Target Rules - Define remediation time lines for VIs and remediation tasks (RTs).
    • Review and edit the settings for the third-party applications and installed solutions you installed and define conditions for your data imports. Enter your third-party account information and configure import settings, and schedules, configuration item (CI) lookup rules, as well as other settings.

    See Implementation checklist for the Vulnerability Response application for more information.

    For additional information while customizing or implementing the Vulnerability Response application, see the Best Practices: Vulnerability Response Implementation for better performance Knowledge Base article [KB1157979].