Combined Configuration Compliance release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Configuration Compliance Release Notes for Upgrades from Yokohama to Zurich
This consolidated guide covers the release notes for Configuration Compliance upgrades from Yokohama to Zurich, focusing on new features, important upgrade considerations, and integration enhancements. It is designed to help ServiceNow customers understand changes, plan upgrades, and utilize new functionalities effectively.
Show less
Important Upgrade Information
- Before upgrading to Zurich, complete pre- and post-upgrade tasks as recommended.
- If not upgrading to Unified Security Exposure Management (USEM), install Configuration Compliance versions below v30.x for compatibility with third-party integrations.
- The Missing Assets [snvulwizmissingasset] table used in Vulnerability Response Integration with Wiz is deprecated; post-upgrade to version 1.1, backdate existing Wiz integrations by three days and rerun them.
- Backfill integrations related to Wiz are activated by default to handle missing assets previously unprocessed.
- Refer to the Vulnerability Response Compatibility Matrix for supported third-party and ServiceNow applications with Zurich.
New Features
- Wiz Resource Type Identification: Select Wiz asset types to import via the Wiz Integration Resource Type configuration page in the ServiceNow AI Platform instance; applies to most Wiz integrations except the Container Vulnerability Integration.
- Wiz Backfill Integrations: Specialized integrations to process missing assets data, activated by default.
- Host Test Result Vulnerability Integration: Imports test results for VIRTUAL MACHINE resource types and is activated by default.
- Manual Remediation Task Creation: Users with
snvulc.adminrole can create remediation tasks in the Vulnerability Manager Workspace; those withsnvulc.remediationownerrole can do so in the IT Remediation Workspace. Tasks are grouped based on selected criteria. - Risk Score Details in Work Notes: System property
snseccmn.riskscorechangesaddworknotes(inactive by default) controls visibility of risk score changes in test result work notes. - Quick Start Tests: Recommended after upgrades or new integrations to verify Configuration Compliance functionality; customizable for tailored implementations.
- Qualys Integration Parameter: Added
ignorepassedresultparameter (default false) to control import of passed test results, improving data relevance. - Granularity Configuration for Test Results: Ability to split Tenable and Qualys Configuration Test Results into unique findings per instance, enhancing visibility into patching efforts.
- Related List Row Limit: System property allows limiting rows shown in related lists to improve form readability and performance.
- Enhanced State Management: Improved logic for state roll-up and roll-down between remediation tasks and findings for better accuracy and streamlined workflows.
- Dark Theme Support: Zurich introduces a Coral theme with dark mode option for web and mobile to improve readability and reduce eye strain.
Changes and Deprecations
- Deprecated Features: The
Missing Assets [snvulwizmissingasset]table and theisignoredcolumn in Host Test Results and Test Results integrations are deprecated and replaced by updated fields such asisresultignored. - Source Severity Mapping: Source severity is now mapped to the Priority column on the Test Results table.
- Resource Type Filters: Enhanced filtering options on Wiz configuration tabs allow more precise resource type import management; integration instance settings take precedence over global configurations.
- Additional Attributes: Attributes from Wiz not stored in Discovered Items are now stamped as Asset Attributes.
- CMDB Field Mapping: The internet-facing field on discovered items is mapped to Limited Internet Exposure on findings.
- Description Field Length Increased: Host Vulnerability import table descriptions support longer text.
Activation and Installation
- Configuration Compliance and related third-party integrations are available through the ServiceNow Store; customers should request installation from there.
- For cumulative release notes and app updates, refer to the ServiceNow Store version history.
Additional Information
- No new browser or localization requirements were introduced in Zurich.
- Accessibility improvements include the addition of a dark theme to enhance user experience.
- Manual remediation task creation continues to be supported in both Vulnerability Manager and IT Remediation Workspaces with appropriate roles.
- For customers planning to upgrade to USEM, separate release notes provide migration guidance.
Consolidated page of all release notes for Configuration Compliance from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Configuration Compliance release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Configuration Compliance to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
If you are currently using Configuration Compliance, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Configuration Compliance and for upgrades to supported third-party integration applications. The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community. For more information about the released versions of the Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base. |
New features
Between your current release family and Zurich, new features were introduced for Configuration Compliance.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Configuration Compliance features.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Removed
Between your current release family and Zurich, some Configuration Compliance features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Configuration Compliance features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Configuration Compliance.
| Release | Release notes |
|---|---|
Yokohama |
Install Configuration Compliance by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Configuration Compliance and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Configuration Compliance, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Configuration Compliance for more information. |
Zurich |
See Configuration Compliance for more information. |