Example workflow for the Vulnerability Response patch orchestration integration with HCL BigFix
An example of how patch orchestration works with the HCL BigFix product.
始める前に
Say, for example, your entire environment is patched once every three weeks. The most recent patching window was completed a week ago, but you want to apply a patch to fix a critical vulnerability that has recently become known. Due to the critical nature of this vulnerability, you cannot wait two more weeks for the next scheduled patch.
Roles required:
- sn_vul.vulnerability_analyst or sn_vul.vulnerability_admin for the Vulnerability Manager Workspace.
- sn_vul.remediation_owner to view the IT Remediaiton Owner workspace.
- sn_vul_patch_orch.configure_patch role to configure and schedule patches.
- sn_vul_patch_orch.read_patch to view (read only) patch information on records. This role is inherited with the sn_vul.remediation_owner and sn_vuln.vulnerability_analyst roles that are required for the IT Remediation and Vulnerability Manager Workspaces.
このタスクについて
As a vulnerability manager or analyst working in the Vulnerability Manager Workspace, you
might consider creating watch topics, or editing existing watch topics to help you capture
imported VIs with critical vulnerabilities. With the patch orchestration integration, you can
also see the patches you want to use to fix and track these vulnerabilities. The following table
lists a few samples with the conditions you might set for watch topics for patch orchestration.
Use these examples to help you determine settings that work best for your environment. See Create a watch topic in the Vulnerability Manager Workspace for more information about
setting up the watch topic.
| Watch topic name | Description |
|---|---|
| Critical Vulnerabilities with Patch Leaks | Risk rating is 1 - critical AND Reason is Patch Not Scheduled |
| Critical Vulnerabilities with Patches Scheduled (missing SLA) | Reason is Patch Scheduled (Missing Target Date) |
| Critical Vulnerabilities with Patches Scheduled | Risk rating is 1 - critical AND Patch scheduled date is not empty AND Reason is Patch Scheduled |
- As a vulnerability manager or analyst, after you create the watch topics and remediation efforts, you generate remediation tasks. From VI records and remediation tasks, you can drill down into the Detections tab and locate discovered item records that have the vulnerability you are tracking, along with the assets imported by the BigFix product.
- As a vulnerability analyst or admin, you can monitor the patch data associated with the vulnerability. You might also deploy a patch or multiple patches to a specific asset (configuration item) from a discovered item record.
As an IT remediation specialist, you have options for how you address the vulnerability with a patch deployment.
- You can schedule the patch from a Patch Update record (VPU#).
- If vulnerable items (VI)s have preferred solutions mapped to them, and they are assigned to you or your groups, you can schedule the patches from a remediation task that has these vulnerable items.