---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Integrate

# Unified Security Exposure Management integrations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 12 minutes to read

Unified Security Exposure Management supports multiple third-party integrations to help with vulnerability management, orchestration and remediation. This section provides guidelines for managing and developing
integrations.

## How integrations
work {#integrating-usem__section_k3d_nzy_mbb}

Integrations work in the following way:

1. Vulnerability entries are imported from the National Vulnerability Database (NVD), Central Vulnerability Database and third-party scanners.
2. Detection data from third-party scanners are matched against assets in your Configuration Management Database (CMDB).
3. When a match is found, a finding is created.
4. The findings are then:
   * Grouped into remediation tasks.
   * Risk-scored with business context.
   * Prioritized and assigned to the appropriate teams.
   {#integrating-usem__ul_ncp_5bj_dhc}
{#integrating-usem__ol_od5_pbj_dhc}
The following table provides a list of Unified Security Exposure Management integrations created by ServiceNow® and partners.{#integrating-usem__table_cyh_1yv_t2c__entry__6}

| Integration | Product installation | Category | Use case | Setup Guide | Built by |
|-|-|-|-|-|-|
| Import vulnerabilities and create vulnerable items ||||||
| Tenable | [Vulnerability Response Integration with Tenable](https://store.servicenow.com/store/app/861aa3e21b246a50a85b16db234bcb7c) | Vulnerability Response | Match assets, import third-party vulnerabilities to create vulnerable items. Note: Tenable.io doesn't support launching rescan on agent-based machines. | [Understanding the Tenable Vulnerability Integration](https://www.servicenow.com/docs/LBEiVzZ9snj0he1KfeiBpw "The Vulnerability Response Integration with Tenable application developed by ServiceNow engineering for the Tenable Vulnerability Integration uses data imported from the Tenable.io, Tenable.sc, and Tenable.cs products to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.") | ServiceNow |
| AWS | [AWS Integration for Security Exposure Management](https://www.servicenow.com/docs/wW4GccMDUaNK4S3r2teVHQ "AWS Integration for Security Exposure Management connects your AWS environment to your ServiceNow AI Platform, enabling you to import security findings from AWS Inspector and AWS Security Hub.") |   |   |   |   |
| Rapid7 | [Rapid7 Integration for Security Operations](https://store.servicenow.com/store/app/b349ebae1be06a50a85b16db234bcbb6) | Vulnerability Response | Match assets, import third-party vulnerabilities to create vulnerable items. | [Understanding the Rapid7 Vulnerability Integration](https://www.servicenow.com/docs/x6g91G68OSnfYIpX~hjiww "The ServiceNow Rapid7 Vulnerability Integration uses data imported from the Rapid7 data warehouse or the Rapid7 InsightVM products to help you determine the impact and priority of potentially malicious threats.") | ServiceNow |
| Qualys | [Qualys integration for Security Operations](https://store.servicenow.com/store/app/9f3b6f2a1b246a50a85b16db234bcb13) | Vulnerability Response | Match assets, import third-party vulnerabilities to create vulnerable items. Note: On-demand rescan is available. | [Understanding the Qualys Vulnerability Integration](https://www.servicenow.com/docs/voPK7ViYvD_BP1vyXszRpQ "The Qualys product sensors collect the data and automatically send it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates with Vulnerability Response as the Qualys Vulnerability Integration to map vulnerabilities to CIs and business services to determine impact and priority of potentially malicious threats.") | ServiceNow |
| CrowdStrike | [CrowdStrike Falcon Exposure Management for Vulnerability Response](https://store.servicenow.com/store/app/ca6ca7ae1b246a50a85b16db234bcb87) | Vulnerability Response | Match assets and use NVD to create vulnerable items. Supports tag-based filtering on import. |   | Partner |
| Microsoft | [Microsoft Defender Integration for Security Exposure Management](https://store.servicenow.com/store/app/df09276e1be06a50a85b16db234bcbe5) | Vulnerability Response | Match assets and import endpoint vulnerabilities to create vulnerable items. | [Understanding the Microsoft Threat and Vulnerability Management Vulnerability integrations for Security Exposure Management](https://www.servicenow.com/docs/zidYOmc32tY4Sfp0ltHCtw "The Microsoft Threat and Vulnerability Management integrations are included with the Microsoft Defender Integration for Security Exposure Management application available with a subscription from the ServiceNow Store.") | ServiceNow |
| Microsoft | [Vulnerability Response Integration with Microsoft Defender for IoT (On-premises Management Console)](https://store.servicenow.com/store/app/349ce3ee1b246a50a85b16db234bcb40) | Vulnerability Response | Import vulnerabilities into ServiceNow Operational Technology Vulnerability Response and take risk-based action with production process context. | [Vulnerability Response patch orchestration integration with Microsoft SCCM](https://www.servicenow.com/docs/PZV21C07W_aS_du2IqIsmA "The Vulnerability Response integration with the Microsoft System Center Configuration Manager (SCCM) supports patch management and deployment for critical vulnerabilities across your assets.") | ServiceNow |
| Cisco (Kenna) | [Kenna.VM (Vulnerability Management)](https://store.servicenow.com/store/app/5b7d2b261b646a50a85b16db234bcb43) | Vulnerability Response | Match assets and use NVD to create vulnerable items. Includes Kenna Risk score. |   | Partner |
| Tanium | [Tanium Vulnerability Management](https://store.servicenow.com/store/app/b13aafe21b246a50a85b16db234bcb0e) | Vulnerability Response | Match assets and import third-party vulnerabilities to create vulnerable items. |   | Partner |
| Orca | [Orca Security for Vulnerability Response](https://store.servicenow.com/store/app/20b9a3621b246a50a85b16db234bcb31) | Vulnerability Response | Match assets and import third-party vulnerabilities to create vulnerable items. |   | Partner |
| Onapsis | [Onapsis Vulnerability Integration](https://store.servicenow.com/store/app/c8b963621b246a50a85b16db234bcb69) | Vulnerability Response | Match assets and import third-party vulnerabilities to create vulnerable items for SAP assets and applications. |   | Partner |
| Synack | [Synack - Vulnerability Response](https://store.servicenow.com/store/app/2960bbe21ba46a50a85b16db234bcbc0) | Vulnerability Response | Import vulnerabilities from Synack. |   | Partner |
| Wiz.io | [Wiz Integration for Security Operations](https://store.servicenow.com/store/app/d069e3ee1be06a50a85b16db234bcb1d) | Vulnerability Response | Match cloud assets and import third-party vulnerabilities to create vulnerable items. | [Understanding the Wiz Vulnerability Response Integration](https://www.servicenow.com/docs/aekuuwJ9iIMNyepexD5scw "Import vulnerability and compliance data from Wiz scanners into your ServiceNow AI Platform instance to help you get deeper insights into your cloud infrastructure risks. These integrations provide you with a comprehensive assessment of your overall cloud security posture and help you drive remediation actions directly from your instance.") | Partner |
| Lacework | Lacework | Vulnerability Response | Import infrastructure vulnerabilities from your cloud asset sources. Supports vulnerability calculator and filtering by severity. |   | Partner |
| Recorded Future | [Attack Surface Intelligence](https://store.servicenow.com/store/app/8519e76e1be06a50a85b16db234bcbbb) | Vulnerability Response | External attack surface assets and exposures imported into ServiceNow Vulnerability Response. Create vulnerable items from external asset detections. Includes Recorded Future threat and vulnerability enrichment. |   | Partner |
| Mandiant | Mandiant Attack Surface Management | Vulnerability Response | Import information about vulnerabilities and vulnerable items from the Mandiant Attack Surface Management platform. |   | Partner |
| IBM | [IBM Guardium Data Protection](https://store.servicenow.com/store/app/36bc63221b646a50a85b16db234bcbc1) | Vulnerability Response | Integrate IBM Guardium database vulnerability scan results with ServiceNow. |   | Partner |
| CyCognito | [CyCognito App for Vulnerability Response](https://store.servicenow.com/store/app/fc4c2f6e1b246a50a85b16db234bcb98) | Vulnerability Response | Import issues and assets from Cycognito SAAS platform. |   | Partner |
| VMware | Carbon Black Cloud | Vulnerability Response | Ingest vulnerability data and context from Carbon Black Cloud. Create configuration items from Carbon Black Cloud endpoints and workload. |   | Partner |
| Nucleus | [Nucleus Security for Vulnerability Response](https://store.servicenow.com/store/app/4aaaef661b246a50a85b16db234bcbab) | Vulnerability Response | * Import findings from Nucleus Security Auto-update Vulnerable Items. * Bi-directional update via comments field. * Map custom fields. {#integrating-usem__ul_g2l_f21_hhc} |   | Partner |
| InfoSec Global (ISG) | [InfoSec Global (ISG) AgileSec Analytics Integration for Vulnerability Response Module](https://store.servicenow.com/store/app/9d4bef2a1b246a50a85b16db234bcb30) | Vulnerability Response | Import vulnerability findings on Cryptographic assets: Cryptographic Keys, Keystores, and Libraries |   | Partner |
| Censys | [Censys ASM to Vulnerability Response Integration](https://store.servicenow.com/store/app/68603be21ba46a50a85b16db234bcba1) | Vulnerability Response | Scan, discover, and catalog vulnerabilities on internet-facing assets. |   | Partner |
| Import container findings, vulnerabilities, and images ||||||
| Palo Alto | [Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute](https://store.servicenow.com/store/app/e95be36a1b246a50a85b16db234bcbf6) | Container Vulnerability Response | Ingest container vulnerabilities from Prisma Cloud Compute (formerly Twistlock) and use runtime context (cluster/ namespace and so on) to automate remediation workflow. | [Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute integration](https://www.servicenow.com/docs/feo76oCpZ9k2a_r4hRZS4Q "The Prisma Cloud Compute integration enables you to scan container images to detect vulnerabilities.") | ServiceNow |
| Aqua | [Aqua Security Platform integration with Vulnerability Response for Containers](https://store.servicenow.com/store/app/fedb6fea1b246a50a85b16db234bcb7c) | Container Vulnerability Response | Import container vulnerabilities from Aqua Platform. Docker and MID Server support. |   | Partner |
| AWS | [AWS Integration for Security Exposure Management](https://www.servicenow.com/docs/wW4GccMDUaNK4S3r2teVHQ "AWS Integration for Security Exposure Management connects your AWS environment to your ServiceNow AI Platform, enabling you to import security findings from AWS Inspector and AWS Security Hub.") |   |   |   |   |
| Sysdig | [Sysdig Container Vulnerability Response](https://store.servicenow.com/store/app/cf3927ae1be06a50a85b16db234bcba0) | Container Vulnerability Response | Import container vulnerabilities from Sysdig. Supports VI granularity, container, kubernetes, and host security |   | Partner |
| Lacework | Lacework | Container Vulnerability Response | Import container vulnerabilities and attempt to match based on docker configuration items (CIs). Supports vulnerability calculator and filtering by severity. |   | Partner |
| WIZ | [Wiz Integration for Container Vulnerability Response](https://store.servicenow.com/store/app/225b676a1b246a50a85b16db234bcb18) | Container Vulnerability Response | Import all container vulnerabilities from Wiz. | [Exploring the Wiz Container Vulnerability Integration](https://www.servicenow.com/docs/9M6cdz~scnndUUmLqfBnVA "Import container vulnerability data with the Wiz Container Vulnerability Integration that is included with the Wiz Vulnerability Response Integration.") | Partner |
| Qualys | [Qualys Container Vulnerability Response Integration](https://store.servicenow.com/store/app/c309276e1be06a50a85b16db234bcbb8) | Container Vulnerability Response | Import all container vulnerabilities from QCS. |   | Partner |
| CrowdStrike | [CrowdStrike Falcon Cloud security for Container Vulnerability Response](https://store.servicenow.com/store/app/10728f441b9dea10a85b16db234bcb4e) | Container Vulnerability Response | Import all container vulnerabilities from FCS. |   | Partner |
| Solution Intelligence ||||||
| Microsoft | [Vulnerability Solution Management](https://store.servicenow.com/store/app/8f2e6b2a1b646a50a85b16db234bcb2a) | Vulnerability Response - Content | Provides solution content for vulnerabilities. | [Microsoft Security Response Center Solution Integration](https://www.servicenow.com/docs/uGtfwU~G6AAnO0qVqVqlIw "Review and implement proposed remediation solutions provided by the Microsoft Security Response Center Solution Integration.") | ServiceNow |
| Red Hat | Red Hat Security Data | Vulnerability Response - Content | Provides solution content for vulnerabilities. | [Red Hat Solution Integration](https://www.servicenow.com/docs/xUvrbI_CMogxDoUVYfaPXw "You can review and implement proposed remediation solutions provided by the Red Hat Solution Integration in the Vulnerability Response application.") | ServiceNow |
| Rapid 7 | [Rapid7 Integration for Security Operations](https://store.servicenow.com/store/app/b349ebae1be06a50a85b16db234bcbb6) | Vulnerability Response - Content | Provides solution content for vulnerabilities. | [Rapid7 solution management](https://www.servicenow.com/docs/VC_RdvhWFrFDUBuf3qNyNg "Solutions are known remediations that are imported into your Rapid7 Vulnerability Integration from either the Rapid7 data warehouse or Rapid7 InsightVM. Rapid7 data warehouse imports both solutions and superseding solutions. With Rapid7 InsightVM, you get solutions as part of the Rapid7 Vulnerable Item Integration - API.") | ServiceNow |
| Tanium | [Tanium Vulnerability Management](https://store.servicenow.com/store/app/b13aafe21b246a50a85b16db234bcb0e) | Vulnerability Response - Content | Provides solution content for vulnerabilities. |   | Partner |
| CVRF Generic Framework | Supports CVRF Format | Vulnerability Response - Content | Provides solution content for vulnerabilities. | * [Generic framework to ingest data from any solution vendor](https://www.servicenow.com/docs/JUk972xTDCB30ypoWZBzig "A generic framework for solution intelligence integration is available to support ingestion of data in different file formats from solution vendors. These formats speed up information exchange and processing and facilitate the sharing of critical security-related information in a standardized reporting format.") * [Setting up vulnerability solution providers](https://www.servicenow.com/docs/1nV3xX2Vyvf6J6y~hOfwBQ "Set up vulnerability solution providers by following the checklist and then configuring the providers in the Setup Assistant.") {#integrating-usem__ul_zv1_frc_hhc} | ServiceNow |
| CSAF Generic Framework | Supports CSAF Format | Vulnerability Response - Content | Provides solution content for vulnerabilities. | * [Generic framework to ingest data from any solution vendor](https://www.servicenow.com/docs/JUk972xTDCB30ypoWZBzig "A generic framework for solution intelligence integration is available to support ingestion of data in different file formats from solution vendors. These formats speed up information exchange and processing and facilitate the sharing of critical security-related information in a standardized reporting format.") * [Setting up vulnerability solution providers](https://www.servicenow.com/docs/1nV3xX2Vyvf6J6y~hOfwBQ "Set up vulnerability solution providers by following the checklist and then configuring the providers in the Setup Assistant.") {#integrating-usem__ul_bzg_mrc_hhc} | ServiceNow |
| Vulnerability enrichment and threat scoring ||||||
| Recorded Future | Vulnerability Intelligence | Vulnerability Response - Intelligence | Use Recorded Future vulnerability intelligence to prioritize vulnerabilities. |   | Partner |
| Flashpoint | [Flashpoint Ignite for Vulnerability Response](https://store.servicenow.com/store/app/d54e236a1b646a50a85b16db234bcbdb) | Vulnerability Response - Intelligence | Consume alerts as security incidents (email), Import TI and vulnerability context. |   | Partner |
| Cisco (Kenna) | [Kenna.VI+ (Kenna Vulnerability Intel)](https://store.servicenow.com/store/app/d5c92b621b246a50a85b16db234bcbb0) | Vulnerability Response - Intelligence | Use Kenna.vi vulnerability intelligence to prioritize vulnerabilities. |   | Partner |
| Risk Based Security by Flashpoint | [Flashpoint VulnDB](https://store.servicenow.com/store/app/bb3ceb6e1b246a50a85b16db234bcba4) | Vulnerability Response - Intelligence | Import RBS records into third-party vulnerabilities. Risk scores and software-based vulnerability matching. |   | Partner |
| Digital Shadows (Grey Matter by Reliaquest) | [GreyMatter Digital Risk Protection Vulnerability Intelligence for Vulnerability Response](https://store.servicenow.com/store/app/6f7d2b261b646a50a85b16db234bcb86) | Vulnerability Response - Intelligence | Prioritize vulnerabilities using Digital Shadows risk factors and scoring based on analyst-curated threat intelligence. |   | Partner |
| Mandiant \| Google | [Google Threat Intelligence for SecOps](https://store.servicenow.com/store/app/07f781de4798bed4392d3369126d4370) | Vulnerability Response - Intelligence | Enriches vulnerability item records with Mandiant vulnerability intelligence for better prioritization. |   | Partner |
| CISA | [Vulnerability Response Integration with CISA](https://store.servicenow.com/store/app/02ea27e61b246a50a85b16db234bcb2e) | Vulnerability Response - Intelligence | Use known exploitedvulnerabilities. Catalog to prioritize vulnerabilities. | [CISA Known Exploit Vulnerability (KEV) Integration](https://www.servicenow.com/docs/h~5vrVBtkzuhGX_VN9~5QQ "The Vulnerability Response integration with the CISA Known Exploited Vulnerabilities (KEVs) catalog ingests data to help you effectively prioritize and remediate these vulnerabilities.") | ServiceNow |
| First.org | EPSS | Vulnerability Response - Intelligence | Use the Exploit prediction scoring system to prioritize vulnerabilities. | [Understanding the Exploit Prediction Scoring System (EPSS) integration](https://www.servicenow.com/docs/FPlArdjh_yoBuL_8ZBa2TA "Overview of the EPSS integration with Vulnerability Response.") | ServiceNow |
| XM Cyber | [XM Cyber - Vulnerability Response](https://store.servicenow.com/store/app/d8f9a7a21b246a50a85b16db234bcbac) | Vulnerability Response - Intelligence | Asset Ingestion Link Additional Risk Data Application Risk Measures |   | Partner |
| Zafran | [Zafran Threat Exposure Management Platform](https://store.servicenow.com/store/app/ccebefea1b246a50a85b16db234bcb21) | Vulnerability Response - Intelligence | Ingest vulnerabilities from scanning tools, provide Zafran enrichment and then link to vulnerable items in Vulnerability Response. Intelligence includes mitigation factors, internet-facing, and custom risk score. |   | Partner |
| Armis | Early Warning for Security Exposure Management | Vulnerability Response - Intelligence | Enrich vulnerability entries with intelligence on imminent exploitation, so you can prioritize CVEs that threat actors are actively targeting. | [Early Warning for Security Exposure Management](https://www.servicenow.com/docs/HTx5A9NBq3njWqlGOA64AQ "Early Warning for Security Exposure Management, powered by Armis, enriches the Central Vulnerability Database (CVDB) in Unified Security Exposure Management (USEM) with vulnerability intelligence of imminent exploit. This enables your security team to prioritize and patch vulnerabilities before threat actors weaponize them.") | ServiceNow |
| Armis | Fix Intelligence for Security Exposure Management | Vulnerability Response - Intelligence | Enrich host findings with normalized fix information from Armis Centrix™ for ViPR, and remediate by fix instead of one finding at a time. | [Fix Intelligence for Security Exposure Management](https://www.servicenow.com/docs/spSTSACGMs2oIdsifUUX3Q "Fix Intelligence for Security Exposure Management brings fix and remediation intelligence from Armis Centrix™ for Vulnerability Prioritization and Remediation (ViPR) into Unified Security Exposure Management (USEM), so your security team can remediate vulnerabilities by fix instead of one finding at a time.") | ServiceNow |
| Patch orchestration in solution management ||||||
| Microsoft | [Vulnerability Response Patch Orchestration with Microsoft SCCM](https://store.servicenow.com/store/app/c1dbabea1b246a50a85b16db234bcbdf) | Vulnerability Response - Patching | Ingest the patch details and correlate the patch, solution, and asset details to suggest Security and IT which assets are missing patches. | [Vulnerability Response patch orchestration integration with Microsoft SCCM](https://www.servicenow.com/docs/PZV21C07W_aS_du2IqIsmA "The Vulnerability Response integration with the Microsoft System Center Configuration Manager (SCCM) supports patch management and deployment for critical vulnerabilities across your assets.") | ServiceNow |
| HCL | [Vulnerability Response Patch Orchestration with HCL Bigfix](https://store.servicenow.com/store/app/02196b6e1be06a50a85b16db234bcb05) | Vulnerability Response - Patching | Ingest the patch details and correlate the patch, solution, and asset details to suggest Security and IT which assets are missing patches. | [Understanding the HCL BigFix patch orchestration integration with Vulnerability Response](https://www.servicenow.com/docs/h73nSOqPqd59_wefnz5Itg "You can manage patches and patch deployments for critical vulnerabilities for large groups of assets with the Vulnerability Response patch orchestration integration with the HCL BigFix product.") | ServiceNow |
| Tanium | [Tanium Patch Management for Vulnerability Response](https://store.servicenow.com/store/app/b41a63e21b246a50a85b16db234bcb1e) | Vulnerability Response - Patching | Patches CIs through the Vulnerability Response Patch Orchestration module. This can be used in addition to the Tanium VR integration to close the loop from identifying vulnerabilities with Tanium Comply to patching those vulnerabilities with Tanium Patch. |   | Partner |
| Import test, policies, results ||||||
| Qualys | [Qualys Integration for Security Operations](https://store.servicenow.com/store/app/9f3b6f2a1b246a50a85b16db234bcb13) | Configuration Compliance | Import test, policies, results. | [Qualys integration with Configuration Compliance](https://www.servicenow.com/docs/bUb_bXtlfalvZI2LbIyoeA "The Qualys Policy Compliance collects the data and automatically sends it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates as the Qualys Integration for Security Operations to map configuration findings to CIs and business services to determine the impact and priority of potential misconfigurations.") | ServiceNow |
| Qualys | [Qualys CSPM Integration](https://store.servicenow.com/store/app/8cfda1d71b792210f4b3dc28b04bcbcc) | Configuration Compliance | Import test, policies, results. |   | Partner |
| AWS | [AWS Integration for Security Exposure Management](https://www.servicenow.com/docs/wW4GccMDUaNK4S3r2teVHQ "AWS Integration for Security Exposure Management connects your AWS environment to your ServiceNow AI Platform, enabling you to import security findings from AWS Inspector and AWS Security Hub.") |   |   |   |   |
| Tenable | [Vulnerability Response Integration with Tenable](https://store.servicenow.com/store/app/861aa3e21b246a50a85b16db234bcb7c) | Configuration Compliance | Import test, policies, results. | [Understanding the Tenable Vulnerability Integration](https://www.servicenow.com/docs/LBEiVzZ9snj0he1KfeiBpw "The Vulnerability Response Integration with Tenable application developed by ServiceNow engineering for the Tenable Vulnerability Integration uses data imported from the Tenable.io, Tenable.sc, and Tenable.cs products to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.") | ServiceNow |
| Tanium | [Tanium Configuration Compliance Integration](https://store.servicenow.com/store/app/19517b2a1ba46a50a85b16db234bcb87) | Configuration Compliance | Import test, policies, results. |   | Partner |
| Palo Alto Networks | [Expander Configuration Compliance](https://store.servicenow.com/store/app/c3d9ef621b246a50a85b16db234bcb8d) | Configuration Compliance | Import attack surface and alerts from Expander. |   | Partner |
| Trend Micro | [Conformity Connector](https://store.servicenow.com/store/app/bc1e632a1b646a50a85b16db234bcb36) | Configuration Compliance | Import misconfiguration and test results from Trend Micro Cloud One into ServiceNow. |   | Partner |
| Import cloud misconfiguration data (Cloud Security) ||||||
| Microsoft | Defender for Endpoint | Configuration Compliance | Import test, policies, results. |   | ServiceNow |
| Microsoft | [Microsoft Defender for Security Exposure Management](https://store.servicenow.com/store/app/df09276e1be06a50a85b16db234bcbe5) | Configuration Compliance | Import the cloud resource configuration issues from Microsoft Defender for Cloud and automate remediation workflow. | [Understanding the Microsoft Defender for Cloud integrations for Security Exposure Management](https://www.servicenow.com/docs/jU7BeWoduINzGBT6eWdW8A "The Microsoft Defender for Cloud integrations included with the Microsoft Defender Integration for Security Exposure Management application import cloud misconfiguration findings, compliance data, and container image vulnerabilities.") | ServiceNow |
| Palo Alto | [Vulnerability Response Integration with Palo Alto Prisma Cloud](https://store.servicenow.com/store/app/b139a3ae1be06a50a85b16db234bcbd0) | Configuration Compliance | Import the cloud resource configuration issues from Prisma Cloud (formerly RedLock) and automate remediation workflow. | [Understanding the Vulnerability Response Integration with Palo Alto Prisma Cloud](https://www.servicenow.com/docs/b~3N4XAiR~i71CplBDnVqA "Prisma Cloud is an API-based cloud infrastructure security solution. It connects to your cloud environment and monitors the resources deployed on the public cloud environments, such as Amazon Web Services (AWS), Microsoft Azure, and so on. You get complete visibility and control over risks within your public cloud infrastructure.") | ServiceNow |
| Wiz | [Wiz Integration for Configuration Compliance](https://store.servicenow.com/store/app/81d96f621b246a50a85b16db234bcb56) | Configuration Compliance | Import the cloud resource configuration issues from Microsoft Defender for Cloud and automate remediation workflow. | [Exploring the Wiz Test Results and Issues Integrations with Configuration Compliance](https://www.servicenow.com/docs/~1nzZKczPVfUwpmiahlKpw "Import cloud configuration data with the Wiz Test Results and Issues Integrations with Configuration Compliance that are included with the Wiz Vulnerability Response Integration.") | Partner |
| Rapid7 | [Rapid7 InsightCloudSec CC Integration](https://store.servicenow.com/store/app/b04f67ae1b646a50a85b16db234bcb97) | Configuration Compliance | Import cloud misconfigurations and compliance issues |   | Partner |
| Lacework | Lacework Code to Cloud | Configuration Compliance | Import cloud misconfigurations and compliance issues. |   | Partner |
| AWS | [AWS Integration for Security Exposure Management](https://www.servicenow.com/docs/ReMFWrz6tFB2oqsmnih35A "Integrations, roles, dependencies, and REST messages used for the AWS Integration for Security Exposure Management.") |   |   |   |   |
| Import dynamic, static analysis results and SCA ||||||
| Veracode | [Vulnerability Response Integration with Veracode](https://store.servicenow.com/store/app/e109a36e1be06a50a85b16db234bcbc7) | Application Vulnerability Response | Import test, policies, results, DAST findings, SAST findings and SCA findings. | [Veracode Vulnerability Integration](https://www.servicenow.com/docs/UaJdOAyH3lz8Z703obNHTg "The Vulnerability Response Integration with Veracode application uses data imported from the Veracode product to help you determine the impact and priority of flaws in your code.") | ServiceNow |
| Qualys WAS | [Vulnerability Response Integration with Qualys WAS](https://store.servicenow.com/store/app/be6e2f6a1b646a50a85b16db234bcbb1) | Application Vulnerability Response | Import Dynamic Scan results from Qualys WAS application. |   | Partner |
| Microfocus Fortify | [Fortify Application Vulnerability Integration](https://store.servicenow.com/store/app/e1a9af221b246a50a85b16db234bcbbe) | Application Vulnerability Response | Import DAST and SAST findings. | [Fortify Vulnerability Integration](https://www.servicenow.com/docs/Ua~e5pANzgi~D2xgaYrzcw "The Fortify Vulnerability Integration uses data imported from the Fortify product to help you determine the impact and priority of flaws in your code.") | ServiceNow |
| Snyk | [Snyk Security for Application Vulnerability Response](https://store.servicenow.com/store/app/bc2ae7e21b246a50a85b16db234bcb88) | Application Vulnerability Response | Import SCA and SAST findings. |   | Partner |
| Open source vulnerability intelligence (SBOM workflows) ||||||
| Snyk | [Snyk API and Web for Application Vulnerability Response](https://store.servicenow.com/store/app/0a5317329797ea103fa8b84bf253afe4) | Application Vulnerability Response | Web App Scanning findings API Security findings |   | ServiceNow |
| GitHub | [Github Application Vulnerability Integration](https://store.servicenow.com/store/app/006dafe21b646a50a85b16db234bcba2) | Application Vulnerability Response | Code Scanning Secret Scanning Dependabot alerts. | [GitHub Application Vulnerability Integration](https://www.servicenow.com/docs/MbOi_yWO4ClJ8gEPxICBWw "The GitHub Application Vulnerability Integration imports Static application security testing (SAST) and Software Composition Analysis (SCA) data to help you view vulnerability alerts in the repositories in your GitHub environment.") | ServiceNow |
| HCL AppScan | [Vulnerability Response Integration with HCL AppScan](https://store.servicenow.com/store/app/a73a23261b246a50a85b16db234bcb3b) | Application Vulnerability Response | Import Dynamic Scan results from HCL AppScan. |   | Partner |
| Checkmarx | [Checkmarx CxSAST Vulnerability Integration](https://store.servicenow.com/store/app/cf19ab6e1be06a50a85b16db234bcb55) | Application Vulnerability Response | Import SAST findings. Note: Uses CxSAST API. |   | Partner |
| Checkmarx | [Checkmarx One Vulnerability Integration](https://store.servicenow.com/store/app/cbc8efea1be06a50a85b16db234bcb97) | Application Vulnerability Response | Import SAST and SCA findings from Cx VulnerabilityOne API. |   | Partner |
| Invicti | [Invicti Application Vulnerability Integration](https://store.servicenow.com/store/app/12e18770473176d095ebf235126d4324) | Application Vulnerability Response | * Import applications, scan summaries, results * Import IAST findings. * Import SAST findings. {#integrating-usem__ul_sn5_vf1_hhc} | [Invicti Vulnerability Integration](https://www.servicenow.com/docs/Mu_fL94Ze3w7jH6sd6KtZg "The Invicti Vulnerability Integration uses application data imported from the Invicti product to help you determine the impact and priority of flaws in your code.") | ServiceNow |
| Synopsys | [Vulnerability Response Integration with Black Duck](https://store.servicenow.com/store/app/c7b3d2a293d72a10a0f2fc1d6cba10a3) | Application Vulnerability Response | Import SCA findings. | [Vulnerability Response Integration with Black Duck](https://www.servicenow.com/docs/JqhOcjL1NmWv7pQUNe5ODg "The Vulnerability Response integration with Vulnerability Response Integration with Black Duck uses the data that is imported from the Black Duck Software Composition Analysis (SCA) tool to help you determine the impact and priority of the flaws in your code.") | ServiceNow |
| Sonatype | [Sonatype Security for Application Vulnerability Response](https://store.servicenow.com/store/app/fb6aef261b246a50a85b16db234bcb0e) | Application Vulnerability Response | SCA -- import open source vulnerabilities from Sonatype Lifecycle product. |   | Partner |
| Apiiro | [Apiiro ASPM for Application Vulnerability Response](https://store.servicenow.com/store/app/945d2be21b646a50a85b16db234bcb5f) | Application Vulnerability Response | Application Security Posture Management vulnerabilities, fix issues by assigning to code owners [CMDB App](https://store.servicenow.com/store/app/c3be7a921bd666d02ca2a643604bcb80) is also available. |   | Partner |
| Rapid7 | [Rapid7 InsightAppSec Application VR Integration](https://store.servicenow.com/store/app/335dafe21b646a50a85b16db234bcb73) | Application Vulnerability Response | Fetch apps, scans, vulnerabilities, attacks, attack modules into ServiceNow Vulnerability Response. Web application scanning results. |   | Partner |
| NoName (by Akamai) | [Akamai API Security Integration for AVR](https://store.servicenow.com/store/app/3432376e1ba46a50a85b16db234bcb03) | Application Vulnerability Response | Create and update vulnerable items from NoName on API detections. |   | Partner |
| Tenable | Tenable WAS | Application Vulnerability Response | Application security findings. |   | Partner (Tenable) |
| Snyk | [Snyk Vulnerability Intelligence for SBOM](https://store.servicenow.com/store/app/994d67e21b646a50a85b16db234bcb56) | Application Vulnerability Response - SBOM | Vulnerability Intelligence on Open-source components in SBOM. |   | Partner |
| Google (open source) | [SBOM Response](https://store.servicenow.com/store/app/0bd8e32e1be06a50a85b16db234bcba1) | Application Vulnerability Response - SBOM | Vulnerability intelligence information for a given version of a package or library. |   | ServiceNow |
| Google (open source) | [SBOM Response](https://store.servicenow.com/sn_appstore_store.do#!/store/application/6e1505c977007110adaf0da3fa5a99e1/3.0.3?referer=/store/search?listingtype=allintegrations%253Bancillary_app%253Bcertified_apps%253Bcontent%253Bindustry_solution%253Boem%253Butility%253Btemplate%253Bgenerative_ai%253Bsnow_solution&q=osv&sl=sh) | Application Vulnerability Response - SBOM | License and dependency information for a given version of a package or library. |   | ServiceNow |
| Veracode | [Vulnerability Response Integration with Veracode](https://store.servicenow.com/store/app/e109a36e1be06a50a85b16db234bcbc7) | Application Vulnerability Response - SBOM | * Upload exported vulnerabilities to create AVITs. * Prioritize by NVD severity. {#integrating-usem__ul_oxc_3g1_hhc} |   | ServiceNow |
| Agile task creation for remediation ||||||
| Atlassian | [Vulnerability Response Integration with Atlassian Jira](https://store.servicenow.com/store/app/a83a2fe21b246a50a85b16db234bcb22) | Vulnerability Response - Agile Tools | Create Jira tasks/ issues for Application and Container vulnerabilities. Bi-directional status updates between Vulnerability Response and Jira. | [Understanding the Atlassian Jira integration with Vulnerability Response](https://www.servicenow.com/docs/cmCLwGl6beN5RwzHfE0PQw "The Atlassian Jira integration with Vulnerability Response enables you to leverage different issue-tracking and agile management tools for tracking efforts of vulnerability remediation.") | ServiceNow |
[Table 1. Integrations]

{#integrating-usem__table_cyh_1yv_t2c}

## Custom integrations {#integrating-usem__section_v1z_dy2_dbb}

You can manually create integrations not available in the ServiceNow Store. See [Manually create a vulnerability integration](https://www.servicenow.com/docs/N~R2nD9HvzuqZOO8dB1KFg "Vulnerability integrations provide the ability for customers and vendors to enrich the vulnerability data on their instance by retrieving data from external systems and vendors. This ability can simplify the vulnerability remediation life cycle by keeping the instance synchronized with other vulnerability management systems.") for more information.

## Configuring and managing integrations {#integrating-usem__section_aw5_cnz_wvb}

* You can install, configure, schedule, and launch many integration applications.
* For integrations supporting multiple deployments, refer to [Create domain-separated imports for an integration](https://www.servicenow.com/docs/0N9JZHv_nZJYrkMbQYSBbQ "If you require imported data to be in a specific domain, the user assigned to run the integrations must belong to that domain.").
* The Rapid7 Vulnerability Integration application can be installed from Setup Assistant, but its configuration isn't supported within Setup Assistant. See [Install the Rapid7 Vulnerability Integration](https://www.servicenow.com/docs/8QYrJRzRRzMx_oecEzk4tw "After you complete the set up steps for the integration so that it properly integrates with Vulnerability Response, get entitlements, download, and install the application on your ServiceNow AI Platform instance.") for more information. You can install, configure, schedule, and launch on-demand many of the integration applications from within Setup Assistant.
{#integrating-usem__ul_ev2_rlz_wvb}

## Performance and timeout handling {#integrating-usem__section_bv1_xgj_dhc}

During integration execution, multiple processes are generated, and data is received in the form of pages. Each process can contain one or more import queue entries with attached data in pages. These entries must process the data within the one-hour time limit. However, if the payload size is large, the processing time may exceed one hour or get stuck, resulting in an integration timeout error. The integration continues to process the data despite the timeout error. To avoid this miscommunication, timestamps (heartbeats) are sent periodically to indicate if the queue is active and processing data. The Last Record Processed field in the Import Queue Entry page is updated based on the count of records the import queue creates or updates. In case an import queue entry exceeds the one-hour time limit, the system checks the Last Record Processed field to see if it's also older than one hour. If it is, this indicates that the import queue entry is stuck, and it's timed out to prevent any further delays in processing.  
Note:  
The Last Record Processed field is updated based on what is defined in the following system properties:

* sn_sec_cmn.record_threshold_heartbeat: Defines the number of processed records, after which the heartbeat (timestamp) is sent to the import queue entry.
* sn_sec_cmn.maximum_heartbeat_delay: Defines the time after which the import queue entry must be timed out.
{#integrating-usem__ul_g23_sgw_dyb}
* **[Review Unified Security Exposure Management integrations](https://www.servicenow.com/docs/n9CV2GWwldUPDJklm6Yxww)**   
  The integration dashboard provides an overview of the installed third-party applications and the status of the integration runs.
* **[Early Warning for Security Exposure Management](https://www.servicenow.com/docs/HTx5A9NBq3njWqlGOA64AQ)**   
  Early Warning for Security Exposure Management, powered by Armis, enriches the Central Vulnerability Database (CVDB) in Unified Security Exposure Management (USEM) with vulnerability intelligence of imminent exploit. This enables your security team to prioritize and patch vulnerabilities before threat actors weaponize them.
* **[Fix Intelligence for Security Exposure Management](https://www.servicenow.com/docs/spSTSACGMs2oIdsifUUX3Q)**   
  Fix Intelligence for Security Exposure Management brings fix and remediation intelligence from Armis Centrix™ for Vulnerability Prioritization and Remediation (ViPR) into Unified Security Exposure Management (USEM), so your security team can remediate vulnerabilities by fix instead of one finding at a time.

**Related concepts**   

* [Review Unified Security Exposure Management integrations](https://www.servicenow.com/docs/n9CV2GWwldUPDJklm6Yxww "The integration dashboard provides an overview of the installed third-party applications and the status of the integration runs.")

