Integrating Application Vulnerability Response with other applications
Summarize
Summary of Integrating Application Vulnerability Response with Other Applications
Application Vulnerability Response supports third-party integrations to enhance vulnerability data by retrieving information from external systems and vendors. Key integrations include Fortify, GitHub, Invicti, Veracode, and Atlassian Jira. Note that multi-source integrations are not supported, and there is no deduplication of application vulnerable items across different integrations.
Show less
Key Features
- Manual Ingestion: Users can manually create agile issues in the Vulnerability Manager Workspace to track remediation efforts.
- Data Processing: Each integration executes multiple processes, managing data in pages. Import queue entries must process within a one-hour limit, with mechanisms in place to handle timeout errors.
- Timestamps and Heartbeats: Starting from version 18.2.4, heartbeats are sent periodically to indicate active processing, helping to manage integration health.
- Scheduled and Manual Runs: Integrations are configured to run on a schedule but can also be executed manually as needed by users with the appropriate role.
Key Outcomes
By leveraging these integrations, ServiceNow customers can efficiently manage and respond to application vulnerabilities, ensuring timely data processing and improved tracking of remediation efforts. Regular updates and monitoring allow for proactive management of potential issues within the application landscape.
Vulnerability Response includes support for third-party integrations.
Third-party integrations
- Fortify Vulnerability Integration
- GitHub Application Vulnerability Integration
- Invicti Vulnerability Integration
- Veracode Vulnerability Integration
- Manual ingestion of vulnerabilities for Application Vulnerability Response
- Atlassian Jira IntegrationImportant:In the Vulnerability Manager Workspace, you can create an agile issue manually using the list action and form action to track the remediation of AVITs and RTs.
Multi-source integrations are not supported in Application Vulnerability Response. Third-party integrations are treated separately. If more than one third-party integration application is in use in your environment, there is no application vulnerable item (AVI) deduplication across integrations.
Additional notes for integrations
- sn_sec_cmn.record_threshold_heartbeat: Defines the number of processed records, after which the heartbeat (timestamp) is sent to the import queue entry.
- sn_sec_cmn.maximum_heartbeat_delay: Defines the time after which the import queue entry must be timed out.
Vulnerability integrations for Application Vulnerability Response are configured to run on a scheduled basis. However, you can run them manually when needed.
Role required: sn_vul.app_read_integrations
- Navigate to .
- Open the record for the integration that you want to run.
- Click Execute Now.