Tenable.sc integrations with the Vulnerability Response application
Summarize
Summary of Tenable.sc Integrations with the Vulnerability Response Application
The Tenable.sc integrations with the Vulnerability Response application enable seamless vulnerability management by importing and processing vulnerability data from Tenable.sc within your ServiceNow environment. With the introduction of Vulnerability Response v20.0, assets scanned by an agent are clearly identified as "true" in the Discovered Items list, confirming the authenticity of the scan.
Show less
Key Features
- Multi-source Support: You can deploy multiple instances of Tenable.io and Tenable.sc integrations via the Setup Assistant.
- Integration Types:
- Assets Integration: Prevents duplicate discovered items and imports vulnerability data categorized as Open or Fixed.
- Plugin Integration: Ensures current vulnerability data by importing active plugins from Tenable.sc.
- Fixed Vulnerabilities Integration: Processes vulnerabilities based on severity and updates existing vulnerable items when detections are Fixed, with an option to create new entries.
- Open Vulnerabilities Integration: Activated post Fixed Vulnerabilities Integration, it imports active vulnerabilities and updates or creates vulnerable items accordingly.
- Scan Credential Integration: Retrieves and manages scan credentials required for initiating scans from ServiceNow.
- Backfill Vulnerabilities Integration: Imports any missed open and fixed vulnerabilities from the last week to ensure comprehensive data coverage.
- User Authentication: Supported for Tenable.sc version 5.13 and requires user authentication for earlier versions. Tokens are automatically refreshed in the background during integration runs.
Key Outcomes
By utilizing the Tenable.sc integrations, ServiceNow customers can effectively manage and respond to vulnerabilities across their environment. These integrations facilitate accurate data imports, ensure timely updates of vulnerability statuses, and help maintain comprehensive visibility into security postures. The automated handling of tokens and scheduled runs further enhances integration reliability and performance management.
The Tenable.sc integrations in the Vulnerability Response Integration with Tenable application.
Starting with Vulnerability Response v20.0, if an asset is scanned by an agent, the "Agent exists" column in the Discovered Items list displays the value as "true." This indicates that the scan is authentic.
List of Tenable.sc integrations
Multi-source is supported for all the Tenable.io and Tenable.sc integrations. You can add and deploy multiple instances of the following integrations across your environment from Setup Assistant in Vulnerability Response. You can also install and configure the Vulnerability Response Integration with Tenable application from Setup Assistant.
- Tenable.sc is an on-premises integration that gives you the option to use a MID Server if the Tenable.sc product and your ServiceNow AI Platform instance are in the same environment.
- If the Tenable.sc product and your ServiceNow AI Platform instance aren’t in the same environment, you’re required to use a MID Server.
| Integration | Description |
|---|---|
| Tenable.sc Assets Integration |
To avoid creating duplicate discovered items with imported asset data, the Asset Integration of the Tenable.sc product is comprised of two integrations.
|
| Tenable.sc Plugin Integration |
|
| Tenable.sc Fixed Vulnerabilities Integration |
The output of this integration is Closed/Fixed vulnerable items (VIs). It also creates assets and third-party entries if they don't exist. This integration run is a scheduled run. It’s a chained integration which means after a run is successfully completed, the Tenable.sc Open Vulnerabilities Integration described next is triggered. Note:
By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Open Vulnerabilities Integration |
Note:
By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Scan Credential Integration |
|
| Tenable.sc Backfill Vulnerabilities Integration |
|
User authentication and Tenable.sc
User authentication is supported by your ServiceNow AI Platform® instance and version 5.13 of the Tenable.sc product. User authentication is required if you’re using version 5.12 and earlier of the Tenable.sc product.
When you select user authentication for the Tenable.sc integrations, tokens might expire and be replaced during integration runs. In the Notes column on the Vulnerability Integration Run record (VIN), the following message is displayed for a process when a token expires, Error: Token validation is failed. No action is required if this message is displayed. Expired tokens are automatically refreshed in the background and the message doesn’t indicate a pause or error with the integration process.