Using generative AI skills
Summarize
Summary of Using generative AI skills
Generative AI skills in ServiceNow assist vulnerability managers, analysts, and security teams by providing automated insights, recommendations, and data analysis to streamline remediation tasks within their workflows. Access to these AI capabilities depends on your ServiceNow license and product tier. AI skills operate within domain-separated environments, ensuring data privacy by restricting AI-generated outputs to the user's domain data, without co-mingling or persisting prompts and responses outside the instance.
Show less
Key Features
- Security Exposure 360: Allows users to query vulnerability exposure data in plain language and receive detailed answers about host, container, and test result findings.
- AI Guardrails Helper Skill and Agentic Workflow: Helps identify finding types, mapped guardrails, and rationale behind mappings to determine mitigated or deferred findings (supported only in USEM workspace).
- Vulnerability Insights: Provides contextual summaries and actionable recommendations to better understand and prioritize security posture.
- Exception and False Positive Approval Recommendations: Offers on-demand recommendations to streamline approval workflows for exceptions and false positives.
- API Connector Builder Assistance: Uses generative AI to automate creation steps in the API Connector builder, requiring specific application installations.
- Duplicate Vulnerable Item Identification: Detects and groups duplicate vulnerable items from multiple scanners, helping managers identify primary items and close duplicates.
- Vulnerability Solution Suggestions: Recommends the most appropriate preferred solutions for active host vulnerable items, leveraging the Vulnerability Solution Management application and imported third-party solutions.
- Approval Impact Analysis Recommendations: Provides AI-driven guidance to streamline approval processes for exceptions and false positive requests.
Practical Benefits for ServiceNow Customers
- Improved efficiency and accuracy in vulnerability management through AI-augmented analysis and recommendations.
- Enhanced security posture visibility with AI-generated insights tailored to specific domain data.
- Automated support for complex tasks such as API connector creation and duplicate vulnerability resolution.
- Streamlined exception and false positive approvals with AI-driven suggestions, reducing manual effort.
- Integration with existing ServiceNow applications like Vulnerability Solution Management ensures up-to-date and actionable remediation options.
AI skills help vulnerability managers and analysts resolve remediation tasks within their flow of work by providing automated insights, recommendations, and data analysis.
Skills in global domain reuse
By default, all skills exist in the global domain. When you use AI in a domain-separated environment, users are only able to access data in their domain. For example, if a user uses the summarization skill, AI only uses material that exists in the user's domain when generating that summary. Additionally, there is no co-mingling of data for domain-separated instances when using generative AI skills. The data resides only on the instance, and the shared services used for generative AI do not persist any requests (prompts) and responses. For more information, see Domain separation in the Now Assist Admin console. (Note that global domain is not the same as global scope. For more information, see Exploring Next Experience pickers.)
Overview of available ServiceNow Otto for Unified Security Exposure Management skills
With generative AI skills with ServiceNow Otto for Unified Security Exposure Management, your vulnerability managers and analysts have the option to use generative AI skills to help them with the following tasks. Unless otherwise noted, these generative AI skills are supported in both the legacy and Unified Security Exposure Management (USEM) workspaces.
| Generative AI skill | Description | Users |
|---|---|---|
| Evaluate vulnerability exposure data with Security Exposure 360 | Enter questions in plain language to receive comprehensive answers about findings for host, container, and test results vulnerabilities. | Vulnerability managers and analysts |
| Using the AI guardrails helper skill and agentic workflow |
Identify finding types, understand mapped guardrails, and see why specific findings were selected for mapping. This information helps you determine which findings are already mitigated or deferred for later
review.
Note: Supported only in the Unified Security Exposure Management (USEM) workspace. |
Vulnerability analysts, vulnerability managers, and chief information security officers (CISOs) |
| Generate vulnerability insights with generative AI | Receive insights based on contextual summaries and see actionable recommendations. | Vulnerability managers and analysts |
| Get exception and false positive approval recommendations | Receive on-demand approval and false positive recommendations. | Exception and false positive approvers |
| Create an API connector with generative AI |
Automatically populate steps in the API Connector builder. Note:
You must install and activate the required applications and ServiceNow Otto for Unified Security Exposure Management to use the generative AI skill to help you create your own API connector. |
Developers in your organization, vulnerability and security admins |
| Identify duplicate vulnerable items with generative AI | Identify and group duplicate vulnerable items (VITs) created from multiple scanners. Identify the primary vulnerable item and remove (close) duplicates. | Vulnerability managers and analysts |
| Suggest vulnerability solutions with generative AI |
Identify the most appropriate preferred solution for a given vulnerable item (VIT). Requirements:
|
Vulnerability managers and analysts |
| Generate vulnerability insights with generative AI | Understand your security posture with AI-generated summaries and recommendations to help you prioritize and act on critical findings. | Vulnerability managers and analysts |
| Generate a recommendation for approval impact analysis | Streamline the approval process for exceptions and false positive requests with AI-driven recommendations. | Vulnerability managers and analysts |