Supporting information for Unified Security Exposure Management AI skills and agents
Summarize
Summary of Supporting information for Unified Security Exposure Management AI skills and agents
The Unified Security Exposure Management (USEM) application in ServiceNow provides AI-driven capabilities to enhance vulnerability and security exposure management. It integrates multiple applications and supports various user interfaces to help security teams analyze, prioritize, and remediate vulnerabilities effectively. This information highlights the required applications, supported versions, and core AI features available to users.
Show less
Required Applications and Versions
To fully utilize USEM, the following applications must be installed with specified minimum versions:
- ServiceNow Otto for Unified Security Exposure Management (v5.2.3)
- ServiceNow Otto® for platform [sngenaiplatform] (v12.2.0)
- Vulnerability Response Integration with CISA (v1.5.1)
- Vulnerability Response [snvul] and USEM-specific versions (v26.5.3 and v30.7.6)
- Vulnerability Response licensing and usage (v2.7.1)
- Vulnerability Response Common Workspace (v1.10.0)
- Vulnerability Response Integration Framework (v1.5.0)
- AI Security Exposure Management (v2.1.2)
- Vulnerability Solution Management (v10.4.3)
- Security Posture Control API Connectors and related applications for API Connector skill (v2.1.1 to v7.2.1)
These components collectively enable AI-powered insights and integrations essential for USEM functionality.
Supported User Interfaces and AI Skills
USEM supports multiple workspaces and interfaces, each equipped with generative AI skills and agents that assist security professionals:
- Vulnerability Manager Workspace: Allows natural language queries to retrieve detailed vulnerability and exposure data including hosts, containers, and test results. AI capabilities include deduplication of vulnerable items, remediation suggestions with third-party solutions, exposure assessments of configuration items and business services, awareness of CISA known exploitable vulnerabilities, compliance metric insights, and remediation goal tracking aligned with SLAs.
- Security Exposure Management (SEM) Workspace: Enables natural language querying for vulnerability and exposure data, generation of insights, and approval impact analysis recommendations. Users receive contextual summaries, actionable guidance, and on-demand approval recommendations directly within the workspace.
- Security Posture Control Workspace: Features the Now Assist SPC Setup Connector skill, allowing developers to create custom API connectors for importing security data from third-party products. This accelerates monitoring and management of the organization's security posture by enabling easy integration of external security data sources.
Additionally, in the ServiceNow Otto® panel, UI6 links open in new browser tabs for better user navigation.
Practical Benefits for ServiceNow Customers
- Leverage AI-powered natural language interactions to efficiently access and analyze vulnerability and exposure data.
- Improve remediation workflows with AI-driven recommendations and solution suggestions.
- Maintain up-to-date awareness of critical vulnerabilities through integration with CISA data.
- Facilitate better decision-making with compliance and remediation goal insights aligned to SLAs.
- Enable custom integrations with third-party security products to enhance security posture visibility.
Overall, USEM empowers security teams to proactively manage vulnerabilities and exposures using AI-driven insights, improving organizational security and compliance posture.
Get an overview of the important information that is related to the USEM application.
Supported versions and required applications
The following applications are required:
| Application | Version |
|---|---|
| ServiceNow Otto for Unified Security Exposure Management | 5.2.3 |
| ServiceNow Otto® for platform [sn_genai_platform] | 12.2.0 |
| Vulnerability Response Integration with CISA [sn_vul_cisa] | 1.5.1 |
| Vulnerability Response [sn_vul] non USEM. Note: Application Vulnerability Response is included as a part of Vulnerability Response. |
26.5.3 |
| Vulnerability Response for USEM and Security Exposure Management workspace. Note: Application Vulnerability Response is included as a part of Vulnerability Response. |
30.7.6 |
| Vulnerability Response licensing and usage [sn_vul_licensing] (installed with [sn_vul]) | 2.7.1 |
| Vulnerability Response Common Workspace [sn_vul_cmn_ws] (installed with [sn_vul]) | 1.10.0 |
| Vulnerability Response Integration Framework [sn_vul_int_fw] | 1.5.0 |
| AI Security Exposure Management (sn_sec_ai). | 2.1.2 |
| Vulnerability Solution Management [sn_vul_solution] | 10.4.3 |
| Security Posture Control API Connectors [sn_spc_cxf] for the API Connector skill. | 2.1.1 |
|
Mitigation Controls Monitoring [sn_sec_mit_ctrl] for the API Connector skill. |
4.2.2 |
| Security Posture Control [sn_sec_spc_core] for the API Connector skill. | 7.2.1 |
Supported user interfaces
ServiceNow Otto for Unified Security Exposure Management includes the generative AI skills listed in the following table.
| Interface | Features |
|---|---|
| Vulnerability Manager Workspace | Ask questions in natural language to help you quickly retrieve vulnerability and exposure data for all types of findings that include host, container, and test results vulnerabilities with
Security Exposure 360. Now Assist skills:
AI agents: Vulnerability managers and analysts can assess if your configuration items (CIs) and your business services are exposed to vulnerabilities. Check for any new Cybersecurity and Infrastructure Security Agency (CISA) known exploitable vulnerabilities and assess their potential impact on your environment. Vulnerability managers and analysts can gain insights into your compliance metrics. Vulnerability managers and analysts understand how effectively your organization is meeting remediation goals for vulnerabilities based on Service Level Agreements (SLAs) with these insights. |
| Security Exposure Management (SEM) workspace | Ask questions in natural language to help you quickly retrieve vulnerability and exposure data for all types of findings that include host, container, and test results vulnerabilities with
Security Exposure 360. Generate insights and Generate recommendation for Approval Impact Analysis skills. Receive insights based on contextual summaries, actionable recommendations, and quick links in the Security Exposure Management (SEM) workspace. Receive on-demand approval recommendations directly from the Exception Change Approval record in the Security Exposure Management (SEM) workspace. |
| Security Posture Control Workspace | Now Assist
SPC Setup Connector skill: Create your own API connectors for the Security Posture Control workspace based on common third-party security products. Developers can accelerate the process of selecting API templates and populating request and header parameters and response field mapping. Your cybersecurity teams can use these custom API connectors to import the security data that helps them monitor your security posture. |
| UI6 | Links in the responses in the ServiceNow Otto® panel open new tabs in your browser. |