---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Management Support

# Vulnerability Management Support {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Learn how a new vulnerability is created in TISC with a related vulnerability in VR.

## Before you begin

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-vul-mgmt__ul_hpp_fbn_bcc}

## About this task

When new vulnerability is created in TISC and there is a related vulnerability in VR.

* If VR vulnerability(v2) score is \> 8 OR VR vulnerability(v3) score is \> 8.
* Total VI's associate to it are greater than 0.
{#tisc-vul-mgmt__ul_xpt_14j_ccc}

## Procedure

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Vulnerability Management Support action link to view the respective rule details in the flow designer.
4. View the flow designer action for the following trigger:  

       When new vulnerability is created in TISC and there is a related vulnerability in VR.

5. If the percentage of total VI's remediated that are associated to that vulnerability is 100%, then:
   1. Add a tag called Remediated to the observable.
   {#tisc-vul-mgmt__substeps_msj_lhn_bcc}
6. Else, enrich the observable data with available capabilities:
   1. Create a remediation task for VR.
   2. Notify the concerned VR team's regarding it.  
   {#tisc-vul-mgmt__substeps_u2x_23n_bcc}
{#tisc-vul-mgmt__steps_ugd_yx3_ccc}
**Related concepts**   

* [Automated flows tables](https://www.servicenow.com/docs/ygtkSTqILyqzvLKkuxIwcg "The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.")  
**Related tasks**   

* [Automated IOC Enrichment](https://www.servicenow.com/docs/PRfyoZq64Vv37y3gUbKFwg "Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.")
* [Analyze, assess, and disseminate observables](https://www.servicenow.com/docs/f6mohzGVXYrKukknyK_L7A "Learn how to analyze and disseminate observables which are related to threat.")
* [Analyze and assess threat IoC's](https://www.servicenow.com/docs/WcxVPz15mlNlL71JUH_iwg "Learn how to analyze an IOC’s which are a threat and notifying the security incident team.")
* [Zero-day vulnerability tracking](https://www.servicenow.com/docs/UNjhzjpN~V3iGXKSMyCKfA "Learn how to analyze RSS Feeds coming into the system.")

*[\>]: and then


