Vancouver |
- Viewing the dashboards in Vulnerability Manager Workspace
- Starting with v2.1 of Container Vulnerability Response, the Container Vulnerability Response and Prisma Cloud Compute integration run status dashboards are available in the Next Experience UI from Vulnerability Manager Workspace.
- Configuring fields to receive information on common vulnerabilities and exposures (CVEs)
- Starting from v2.1 of Container Vulnerability Response, when the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute is run, the fields Exploit exists and Remediation notes are populated with the details obtained from Prisma to provide
information on the CVEs. In addition, you can configure the fields that must get updated during the execution.
- Requesting an extension for a deferred container vulnerable item
- Starting with version v2.2.3 of Container Vulnerability Response, you can request an extension for a deferred exception rule before the due date.
- Extension of a deferred extension rule
- Starting with version v2.2.3 of Container Vulnerability Response, you can request an extension for a deferred extension rule before the due date.
- Extension of deferred remediation task
- Starting with version v2.2.3 of Container Vulnerability Response, you can request an extension for a deferred remediation task before the due date.
- Accessing only the container vulnerable items assigned to you and your group with the exception approver
role
- For the exception approver role, sn_vul_container.exception_approver, the granular role, sn_vul_container.read_all, has been removed so that you can access the container vulnerable items and remediation tasks assigned to you
and your group only.
- Adding the work notes for a deferred container vulnerable item
- Starting from 2.3 of Container Vulnerability Response, you can add the relevant information in the Work Notes field for a deferred container vulnerable item also.
- Quick start tests for Container Vulnerability Response
After upgrades and deployments of new applications or integrations, run quick start tests to verify that Container Vulnerability Response works as expected. If you customized Container Vulnerability Response, copy the quick start tests and configure them for your customizations.
|
Washington DC |
|
Xanadu |
- New Properties module
- Starting with v2.11.3 of Container Vulnerability Response, a new Properties module has been added to the navigation menu under the Administration section. This module enables direct modification of the
values, offering a user-friendly method to manage and update system properties directly from the interface.
- Create auto-close rules for Container Vulnerability Response
- Starting with v2.11.3 of Container Vulnerability Response, define auto-close rules with advanced conditions to automatically close older or stale CVITs based on defined filter criteria on container vulnerabilities.
- Customize the calculation of Age and Age closed parameters of a container vulnerable item
- Starting with v2.11.3 of Container Vulnerability Response, the Age and Age Closed durations of a Container Vulnerable Item can be configured to be calculated from the date in the Created, Opened, or First Found fields.
- Open the search results in the Vulnerability Manager Workspace or IT Remediation Workspace rather than the Classic UI
- Starting with v24.0.6 of Vulnerability Response, automatically open your search results in the Vulnerability Manager Workspace or IT Remediation Workspace rather than the Classic UI, by adjusting the application scope in the unified navigation bar to Vulnerability Manager Workspace or IT Remediation Workspace respectively. These application scopes are available to you based on your assigned role.
- Vulnerability Manager Workspace access to the sn_vul_container.read_all role
- Starting with v24.0.6 of Vulnerability Response, as a user with the sn_vul_container.read_all role, you can view the container vulnerable items in the Vulnerability Manager Workspace.
- IT Remediation Workspace access to the sn_vul_container.read_assigned role
- Starting with v24.0.6 of Vulnerability Response, as a user with the sn_vul_container.read_assigned role, you can view the container vulnerable items assigned to you and your assignment groups in the IT Remediation Workspace and remediate them.
- Navigate to the List page in the Vulnerability Manager Workspace or IT Remediation Workspace by selecting the links from the All menu
- Starting with v24.0.6 of Vulnerability Response, when you enable the 'sn_vul_cmn_ws.navigate_to_workspace' system property, selecting predefined filter links in the Container Vulnerability Response module from the 'All' menu will automatically
open these links in the List page in the Vulnerability Manager Workspace or IT Remediation Workspace based on your role.
- Hide the record count on the lists in the Vulnerability Manager Workspace and IT Remediation Workspace
- Starting with v24.0.6 of Vulnerability Response, you can hide the record count on the lists in the List page of the Vulnerability Manager Workspace and IT Remediation Workspace, by adding the table names to the glide.ui.list.seismic.omit.count system property.
- Enable automatic refresh for the Home page dashboard in the Vulnerability Manager Workspace
- Starting with v24.0.6 of Vulnerability Response, when creating and editing filters on the Container Vulnerabilities tab on the Home page of the Vulnerability Manager Workspace, you can configure the widgets to automatically refresh. Otherwise, you can manually refresh the widgets by selecting the Refresh button on the Container Vulnerabilities
tab.
- Re-evaluating remediation properties for all records in the Vulnerability Manager Workspace
- Starting with v24.0.6 of Vulnerability Response, you can evaluate the remediation properties for all the Container Vulnerable Items from the Container Vulnerable Items list by selecting the All items in the Record
selection field of the Re-evaluate remediation properties modal in the Vulnerability Manager Workspace.
- Re-evaluate the remediation properties for container vulnerable items in the Vulnerability Manager Workspace
- Select the container vulnerable items conditionally for reevaluating the following remediation properties in Vulnerability Manager Workspace:
- Assignments
- Remediation tasks
- Remediation target date
- Exceptions (Vulnerability Response v24.0.6)
- Risk score
- Enhanced processing performance of scheduled job
- The Rollup container vulnerable item values to vulnerability and group scheduled job is enhanced to create background jobs with multithreading capabilities. This upgrade involves segmenting the job into
several smaller child jobs, which are executed either in parallel or concurrently. This modification enables processing of multiple records simultaneously, thus significantly speeding up the overall task.
- for Container Vulnerability Response
-
After upgrades and deployments of new applications or integrations, run quick start tests to verify that Container Vulnerability Response works as expected. If you customized Container Vulnerability Response, copy the quick start tests and configure them for your customizations.
- Vulnerability Response Prisma Registry Integration
- Now you can ingest the static image findings obtained from the Prisma registry scan into the ServiceNow Container Vulnerability Response.
|
Yokohama |
- Enhancements to the Vulnerability Manager and IT Remediation workspaces starting with version 2.13
- The Unassign workflow is supported for container vulnerable items (CVITs) and remediation tasks (CVULs).
- Streamline vulnerability assignments in the workspaces with the Unassign UI action from the more actions menu on a CVIT.
- Reassign incorrectly assigned CVITs, clarify ownership for reassessment, and maintain accurate triage records in workspace views.
- You have the option to send unassign requests for approval prior to clearing the Assigned to and Assignment group fields on records.
[Placeholder link text to key cvr-assignment-rules]. You can use the following values imported from the Prisma Cloud Compute integration as conditions when you create or update your assignment rules to help you track ownership across your
container environments.
- Cloud account IDs
- Image namespaces
- Registry
- Hosts
- Labels
- Status - Vendor status for a resolved (Fixed) vulnerability
- Create container remediation tasks manually in the Vulnerability Manager Workspace
- With the sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin role, you can create container remediation tasks manually by selecting some or all the records in the Container vulnerable items lists
in the Vulnerability Manager Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating container remediation tasks.
- Create container remediation tasks manually in the IT Remediation Workspace
- With the role sn_vul_container.remediation_owner, you can create container remediation tasks manually by selecting some or all the records in the Container vulnerable items’ lists in the IT Remediation Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating container remediation tasks.
- Configure container vulnerable items (CVITs) granularity using Registry and data source
- Starting with v2.12.2 of Container Vulnerability Response, you can configure the granularity of container vulnerable items (CVITs) using Registry information and data sources. Depending on the chosen data source, you can view either image or
kubernetes information related to a CVIT record.
- Additional columns in the container vulnerable items (CVITs) table
- Starting with v2.12.2 of Container Vulnerability Response, you can see the precise date and time when a CVIT was first discovered, last opened, resolved, and last found, ensuring clarity and accounting for different time zones.
- View risk score details of a container vulnerable item in the Work Notes section
- Starting with v2.12.2 of Container Vulnerability Response, the system property sn_sec_cmn.risk_score_changes_add_worknotes is inactive by default. If you enable it, only then you can see all the changes related to the risk
score of a container vulnerable item in the Work notes section. Additionally, the work notes are updated only if there’s a change in the risk score.
|