Tenable.sc integrations with the Vulnerability Response application
Summarize
Summary of Tenable.sc integrations with the Vulnerability Response application
The Tenable.sc integrations within the Vulnerability Response application enable ServiceNow customers to import, process, and manage vulnerability and asset data from Tenable.sc, an on-premises vulnerability management product. Starting with Vulnerability Response version 20.0, the system clearly indicates if an asset scan was performed by an agent, enhancing data authenticity verification.
Show less
These integrations support multi-source configurations, allowing multiple Tenable.io and Tenable.sc instances to be deployed and managed from the Vulnerability Response Setup Assistant. Tenable.sc integrations can use a MID Server when the Tenable.sc product and the ServiceNow AI Platform instance are in different environments, ensuring secure and reliable data transfer.
Key Features
- Tenable.sc Assets Integration: Divided into Open Assets and Fixed Assets integrations, it imports vulnerability data classified by Tenable as open (current) or fixed (mitigated), creating or updating vulnerable items to reflect their remediation status.
- Tenable.sc Plugin Integration: Retrieves updated plugin definitions to keep vulnerability identifiers current, ensuring only active vulnerabilities are imported.
- Tenable.sc Fixed Vulnerabilities Integration: Imports fixed vulnerability data based on severity filters, updating vulnerable items to a closed/fixed state when applicable. This integration is scheduled and chained to trigger the Open Vulnerabilities integration upon completion. It excludes certain family IDs by default.
- Tenable.sc Open Vulnerabilities Integration: Triggered after fixed vulnerabilities import, it imports active vulnerabilities and creates or updates corresponding vulnerable items and configuration items, also excluding specific family IDs by default.
- Tenable.sc Scan Credential Integration: Imports scan credentials from Tenable.sc to facilitate scanner access when initiating scans from the ServiceNow AI Platform. This integration runs weekly.
- Tenable.sc Backfill Vulnerabilities Integration: An optional integration that imports missed open and fixed vulnerabilities from the past seven days to ensure data completeness. It is inactive by default due to potential performance impact.
- User Authentication: Supported by ServiceNow AI Platform and Tenable.sc version 5.13 and later. For versions 5.12 and earlier, user authentication is mandatory. Token expiration is automatically handled during integration runs without manual intervention.
Practical Considerations for ServiceNow Customers
- Use the Setup Assistant in Vulnerability Response to install and configure the Tenable.sc integrations and to manage multiple Tenable instances efficiently.
- Deploy a MID Server if your Tenable.sc product and ServiceNow AI Platform reside in separate environments to ensure proper communication.
- Configure query filters carefully in the Setup Assistant to control which assets and vulnerabilities are imported, optimizing performance and relevance.
- Consider scheduling Fixed and Open Vulnerabilities integrations during low system usage to minimize performance impact.
- Be aware that enabling fixed vulnerability imports to create vulnerable items may affect import performance; this feature is optional and off by default.
- Monitor vulnerability integration run records for token expiration messages; these are informational and require no action.
The Tenable.sc integrations in the Vulnerability Response Integration with Tenable application.
Starting with Vulnerability Response v20.0, if an asset is scanned by an agent, the "Agent exists" column in the Discovered Items list displays the value as "true." This indicates that the scan is authentic.
List of Tenable.sc integrations
Multi-source is supported for all the Tenable.io and Tenable.sc integrations. You can add and deploy multiple instances of the following integrations across your environment from Setup Assistant in Vulnerability Response. You can also install and configure the Vulnerability Response Integration with Tenable application from Setup Assistant.
- Tenable.sc is an on-premises integration that gives you the option to use a MID Server if the Tenable.sc product and your ServiceNow AI Platform instance are in the same environment.
- If the Tenable.sc product and your ServiceNow AI Platform instance aren’t in the same environment, you’re required to use a MID Server.
| Integration | Description |
|---|---|
| Tenable.sc Assets Integration |
To avoid creating duplicate discovered items with imported asset data, the Asset Integration of the Tenable.sc product is comprised of two integrations.
|
| Tenable.sc Plugin Integration |
|
| Tenable.sc Fixed Vulnerabilities Integration |
The output of this integration is Closed/Fixed vulnerable items (VIs). It also creates assets and third-party entries if they don't exist. This integration run is a scheduled run. It’s a chained integration which means after a run is successfully completed, the Tenable.sc Open Vulnerabilities Integration described next is triggered. Note:
By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Open Vulnerabilities Integration |
Note:
By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Scan Credential Integration |
|
| Tenable.sc Backfill Vulnerabilities Integration |
|
User authentication and Tenable.sc
User authentication is supported by your ServiceNow AI Platform® instance and version 5.13 of the Tenable.sc product. User authentication is required if you’re using version 5.12 and earlier of the Tenable.sc product.
When you select user authentication for the Tenable.sc integrations, tokens might expire and be replaced during integration runs. In the Notes column on the Vulnerability Integration Run record (VIN), the following message is displayed for a process when a token expires, Error: Token validation is failed. No action is required if this message is displayed. Expired tokens are automatically refreshed in the background and the message doesn’t indicate a pause or error with the integration process.