Combined Configuration Compliance release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Configuration Compliance release notes for upgrades from Yokohama to Zurich
This consolidated release notes page provides ServiceNow customers with essential information about upgrading Configuration Compliance from Yokohama to Zurich. It covers new features, important upgrade instructions, changes, and enhancements introduced in the Zurich release, as well as activation and compatibility guidance. This summary aims to help customers prepare for the upgrade, understand key improvements, and ensure smooth adoption of Configuration Compliance capabilities in Zurich.
Show less
Important Upgrade Information
- If you use Configuration Compliance but do not plan to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x for supported third-party integrations.
- The
Missing Assets [snvulwizmissingasset]table used for storing assets imported by the Vulnerability Response Integration with Wiz is deprecated. After upgrading to version 1.1, backdate existing Wiz primary integrations by three days and run them to ensure proper data processing. - Backfill integrations for Wiz data are activated by default, reducing the need for manual handling of missing assets once upgrades are complete.
- Refer to the Vulnerability Response Compatibility Matrix and Release Schema Changes knowledge base article for detailed compatibility information.
New Features
- Wiz Integration Enhancements: Identify and select Wiz Resource Types to import into ServiceNow, applicable to most Wiz vulnerability and compliance integrations except the container vulnerability integration.
- Wiz Backfill Integrations process missing asset data stored in the deprecated Missing Assets table, including Test Results, Host Test Results, and Issues Backfill integrations.
- Wiz Host Test Result Vulnerability Integration imports virtual machine test results and is activated by default.
- Manual creation of remediation tasks is now possible in both the Vulnerability Manager Workspace (with
snvulc.adminrole) and IT Remediation Workspace (withsnvulc.remediationownerrole), grouping selected Configuration Test Results based on chosen criteria. - Risk score details for test results can be viewed in the Work notes section by enabling the system property
snseccmn.riskscorechangesaddworknotes. - Quick start tests are available to verify Configuration Compliance functionality after upgrades or new deployments.
- Zurich introduces configuration options for test result granularity with Tenable and Qualys integrations, allowing splitting of findings for improved visibility.
- A new parameter,
ignorepassedresult, was added to the Qualys integration to optionally ignore passed test results during import, helping focus on actionable findings.
Changes and Enhancements
- Removal of the
isignoredcolumn replaced byisresultignoredin Host Test Results and Test Results integrations to improve data accuracy. - Source severity is now mapped to the Priority column on the Test Results table for better prioritization.
- Additional attributes imported from Wiz but not stored in the Discovered items table are now stamped as Asset Attributes for enriched context.
- Improved state management logic for remediation tasks and vulnerable items enhances accuracy in status roll-up and roll-down processes, reducing manual effort and clarifying task ownership.
- Resource type filters are configurable on Wiz integration tabs, with integration instance settings taking precedence over Resource Type Configuration tab settings.
- Mapping of the CMDB internet-facing field to Limited Internet Exposure on findings improves exposure visibility.
- Increased column length for descriptions in the Host Vulnerability import table to accommodate more detailed data.
- Configuration option to limit the maximum rows shown in related lists on forms improves performance and readability.
Activation and Installation
- Configuration Compliance and third-party integrations for Zurich are available through the ServiceNow Store.
- Customers should request installation via the ServiceNow Store and refer to cumulative release notes available there for all released apps.
Additional Information
- Browser and Accessibility: No new browser requirements; Zurich introduces a dark theme option within the new Coral theme to improve usability and reduce eye strain.
- Localization: No changes noted for this release.
- Highlights: Manual remediation task creation roles remain important; Wiz integration improvements enhance import and tracking of cloud configuration test results and issues.
- Upgrade to USEM: Customers intending to migrate to Unified Security Exposure Management should consult the specific USEM release notes for guidance.
Consolidated page of all release notes for Configuration Compliance from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Configuration Compliance release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Configuration Compliance to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
If you are currently using Configuration Compliance, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Configuration Compliance and for upgrades to supported third-party integration applications. The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community. For more information about the released versions of the Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base. |
New features
Between your current release family and Zurich, new features were introduced for Configuration Compliance.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Configuration Compliance features.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Removed
Between your current release family and Zurich, some Configuration Compliance features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Configuration Compliance features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Configuration Compliance.
| Release | Release notes |
|---|---|
Yokohama |
Install Configuration Compliance by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Configuration Compliance and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Configuration Compliance, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Configuration Compliance we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Configuration Compliance for more information. |
Zurich |
See Configuration Compliance for more information. |