Tenable.sc integrations with the Vulnerability Response application
Summarize
Summary of Tenable.sc integrations with the Vulnerability Response application
The Tenable.sc integrations with the Vulnerability Response application enable ServiceNow customers to import and manage vulnerability and asset data from the Tenable.sc product within their ServiceNow AI Platform instance. Starting with Vulnerability Response v20.0, scans performed by agents are clearly identified, enhancing the authenticity and reliability of imported data.
Show less
Multi-source support allows deployment of multiple Tenable.io and Tenable.sc integration instances across the environment via the Setup Assistant, streamlining setup and configuration.
Key Features
- Tenable.sc Assets Integration: Consists of two parts—
- Open Assets Integration: Imports current (open) vulnerabilities as vulnerable items (VIs) in the Open state, requiring investigation and remediation.
- Fixed Assets Integration: Imports mitigated or fixed vulnerabilities, transitioning VIs to the Closed/Fixed state to reflect resolved issues.
- Tenable.sc Plugin Integration: Retrieves up-to-date plugin data to ensure active vulnerabilities are current and accurately imported.
- Tenable.sc Fixed Vulnerabilities Integration: Imports fixed vulnerability data based on severity filters. It updates existing VIs and optionally creates new VIs for fixed detections if enabled. This is a scheduled and chained integration triggering the Open Vulnerabilities Integration upon completion.
- Tenable.sc Open Vulnerabilities Integration: Runs after the Fixed Vulnerabilities Integration, importing active vulnerabilities and updating or creating VIs and CIs accordingly. Both fixed and open vulnerabilities integrations exclude family IDs 0 and 39 by default.
- Tenable.sc Scan Credential Integration: Retrieves and synchronizes scan credentials from Tenable.sc to ServiceNow, enabling authenticated scan requests. This runs weekly.
- Tenable.sc Backfill Vulnerabilities Integration: Optionally imports any missed open and fixed vulnerabilities from the previous seven days to ensure data completeness. This integration is inactive by default and may impact performance.
User Authentication
User authentication is supported for Tenable.sc version 5.13 and later via the ServiceNow AI Platform. For versions 5.12 and earlier, user authentication is mandatory. Authentication tokens may expire and be refreshed automatically during integration runs without interrupting processes, with token expiration messages logged for transparency but requiring no customer action.
Practical Considerations for ServiceNow Customers
- Configure and deploy multiple Tenable integration instances as needed using the Setup Assistant for scalable vulnerability management.
- Use the query filter options to tailor imported data to your security and operational priorities, avoiding unnecessary data overload.
- Schedule vulnerability imports strategically to avoid performance impacts, particularly when enabling backfill or fixed vulnerability VIs creation.
- Ensure MID Server usage aligns with your deployment environment—required when Tenable.sc and ServiceNow AI Platform are in different environments.
- Leverage updated plugin and scan credential integrations to maintain accurate, authenticated vulnerability data imports.
The Tenable.sc integrations in the Vulnerability Response Integration with Tenable application.
Starting with Vulnerability Response v20.0, if an asset is scanned by an agent, the "Agent exists" column in the Discovered Items list displays the value as "true." This indicates that the scan is authentic.
List of Tenable.sc integrations
Multi-source is supported for all the Tenable.io and Tenable.sc integrations. You can add and deploy multiple instances of the following integrations across your environment from Setup Assistant in Vulnerability Response. You can also install and configure the Vulnerability Response Integration with Tenable application from Setup Assistant.
- Tenable.sc is an on-premises integration that gives you the option to use a MID Server if the Tenable.sc product and your ServiceNow AI Platform instance are in the same environment.
- If the Tenable.sc product and your ServiceNow AI Platform instance aren’t in the same environment, you’re required to use a MID Server.
| Integration | Description |
|---|---|
| Tenable.sc Assets Integration |
To avoid creating duplicate discovered items with imported asset data, the Asset Integration of the Tenable.sc product is comprised of two integrations.
|
| Tenable.sc Plugin Integration |
|
| Tenable.sc Fixed Vulnerabilities Integration |
The output of this integration is Closed/Fixed vulnerable items (VIs). It also creates assets and third-party entries if they don't exist. This integration run is a scheduled run. It’s a chained integration which means after a run is successfully completed, the Tenable.sc Open Vulnerabilities Integration described next is triggered. Note:
By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Open Vulnerabilities Integration |
Note:
By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Scan Credential Integration |
|
| Tenable.sc Backfill Vulnerabilities Integration |
|
User authentication and Tenable.sc
User authentication is supported by your ServiceNow AI Platform® instance and version 5.13 of the Tenable.sc product. User authentication is required if you’re using version 5.12 and earlier of the Tenable.sc product.
When you select user authentication for the Tenable.sc integrations, tokens might expire and be replaced during integration runs. In the Notes column on the Vulnerability Integration Run record (VIN), the following message is displayed for a process when a token expires, Error: Token validation is failed. No action is required if this message is displayed. Expired tokens are automatically refreshed in the background and the message doesn’t indicate a pause or error with the integration process.