Integrations and dependencies of the Vulnerability Response Patch Orchestration integration with HCL BigFix
Summarize
Summary of Integrations and dependencies of the Vulnerability Response Patch Orchestration integration with HCL BigFix
The Vulnerability Response Patch Orchestration integration with HCL BigFix enables ServiceNow customers to orchestrate patch management by integrating Vulnerability Response data with BigFix endpoint management. This integration requires specific ServiceNow applications and facilitates automated data synchronization between ServiceNow and BigFix, helping customers efficiently view, manage, and deploy patches to address vulnerabilities.
Show less
Key Features
- Required Applications: To utilize this integration, customers must install several applications from the ServiceNow Store, including Vulnerability Response, Vulnerability Solution Management, Vulnerability Response Patch Orchestration, Vulnerability Response Patch Orchestration with HCL BigFix, Security Support, Common Security Support, and Security Support Orchestration. Some may require separate subscriptions.
- Data Tables: The Patch Orchestration application manages various tables storing patch, device, collection, deployment, and vulnerability data to support patch orchestration workflows within ServiceNow.
- Integration Components: The integration consists of four main scheduled or on-demand integrations that run sequentially:
- BigFix Collection Integration: Runs daily to retrieve computers and computer groups from BigFix.
- BigFix Fixlet Integration: Triggered after collection integration, retrieves available fixlets (patches) from BigFix.
- BigFix Device Fixlet Integration: Triggered after fixlet integration, retrieves fixlets currently applied on computers.
- BigFix Actions Integration: Triggered after device fixlet integration, retrieves patch deployment schedules from BigFix.
Key Outcomes
- Enables ServiceNow customers to synchronize vulnerability and patch data with BigFix, providing a comprehensive view of patch status and compliance.
- Automates the import and update of patch and deployment information on scheduled intervals to maintain up-to-date vulnerability remediation insights.
- Enhances patch orchestration capabilities by integrating endpoint data, collections, and patch deployment statuses directly into Vulnerability Response workspaces.
- Supports more effective vulnerability management and remediation planning by combining ServiceNow’s vulnerability intelligence with BigFix’s endpoint patching data.
The following product and dependency applications are required for the Vulnerability Response Patch Orchestration with HCL BigFix Integration. These applications are available in the ServiceNow® Store.
Available versions of applications and dependencies required for the patch orchestration integration
To view patch orchestration data and available updates (patches) in the workspaces in Vulnerability Response, the following applications are required. All applications listed are available in the ServiceNow® Store. Some applications require separate subscriptions.
For more information about version compatibility with the required applications and family releases, refer to the KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes article in the HI Knowledge Base.
| Application and release version |
|---|
| Vulnerability Response |
| Vulnerability Solution Management |
| Vulnerability Response Patch Orchestration application |
| Vulnerability Response Patch Orchestration with HCL BigFix application |
| Security Support Common |
| Security Support Orchestration |
| A supported third-party vulnerability scanner application |
Vulnerability Response Patch Orchestration application tables
The Vulnerability Response Patch Orchestration application contains the following tables:
| Table | Description |
|---|---|
| Patch Update [sn_vul_patch_orch_update] | Stores information about the patches that are available on distinct instances. |
| Device Update [sn_vul_patch_orch_m2m_src_ci_update] | Stores data about the deployed patches, along with deployment status, that are on displayed on discovered item records. |
| Collection [sn_vul_patch_orch_collection] | Stores collection data from distinct instances. |
| Device Collection [sn_vul_patch_orch_m2m_src_ci_collection] | Stores collections data about discovered items. |
| Patch Deployment [sn_vul_patch_orch_deployment] | Stores information about deployed patches about Collections and CIs. |
| Potential Patch [sn_vul_patch_orch_m2m_vuln_patch] | Stores data about patches and vulnerabilities that identify the patches that might be used to resolve a vulnerability. |
Vulnerability Response patch orchestration integrations with HCL BigFix
The integrations developed by ServiceNow® engineering make up the orchestrated solution deployment with the BigFix product. The following integrations are included with the Vulnerability Response Patch Orchestration Integration with HCL BigFix application that you download from the ServiceNow® Store.
After you install the integration application on your ServiceNow AI Platform instance, to view these integrations, navigate to . The Vulnerability Response application processes data on scheduled time intervals imported by these integrations with BigFix endpoints.
| Integration | Description |
|---|---|
| BigFix Collection Integration |
|
| BigFix Fixlet Integration |
|
| BigFix Device Fixlet Integration |
|
| BigFix Actions Integration |
|