Prepare for the Vulnerability Response Patch Orchestration integration with HCL BigFix

  • Release version: Zurich
  • Updated September 5, 2025
  • 3 minutes to read
  • Prepare for the integration by performing the following setup tasks.

    Before you begin

    Roles required: admin for installing the applications and assigning roles. Other roles are listed in the following table.

    About this task

    A successful integration requires planning and careful execution of pre-integration tasks.

    You are ready to Install the Vulnerability Response Patch Orchestration with HCL BigFix application.

    Procedure

    1. For a smooth installation and configuration of the Vulnerability Response Patch Orchestration with HCL BigFix application, follow the checklist provided.
    2. You might prefer to print the following checklist and verify the items listed are completed before you install the application.

      After installation and configuration, import vulnerability and patch-related information into your ServiceNow AI Platform® instance.

      Task Description
      Checkbox image
      (Optional) If not already installed and activated, you may prefer to install the Vulnerability Response application prior to installing the third-party application.

      For more information about installing and activating the Vulnerability Response application, see, Install Vulnerability Response. This integration requires version 16.0 of Vulnerability Response or later.

      Checkbox image
      If not already installed, get entitlements and install and third-party scanner application to import vulnerability data.

      See Vulnerability Response integrations for more information about third-party scanners supported by Vulnerability Response.

      See .

      Checkbox image

      If not already installed, get entitlements and download the Vulnerability Response Patch Orchestration with HCL BigFix application to your ServiceNow AI Platform® instance.

      See .

      Obtain BigFix credentials.

      Verify you have any account names, passwords, and other service information required by your BigFix products so that you have access to them.

      Checkbox image

      Verify that you have groups or users to manage the integrations and remediate vulnerable items.

      admin
      The system admin gets entitlements, downloads, and installs the BigFix Patch Orchestration application and the other applications required for the integration. If not assigned, the admin assigns the vulnerability admin (sn_vul.vulnerability_admin) and other roles in the Setup Assistant in Vulnerability Response or from the User Administration module.
      sn_vul.vulnerability_admin
      Once assigned, the vulnerability admin completes the configuration of the BigFix integrations and the other third-party applications. This role has complete access to the Vulnerability Response (VR) application and its records. This role configures all VR applications, rules, third-party integrations, Vulnerability Response Patch Orchestration and Vulnerability Solution Management applications.
      sn_vul_bigfix.configure_integration
      Users with this role configure the BigFix Patch Orchestration Integration application. This role contains the sn_vul_bigfix.read_integration and connection_admin granular roles that permit the user to connect to the BigFix console and configure the integration instances in your ServiceNow AI Platform.
      sn_vul_bigfix.read_integration
      Users with this role can view (read only) the  records of the Vulnerability Response and the BigFix Patch Orchestration Integration application and patch orchestration data.
      sn_vul_patch_orch.configure_patch
      Users with this role can configure and apply patches. Patches requested by this user from Vulnerable item and Patch Update records are sent for approval if change management is active and approvers are assigned.
      sn_vul_patch_orch.read_patch
      Users with this role can view (read only) patch information on records. This role is inherited with the sn_vul.remediation_owner and sn_vuln.vulnerability_analyst roles that are required for the IT Remediation and Vulnerability Manager Workspaces.
      Approvers
      Users assigned to the Approver level 1 and, optionally, Approver level 2, approver groups approve submitted patch requests. By default, patches are submitted to the the Approver level 1 group for approval prior to deployment.

      For more information about the approval process, see Patch orchestration with Vulnerability Response. For more information about setting up approvers and groups, see Assign the Vulnerability Response persona roles using Setup Assistant.

      The system admin performs the initial assignment of roles to users and groups for the integration. By default, the Vulnerability Response group is available. If not already created, you may prefer to create additional groups for remediation specialist and vulnerability analyst roles and add users with the User Administration module in your instance. See Create a user group.

      Checkbox image

      Verify you have enabled any features, rules, dependency plugins, or jobs in your instance required for the integration.

      • The Vulnerability Response Patch Orchestration with HCL BigFix is an on-premises integration that requires you to use a standalone MID Server. For more information about MID Servers in your instance, see MID Server.
      • Navigate to System Applications > All Available Applications > All and locate the plugin. If not installed in your instance, install and activate it.

    What to do next

    You are now ready to Install the Vulnerability Response Patch Orchestration with HCL BigFix application.