Triage vulnerabilities automatically
Summarize
Summary of Triage vulnerabilities automatically
Automatically triaging vulnerabilities is essential for effective remediation in ServiceNow Vulnerability Response. This process transforms imported vulnerabilities into actionable remediation tasks through automated assignment of vulnerable items (VIs), risk scoring, remediation target application, and grouping. It streamlines prioritization, orchestration, and validation of remediation efforts to ensure vulnerabilities are addressed efficiently.
Show less
Key Features
- Automated Vulnerable Item Assignment: Uses assignment rules to allocate VIs to appropriate teams, reducing manual workload. However, due to large data volumes, rule validation is critical to avoid misassignment.
- CI Lookup and Grouping Rules: Identify configuration items for VIs and group them into remediation tasks based on established rules. Ungrouped or unmatched items require manual review or rule refinement.
- Risk Scoring: Vulnerable items in remediation tasks can have risk scores revised using predefined calculators to prioritize remediation efforts effectively.
- Remediation Target Rules: Applied during VI import to define remediation goals and guide task creation. These rules are configured in the Setup Assistant.
- Validation and Closing: Older or undetected vulnerable items can be automatically closed to maintain data relevance. Rescanning and refreshing VIs help keep vulnerability data current.
- Change Requests and Incident Integration: Create Change Requests for remediation tasks and assign them to groups such as IT Operations. If Security Incident Response is enabled, remediation tasks can generate security incident records.
Practical Steps for Customers
- Log in to your Vulnerability Response instance and verify that CI Lookup and Assignment rules function correctly.
- Validate remediation target rules to ensure accurate task creation aligned with organizational goals.
- Review ungrouped vulnerable items to identify rule gaps; adjust grouping rules or manually create remediation tasks as needed.
- Manually adjust risk scores for better prioritization where necessary.
- Close outdated vulnerable items no longer detected by integrations to focus on current risks.
- Research and determine remediation priorities based on risk, affected systems, and patch schedules.
- Create Change Requests to assign remediation tasks to the appropriate teams and update the task status to “Under Investigation.”
Benefits for ServiceNow Customers
This automated triage framework enables customers to efficiently manage high volumes of vulnerability data, prioritize remediation based on risk, and streamline collaboration between security and IT operations teams. It reduces manual effort, improves accuracy in vulnerability handling, and supports ongoing validation and closure of vulnerabilities to maintain a secure environment.
Reviewing and triaging new vulnerabilities is necessary to ensure successful remediation. Transform vulnerability imports into remediation tasks with automated vulnerable item (VI) assignment, risk calculation, remediation targets, and VI grouping.
Starting with imported vulnerabilities, reconcile the assets not found in the CMDB, prioritize the results, translate that to remediation activities that are automatically assigned, orchestrate the remediation process, and confirm completion with a validation scan.
New vulnerable items are usually sorted into remediation tasks upon import, based on remediation tasks rules. Sometimes, vulnerable items cannot be grouped or do not contain a recognized configuration item.
- Log in to your Vulnerability Response instance.
- Validate that your rules (CI Lookup, Assignment) for vulnerable item are working as
expected. For information on revising CI Lookup Rules, see CI lookup rules for identifying configuration items from Vulnerability Response third-party vulnerability integrations. For
information on Assignment rules, see Vulnerability Response assignment rules overview.Note:Due to the large volume in data imports, care should be taken with automated vulnerable item assignment.
- Validate that your remediation targets are correct. See Vulnerability Response remediation target rules for information on how remediation target rules work and how to revise them.
- View ungrouped vulnerable
items.
- Looking at the ungrouped vulnerable items, consider revising your group rules and performing a rescan. See Create or edit Vulnerability Response remediation task rules for more information.
- Manually group the vulnerable items. Manually create a remediation task in Vulnerability Response for more information.
- Revise risk scores for the vulnerable items in your remediation tasks. See Vulnerability Response calculators and vulnerability calculator rules for more information.
- Close older vulnerable items not recently detected by your third-party integrations. See Automatic closing of vulnerable items and detections for more information.
- View and reclassify unmatched configuration items.
- Research what needs to be done for remediation.
This step can include:
- Determine what to deal with now and what you can defer. This determination is often
based on risk score, affected systems, and patches with change
windows.Note:Remediation target rules belong to vulnerable items. These rules are run when the vulnerable item is imported. These rules were created previously in the Setup Assistant.
- Refresh vulnerable items, if necessary, and View the remediation target status of a Vulnerability Response vulnerable item.
- Create a Change Request and assign the remediation task to an
assignment group (IT Operations) for remediation.Note:If the vulnerability constitutes a security incident and the Security Incident Response plugin (com.snc.security_incident) is activated, you can create security incident records from the remediation tasks instead.
- After submitting one or more change requests, move the group state to Under Investigation.
- Determine what to deal with now and what you can defer. This determination is often
based on risk score, affected systems, and patches with change
windows.