Note:
- Versions 30.0.X are part of the Innovation Lab (Early Access) release for Unified Security Exposure Management (USEM). These versions are intended for sub-production environments and a limited number of selected customers participating in the USEM Innovation Lab program.
- Upgrade Guidance: If you're not part of the USEM Innovation Lab program and want to upgrade without USEM, please select the latest GA version below 30.x.
The Vulnerability Response integration with the CISA Known Exploited Vulnerabilities (KEVs) catalog ingests crucial information about vulnerabilities that are actively exploited. Additionally, it integrates with EPSS data from first.org, focusing on software vulnerabilities currently under exploitation. This comprehensive approach empowers organisations to prioritize and address these vulnerabilities efficiently, enhancing your overall Vulnerability Management strategy.
Cybersecurity & Infrastructure Security Agency (CISA) KEVs highlight actively exploited vulnerabilities, Exploit Prediction Scoring System (EPSS) scores predict future exploit likelihood and enriched National Vulnerability Database (NVD) data empowers informed decisions in ServiceNow, for optimal vulnerability prioritization.
Initial release:
- If Vulnerability Response Integration with CISA for SecOps is installed, a tile to review the integration status run is displayed in the Administration Console.
- The Vulnerability Response application and its dependency plugins must be installed and activated.
- The Vulnerability Response Integration with NVD plugin must be installed.