3
1.0.1
Australia, Zurich, Yokohama
Integration
The Picus VR App for ServiceNow Vulnerability Response enriches Vulnerable Items with validated risk insights from Picus Exposure Validation.
By adding the Picus Exposure Score (PXS) and its underlying components directly into Vulnerable Items, the app enables security and IT teams to prioritize remediation based on real security impact rather than severity scores alone.
The Picus Exposure Score (PXS) provides a risk-based view of exposures by combining multiple contextual factors, including:
By adding the Picus Exposure Score (PXS) and its underlying components directly into Vulnerable Items, the app enables security and IT teams to prioritize remediation based on real security impact rather than severity scores alone.
The Picus Exposure Score (PXS) provides a risk-based view of exposures by combining multiple contextual factors, including:
- Exploitability
- Contextual CVSS
- Security Control Effectiveness
- Asset Criticality
By combining these factors into a single, contextualized risk score, Picus helps organizations move beyond generic severity ratings and focus on vulnerabilities that pose the greatest real-world risk to their environment. With these insights available directly inside ServiceNow Vulnerability Response, teams gain better visibility into which vulnerabilities require immediate attention and why they matter, improving overall vulnerability response effectiveness.
- Vulnerable Item Enrichment
Enrich existing Vulnerable Items with Picus Exposure Score (PXS) and detailed risk components.
- Exposure Score Visibility
Provide visibility into the factors driving risk, including exploitability, contextual CVSS, security control effectiveness, and asset criticality.
- Risk-Based Prioritization
Support remediation prioritization using validated exposure risk instead of relying only on severity levels.
- Seamless Integration
Integrates directly into ServiceNow Vulnerability Response workflows without disrupting existing processes.
Initial Release
Not applicable for this application version.
Required plugins and products:
- The Vulnerability Response application and its dependency plugins must be installed and activated.
- A valid Picus Security platform tenant with an active Exposure Validation (EXV) license.
Permissions and roles:
- System Admin (admin) for installation
- Picus Administrator (x_pise_picus_sec_0.admin) for configuration, accessing the Configuration page, saving API settings, testing the connection, and enabling/disabling the daily sync
- Picus User (x_pise_picus_sec_0.user) for on-demand score refresh, using the "Update Picus Scores" button on individual vulnerable item records. The admin role also grants access to this action.