Note:
This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications.
If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. For full details, please refer to the KB2556844 and documentation before proceeding.
If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.
Vulnerability Response and Configuration Compliance for Containers helps organizations respond to container vulnerabilities quickly and efficiently by connecting security and application teams, and providing real-time visibility into your security posture. Container Vulnerability Response connects the workflow and automation capabilities of the Now Platform® with vulnerability scan data from leading container security vendors to give your teams a single platform for a response that can be shared between security and application teams.
The Vulnerability Response and Configuration Compliance for Containers application includes the following capabilities:
- Refer to a Docker image as a configuration item (CI) from the container vulnerable items (CVITs).
- Provide runtime context such as Kubernetes Services, Clusters, Namespaces, and cloud account metadata for security teams so they can make decisions on assignment, remediation target, risk score calculation, and more.
- Assignment rules automatically assign container vulnerabilities to the application teams based on Docker Image labels, Kubernetes cluster/namespace/service information, cloud account ID, cloud account name, cloud region, cloud provider, etc.
- Populate base OS image vulnerable items separately to facilitate independent tracking of these vulnerabilities.
- Provide flexibility to configure granularity of container vulnerable items to track at Docker image level, cluster level, service level, etc.
- Automatically detect new versions of container images being deployed and close vulnerabilities reported on older versions.
- Exception management features for remediation owners to request for exceptions, multi-level approval workflow, and exception rules to automatically defer container vulnerable items.
- PA dashboard, which provides visibility into vulnerability and remediation trends.
New:
- Comprehensive Wiz integration support that includes ingestion of Wiz Running Container Vulnerability findings into the Container Vulnerability Response framework.
- Heartbeat monitoring for the container vulnerability response integration framework, providing improved visibility into integration health status.
- A Source Severity column to the vulnerability finding form.
- Discovered item source data now includes resource-delete information, improving traceability when a resource is removed.
- A configurable buffer-time parameter for the Wiz integration.
Changed:
- Enhancements to configuration item lookup and validation logic for the Wiz integration.
Fixed:
- An issue where vulnerabilities might be missing from container vulnerable items due to a broken reference.
- An issue where a container vulnerable item's deployment status might flip incorrectly when all deployments for a repository are removed while the related finding remained open.
- An issue where the post-integration job might fail for a third Wiz integration when image mapping data was not yet available.
- An issue where container vulnerable items retained outdated cluster information after images were removed from deployment, instead of reflecting only current deployments.
- Excessive memory consumption and slow performance in the scheduled job that aggregates configuration item manifest data for asset processing.
- Inconsistent translations of chart titles and filter labels on the Container Vulnerability Management Overview dashboard for non-English languages.
Removed:
- Removed discovery as a data source for determining finding granularity for new customers.
The following application for Vulnerability Response and Configuration Compliance for Containers application must be installed and activated.
- Vulnerability Response
- Security Exposure Management (requires entitlement from the store)
Permissions and roles
- Roles required:
- For installation: System Admin (admin)
- For configurations: Container Vulnerability Admin (sn_vul_container.vulnerability_admin) for Container Vulnerability Response