Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Review SecOps artifacts

The Data Collection app contains a pre-build data metric structure for the ServiceNow Performance/Platform Analytics application.

The content pack comes with the following artifact types.

Artifact typeDescription
Indicator SourceCaptures the basic data sets and commits them to the working memory of the platform to provide the foundation for the calculations. This is also called a data cube.
Automated IndicatorBasic calculation definition on the indicator source data set, potentially with additional filter conditions that you apply before making the calculation.
Manual IndicatorMetric for which there is no data set within the platform. Requires you to manually add a data point.
Formula IndicatorA more comprehensive calculation, such as % and ratio calculations that require multiple automated indicator data points for the calculation.
Data Collection JobsSchedule on which the automated data collection will run.
WidgetsConfiguration for the UI visualization of an indicator.
DashboardDisplay of a collection of widgets on a pane. This dashboard contains two tabs. One tab contains widgets showing quarterly values, and the other contains widgets showing monthly values.

Artifacts by type

The app contains the following artifacts for each of the above-specified artifact types.

Artifact typeName
Data Collection JobImpact VM - SecOps - Monthly Data Collection
Data Collection JobImpact VM - SecOps - Monthly Historical Data Collection
DashboardImpact VM - SecOps
WidgetRatio of # of vulnerable items with remediation task to vulnerability team
WidgetRatio of closed vulnerability item to closed remediation task
Widget% of SI's resolved by the SOC Tier 1 response team
WidgetRatio of Security Incidents handled at Tier 1 to # of SOC Tier 1 FTE
WidgetRatio of Security Incidents handled at Tier 2+ to # of SOC Tier 2+ FTE
Widget% of critical vulnerable items not addressed
WidgetAverage age of closed critical vulnerability items
Widget% of non-critical vulnerable items not addressed
WidgetAvg. age of non-critical vulnerable item at closure (days)
WidgetMean time to close a SI (days)
FormulaImpact VM - Ratio of number of vulnerable items with remediation task to the size of vulnerability team
AutomatedImpact VM - # of vulnerable items with remediation task opened this month
AutomatedImpact VM - # of vulnerability team FTEs
FormulaImpact VM - Ratio of closed vulnerability item to closed remediation task
AutomatedImpact VM - # of closed vulnerable items this month
AutomatedImpact VM - # of closed remediation task this month
FormulaImpact VM - % of Security Incidents resolved by the dedicated members of the SOC (tier one)
AutomatedImpact VM - Number of security incidents closed by Tier1 this month
AutomatedImpact VM - Number of closed security incidents this month
FormulaImpact VM - Ratio of total security incidents resolved at Tier 1 to the total number of SOC Tier 1 team
AutomatedImpact VM - # of SOC analyst (Tier 1)
FormulaImpact VM - Ratio of total security incidents resolved at Tier 2+ to the toal number of SOC Tier 2+ team
AutomatedImpact VM - Number of security incidents closed by Tier 2+ this month
AutomatedImpact VM - # of SOC analyst (Tier 2)
FormulaImpact VM - % of critical vulnerable items not addressed
AutomatedImpact VM - # of open critical vulnerable items this month
AutomatedImpact VM - # of vulnerability opened this month
FormulaImpact VM - Average age of closed critical vulnerability items
AutomatedImpact VM - Time to close critical vulnerability items
AutomatedImpact VM - Vulnerable items P1 - P2 this month
FormulaImpact VM - % of non-critical vulnerable items not addressed
AutomatedImpact VM - # of open non-critical vulnerable items this month
FormulaImpact VM - Average age of closed non-critical vulnerability items
AutomatedImpact VM - Average age of non-critical vulnerable items at closure (days)
AutomatedImpact VM - # of non critical (P3, P4, P5) vulnerable items this month
FormulaImpact VM - Mean time to close SI (days)
AutomatedImpact VM - Summed duration of closed security incident

Parent Topic:Impact Value Management Data Collection Content Pack for SecOps