Map the severity of an application vulnerable item automatically
Application Vulnerability Response severity mapping transforms third-party source severity fields to recognizable fields within Vulnerability Response.
Before you begin
Role required: App-Sec Manager group
About this task
Application Vulnerability Response third-party integrations such as the Veracode Vulnerability Integration provide severity mappings on installation. These maps can be adjusted by changing the fields in existing maps.
Creating or editing a severity map is intended only for customized or non-standard third-party mappings in your environment and requires Application Vulnerability Response and ServiceNow expertise.
Procedure
Navigate to All > Application Vulnerability Response > Administration > Normalized Severity Mapping.
Click New.
Fill in the fields on the form, as appropriate.
| Field | Description |
|---|---|
| Source | The name of the source for the severity mapping. |
| Source value | The source severity value. |
| Target value | The target severity value. Choices are: - 1- Critical - 2 - High - 3 - Medium - 4 - Low - 5 - None |
| Integration type | Integration type choices are:- Vulnerability Response - Application Vulnerability Response - National Vulnerability Response - Container Vulnerability Response |
Repeat Step 3 for each source severity level.
Select Save.