Tenable.sc integrations with the Vulnerability Response application
The Tenable.sc integrations in the Vulnerability Response Integration with Tenable application.
Starting with Vulnerability Response v20.0, if an asset is scanned by an agent, the "Agent exists" column in the Discovered Items list displays the value as "true." This indicates that the scan is authentic.
List of Tenable.sc integrations
Multi-source is supported for all the Tenable.io and Tenable.sc integrations. You can add and deploy multiple instances of the following integrations across your environment from Setup Assistant in Vulnerability Response. You can also install and configure the Vulnerability Response Integration with Tenable application from Setup Assistant.
- Tenable.sc is an on-premises integration that gives you the option to use a MID Server if the Tenable.sc product and your ServiceNow AI Platform instance are in the same environment.
- If the Tenable.sc product and your ServiceNow AI Platform instance aren’t in the same environment, you’re required to use a MID Server.
| Integration | Description |
|---|---|
| Tenable.sc Assets Integration | To avoid creating duplicate discovered items with imported asset data, the Asset Integration of the Tenable.sc product is comprised of two integrations.
This integration imports vulnerability data about your assets that Tenable considers Cumulative (current), or Open. The vulnerable items (VIs) that are created in your instance with this imported asset data are considered open, that is, in the Open state. These vulnerable items require investigation and might need remediation.
This integration imports vulnerability data about your assets that Tenable considers Mitigated (no longer vulnerable) or Fixed. The vulnerable items for these assets transition from the Open state to the Closed/Fixed state in your instance, because the results of scans show they’re no longer vulnerable.
|
| Tenable.sc Plugin Integration | - Retrieves the plugin data from the Tenable.sc product. Retrieved data are based on the date that the plugins were last updated by a Tenable.sc integration run. - This import ensures that the Tenable.sc Identifiers \(Ten IDs\) are current and only active vulnerabilities are imported. - Coordinates the REST message calls to the Plugins API. - The output of this integration is third-party vulnerabilities. |
| Tenable.sc Fixed Vulnerabilities Integration |
The output of this integration is Closed/Fixed vulnerable items (VIs). It also creates assets and third-party entries if they don't exist. This integration run is a scheduled run. It’s a chained integration which means after a run is successfully completed, the Tenable.sc Open Vulnerabilities Integration described next is triggered. Note: By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Open Vulnerabilities Integration |
Note: By default, the family IDs 0 and 39 are excluded from this integration. |
| Tenable.sc Scan Credential Integration | - This integration retrieves the scan credentials configured in Tenable.sc. - Coordinates the REST message calls to the Credentials API. - The output of this integration is scan credentials populated in table, \[sn\_vul\_tenable\_scan\_credential\]. - The imported credentials are used to access the scanner when scan requests are initiated from the ServiceNow AI Platform. - This integration is scheduled to run weekly. |
| Tenable.sc Backfill Vulnerabilities Integration |
|
User authentication and Tenable.sc
User authentication is supported by your ServiceNow AI Platform® instance and version 5.13 of the Tenable.sc product. User authentication is required if you’re using version 5.12 and earlier of the Tenable.sc product.
When you select user authentication for the Tenable.sc integrations, tokens might expire and be replaced during integration runs. In the Notes column on the Vulnerability Integration Run record (VIN), the following message is displayed for a process when a token expires, Error: Token validation is failed. No action is required if this message is displayed. Expired tokens are automatically refreshed in the background and the message doesn’t indicate a pause or error with the integration process.
Related topics
Preparing for the Tenable Vulnerability Integration
Install the Vulnerability Response Integration with Tenable application using Setup Assistant