Bitsight for IT Service Management by ServiceNow: Integration Guide

The Bitsight for IT Service Management integration is certified by ServiceNow and is available in the ServiceNow App Store.

Summary

The integration between ServiceNow's IT Service Management (ITSM) module and Bitsight lets organizations manage cybersecurity findings within their existing ITSM workflows. Delivered as an out-of-the-box application from the ServiceNow Store, the integration connects Bitsight Security Posture Management with ITSM to support incident creation, tracking, and remediation.

Configuration begins by adding a Bitsight API token, typically tied to a service account. From there, users choose which entity in their ratings tree to monitor, set thresholds for severity levels, asset importance, or grades, and select the risk vectors relevant to their organization. Incidents can be automatically assigned to designated users or groups, and remediation statuses in Bitsight can be mapped directly to ServiceNow states. Historical findings, such as those from the past 30 days, can also be imported during setup.

Once active, the integration creates detailed incidents in ServiceNow with fields like severity, grade, asset, and priority, alongside contextual links back to the Bitsight portal. Findings can also be tied to CMDB configuration items for added context. The dashboard shows findings by category, severity, asset importance, grade, and risk factor, with drill-down to view specific trends or issues.

Features

Findings management

Bitsight findings reveal associated IP addresses, destination ports, and more. Monitoring and incident management for these findings can be configured to meet your organization's protocols, then automated through the ServiceNow IT Service Management tool. Finding and incident data sync automatically between Bitsight and ServiceNow, so teams don't need to re-enter data manually when handing off a task.

Links in the incident ticket take you back into the Bitsight platform for more detail on the specific finding.
 

Incident creation

Incident tickets include Bitsight data such as observed IP addresses, subsidiaries the finding is attributed to, geographic location, and finding severity. Configure thresholds to automatically generate incident tickets based on finding severity, asset importance, finding grade, and specific risk vectors.
 

Pre-built dashboards

The pre-built dashboard displays findings by risk vector, severity, asset category, and incident status, for reference in reviewing findings trends and incident status.
 

Prerequisites

To use this integration, you need:

  • The Security Posture Management app
  • A supported version of ServiceNow
  • The Bitsight for IT Service Management application
  • The Incident plugin, which provides the base functionality for incident management. It's included with the ServiceNow ITSM package
    • If you already have an ITSM package in your instance, you don't need to install the plugin separately
    • If you don't have an ITSM package, you'll be prompted to install the Incident plugin when you install Bitsight for IT Service Management
  • The Bitsight for Security Posture Management Connector, which is included with Bitsight for IT Service Management. It installs automatically with its dependent applications, and all configuration happens through the dependent application — it doesn't require separate installation or configuration
  • Required system table permission: sys_import_set_row

Permissions

Non-admin users need the User role (itsm_app_user). They also need the itil role to access incidents, either assigned directly or added to their existing role.

Download and installation

  1. Download and install the application from the ServiceNow App Store.
  2. Copy a Bitsight company API token into the API Token field. Use a company API token rather than a user API token, so existing integrations don't break if a user account is deleted. To generate a new token, go to the Company API Token section of the Account page in the Bitsight platform. Treat API tokens like passwords — if you think one has been compromised, generate a new one to invalidate the old one. If the integration is failing, see troubleshooting.
  3. Assign the ServiceNow Admin role (itsm_app_admin) to a user.
  4. As a ServiceNow Admin, go to the Bitsight for ITSM Application Configuration module and set the following:

    Connection and scope

    1. Set the API Token to your Bitsight API token, then select Validate Token to confirm it's set correctly.
    2. Select the organization you want findings for. Relationships are structured as a parent company and subsidiary companies (children), shown in the organization's Ratings Tree in the Bitsight platform.

    Filtering and workflow 3. Configure finding severity to filter finding details. 4. Configure asset importance to filter finding details. 5. Configure risk vectors to filter by. 6. Configure Incident Assignment to route incident tickets to a group or user who will handle them. 7. Configure the Caller field on incident tickets. This field is mandatory; it can point to a web-only user, and all incidents will show this user as caller. 8. Map ServiceNow incident status to Bitsight Remediation Status to sync status between the two systems. 9. Set how many days of historical findings the integration should pull.

  5. As a ServiceNow Admin, go to Bitsight for ITSM → Data Import Job Schedules and set the import time.

The first scheduled run imports Bitsight findings into the incident table; if configured, it creates an incident for any finding that needs resolution. To test immediately, run the import scripts as a ServiceNow admin — this imports findings right away.

Demo

Watch a short video demo of the ITSM integration in Bitsight Academy.

Publish Date or Recent Edits
  • March 19, 2026: Security Posture Management rebrand.
  • September 25, 2025: Updated content and links
Was this article helpful?
2 out of 4 found this helpful

Comments

0 comments

Please sign in to leave a comment.