Bitsight for Vulnerability Response by ServiceNow Setup Guide Erin Conry Bitsight for Vulnerability Response is an integration with the module Vulnerability Response inside the ServiceNow Security Operations product and it transforms how you manage findings as vulnerable items. Bring Bitsight findings into existing security program workflows. Leverage ServiceNow vulnerable item management workflows to automate managing vulnerabilities. Pinpoint and control the sources of infections in your company infrastructure, seamlessly going from awareness to rapid remediation. Set thresholds for the automatic creation of vulnerable items from the Bitsight findings. Easily access the Bitsight platform via links to review the underlying risk data and add additional context around your communication and remediation plans. This integration is certified by ServiceNow and is available in the ServiceNow App Store. FeaturesFindings Management: Bitsight findings reveal associated IP addresses, destination ports, and more. The monitoring and ticket management of these findings can be configured to meet protocols and needs. They can be automated through the ServiceNow Vulnerability Response tool. Leverage the closed-loop workflows and coordinate security responses for better, faster, and more efficient task hand-off.The links in the ticket can also be used to take you back into the Bitsight platform for more information on the specific finding.Vulnerable Item Creation: Vulnerable item tickets include rich Bitsight data including observed IP addresses, subsidiaries (which the findings are attributed to), geographic location, and finding severity. Configure thresholds to automatically generate vulnerable item tickets based on finding severity, asset importance, finding grade, and specific risk vectors.Pre-Built Dashboards: The pre-built dashboard displays important information, including findings by risk vector, severity, asset category, and vulnerable item statuses that allows you to visualize your security posture and track progress.Requirements The Bitsight SPM app A supported version of ServiceNow. The Bitsight for IT Service Management solution. The Vulnerability Response plugin, which provides the base functionality for ticket management. Included with the ServiceNow Vulnerability Response package. If you have a Vulnerability Response package already in your instance, you do not need to install the plugin separately. If you do not have a Vulnerability Response package, you will be asked to install the Vulnerability Response plugin when installing Bitsight for Vulnerability Response. Bitsight for Security Posture Management Connector, which includes Bitsight for Vulnerability Response. This is automatically installed during the installation of dependent applications and all configurations are done through the dependent application; it does not require installation or configuration by the user. Required system table permissions: sys_import_set_row Download and Installation Download and Install the application, available in the ServiceNow App Store. Copy and paste a Bitsight company API token to the “API Token” field to use it in the application. To ensure existing integrations do not break when certain user accounts are deleted, please use a company API token as opposed to a user API token. To generate a new API token, go to the Company API Token section of the Account page in the Bitsight platform. Remember, API tokens should be treated as a password. If you think your token might have been compromised, you can always generate a new one, which will invalidate the previous token. If the integration is failing, see troubleshooting for details. Assign a ServiceNow Admin role (x_bisit_vul_resp.vul_app_admin) to a user. As a ServiceNow Admin, navigate to the Bitsight for Vulnerability Response Configuration module and set the following configurations: Section 1: Set the API Token to the Bitsight API token. Select the Validate Token button to check if the API token is set correctly. Select the organization you would like to receive findings details for. Relationships are structured as a parent company and a subsidiary company (child). Subsidiaries are companies that are within the hierarchy of an organization. They are depicted in an organization’s Ratings Tree in the Bitsight platform. Section 2: Configure the finding severity to filter the finding details. Configure the asset importance to filter the finding details. Configure the finding grade to filter the finding details. Configure the risk vector to filter by particular risk vectors. Configure the Vulnerable Item Assignment to assign the Vulnerable Item incident tickets to a group/user. If opted, this should point to the users who will deal with the incidents. Configure the caller field to set the Caller field in Vulnerable Item tickets. This is done as caller is a mandatory field. It can just be a web-only user. All vulnerable items will have this user as the caller. Select ‘Limit choices to user language only’ option to view the ServiceNow Vulnerable Item states list in the language of the user who is currently logged in. If not selected, the list of all the ServiceNow Vulnerable Item states will be available in multiple languages. Configure the ServiceNow Vulnerable Item states and Bitsight remediation status mapping under the ServiceNow and Bitsight Mapping property. This feature also requires the ServiceNow’s OOTB role (personalize_choices) to behave correctly. It is not recommended to change the ServiceNow and Bitsight Status Mapping property configuration frequently. Configure the max age days field to retrieve the findings of ‘x’ days ago.Note: This is a one-time configuration, and later the field will get disabled. As a ServiceNow Admin, navigate to the Data Import Job Schedule [Bitsight for Vulnerability ResponseITSM ➔Schedule Data Imports Data Import Job Schedules] and set the import time as desired. After Setup The first run will import Bitsight findings into the vulnerable item table. If configured, a vulnerable item for any findings will be created for resolution. To test immediately, execute the import scripts as ServiceNow admin. This should import the findings immediately into the system. Non-Admin users of this application need to be assigned the User (x_bisit_vul_resp.vul_app_user) role. All such users should be able to access vulnerable items. This can be done either by assigning the sn_vul.vulnerability_analyst role directly to the user or by editing the x_bisit_vul_resp.vul_app_user role to include the sn_vul.vulnerability_analyst role. Other ServiceNow integrations: ITSM Security Incident Response VRM March 25, 2026: Published. Related articles Bitsight for Vulnerability Response by ServiceNow Bitsight for Vulnerability Response by ServiceNow: Integration Troubleshooting Bitsight for Vulnerability Response by ServiceNow – March 25, 2026 Bitsight for IT Service Management by ServiceNow: SPM Connector Script API Documentation Overview Feedback 0 comments Please sign in to leave a comment.