Product documentation Docs
    • English
    • Deutsch
    • 日本語
    • 한국어
    • Français
  • More Sites
    • Now Community
    • Developer Site
    • Knowledge Base
    • Product Information
    • ServiceNow.com
    • Training
    • Customer Success Center
    • ServiceNow Support Videos
  • Log in

Product documentation

  • Home
How search works:
  • Punctuation and capital letters are ignored
  • Special characters like underscores (_) are removed
  • Known synonyms are applied
  • The most relevant topics (based on weighting and matching to search terms) are listed first in search results
Topics are ranked in search results by how closely they match your search terms
  • A match on the entire phrase you typed
  • A match on part of the phrase you typed
  • A match on ALL of the terms in the phrase you typed
  • A match on ANY of the terms in the phrase you typed

Note: Matches in titles are always highly ranked.

  • Release version
    Table of Contents
    • Security Operations
Table of Contents
Choose your release version
    Home Paris Security Incident Management Security Operations Vulnerability Response Understanding the Vulnerability Response application Vulnerability Response calculators and vulnerability calculator rules

    Vulnerability Response calculators and vulnerability calculator rules

    • Save as PDF Selected topic Topic & subtopics All topics in contents
    • Unsubscribe Log in to subscribe to topics and get notified when content changes.
    • Share this page

    Vulnerability Response calculators and vulnerability calculator rules

    Vulnerability calculators automate calculating initial values for the fields on vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used.

    Vulnerability Calculators

    The Vulnerability Response base system includes two vulnerability calculators that set the base Risk Score on the vulnerable item.
    • Default Risk Calculator
    • Vulnerability Severity

    Vulnerability calculators can be built to prioritize and rate the impact of vulnerable items based on any criteria by using condition filters. Whether it is the business impact of the vulnerability, the class of the configuration item (CI), or the age of the vulnerable item, you can create additional vulnerability calculators to set other fields on vulnerable items. Or you can customize the existing vulnerability calculators. A calculator can be written to reflect any set of priorities. See Create a Vulnerability Response calculator and Filtering within Vulnerability Response for more information.

    Each calculator contains a list of calculator rules, with a condition determining when to apply it. When the calculator is run, the condition for each calculator rule is evaluated in order, and the first matching calculator rule is used.

    The Vulnerability Severity calculator calculates Risk Score for vulnerable items using the normalized vulnerability severity.
    Note: Only one calculator per target field (Risk Score) can be active at a time. Vulnerability Severity is disabled by default.

    All enabled vulnerability calculators set the selected fields each time a vulnerable item is created, when an associated CI or vulnerability changes, or when the Calculate Risk Score related link in a vulnerable item is used. As an example, the Risk Score is automatically updated on vulnerable item records when the severity value is updated on a vulnerability that is imported. After a vulnerability import has updated a vulnerability score, the recalculate flag is enabled for that vulnerability. The risk scores for the vulnerable items that have the recalculate flag enabled (true) with that vulnerability are recalculated.

    From an existing vulnerable item, if you click the Calculate Risk Score related link and either of the calculators is enabled, the Risk Score field in the vulnerable item is updated.
    Note: The Calculate Risk Score related link is only visible when at least one vulnerability calculator is enabled.

    Vulnerability Calculator Rules

    The base system Default Risk Calculator calculator contains the Default Risk Rule rule, a specialized vulnerability calculator rule called a Risk Rule. It calculates Risk Score based on multiple values:
    • Vulnerability severity
    • Exploit information,
    • Criticality
    • External exposure of the CI with the vulnerability
    You can adjust the values to use in the Default Risk Rule and how much weight to give each of these values. Weights are used to adjust how much each element counts when setting the base Risk Score.

    Each rule has an Order setting however, the first one to match the conditions updates the Risk score field in the vulnerable item. For more information on vulnerability calculator rule settings, see Create a Vulnerability Response calculator. Non-scripted calculator rules typically create less of a performance impact than scripted calculator rules.

    The base system Vulnerability Severity calculator contains calculator rules that assign each level of severity (None to Critical) a value (0-100) for Risk Score based on severity. Unknown Severity is automatically assigned a risk score of 100. These values can be adjusted and, like Default Risk Calculator, new calculator rules or new risk rules can be created.

    Tenable Vulnerability Integration and the Tenable Risk Rule

    Starting with v12.1 of Vulnerability Response, the Tenable Risk Rule is available. The Vulnerability Priority Rating (VPR) is an attribute from the Tenable product that is imported and used with a new default risk calculator in Vulnerability Response. The Tenable Risk Rule is installed with the Tenable Vulnerability Integration application as part of the Default Risk Calculator in the Vulnerability Calculators from Vulnerability Response.

    This risk rule is disabled by default. See Configure the Tenable Vulnerability Integration using Setup Assistant.

    Vulnerability Response Rollup Calculators

    Configure how the cumulative risk score is computed for vulnerability groups and imported vulnerabilities with the vulnerability rollup calculators.

    • Vulnerability Response Rollup Calculators

      Use the vulnerability rollup calculators to configure how the cumulative risk score is computed for vulnerability groups and imported vulnerabilities.

    Related concepts
    • Vulnerability Response personas and granular roles
    • Vulnerability Response assignment rules overview
    • Vulnerability Response groups and group rules overview
    • Machine Learning solutions for Vulnerability Response
    • CI Lookup Rules for identifying configuration items from Vulnerability Response third-party vulnerability integrations
    • Creating CIs for Vulnerability Response using the Identification and Reconciliation engine
    • Discovered Items
    • Vulnerability Response group and vulnerable item states
    • Vulnerability Response vulnerable item detections from third-party integrations
    • Vulnerability Response remediation target rules
    • Vulnerability Solution Management
    • Exception Management overview
    • Exception rules overview
    • False Positive overview
    • Change management for Vulnerability Response
    • Software exposure assessment using Software Asset Management (SAM)
    • Domain separation and Vulnerability Response

    Tags:

    Feedback
    On this page

    Previous topic

    Next topic

    • Contact Us
    • Careers
    • Terms of Use
    • Privacy Statement
    • Sitemap
    • © ServiceNow. All rights reserved.

    Release version
    Choose your release version

      Vulnerability Response calculators and vulnerability calculator rules

      • Save as PDF Selected topic Topic & subtopics All topics in contents
      • Unsubscribe Log in to subscribe to topics and get notified when content changes.
      • Share this page

      Vulnerability Response calculators and vulnerability calculator rules

      Vulnerability calculators automate calculating initial values for the fields on vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used.

      Vulnerability Calculators

      The Vulnerability Response base system includes two vulnerability calculators that set the base Risk Score on the vulnerable item.
      • Default Risk Calculator
      • Vulnerability Severity

      Vulnerability calculators can be built to prioritize and rate the impact of vulnerable items based on any criteria by using condition filters. Whether it is the business impact of the vulnerability, the class of the configuration item (CI), or the age of the vulnerable item, you can create additional vulnerability calculators to set other fields on vulnerable items. Or you can customize the existing vulnerability calculators. A calculator can be written to reflect any set of priorities. See Create a Vulnerability Response calculator and Filtering within Vulnerability Response for more information.

      Each calculator contains a list of calculator rules, with a condition determining when to apply it. When the calculator is run, the condition for each calculator rule is evaluated in order, and the first matching calculator rule is used.

      The Vulnerability Severity calculator calculates Risk Score for vulnerable items using the normalized vulnerability severity.
      Note: Only one calculator per target field (Risk Score) can be active at a time. Vulnerability Severity is disabled by default.

      All enabled vulnerability calculators set the selected fields each time a vulnerable item is created, when an associated CI or vulnerability changes, or when the Calculate Risk Score related link in a vulnerable item is used. As an example, the Risk Score is automatically updated on vulnerable item records when the severity value is updated on a vulnerability that is imported. After a vulnerability import has updated a vulnerability score, the recalculate flag is enabled for that vulnerability. The risk scores for the vulnerable items that have the recalculate flag enabled (true) with that vulnerability are recalculated.

      From an existing vulnerable item, if you click the Calculate Risk Score related link and either of the calculators is enabled, the Risk Score field in the vulnerable item is updated.
      Note: The Calculate Risk Score related link is only visible when at least one vulnerability calculator is enabled.

      Vulnerability Calculator Rules

      The base system Default Risk Calculator calculator contains the Default Risk Rule rule, a specialized vulnerability calculator rule called a Risk Rule. It calculates Risk Score based on multiple values:
      • Vulnerability severity
      • Exploit information,
      • Criticality
      • External exposure of the CI with the vulnerability
      You can adjust the values to use in the Default Risk Rule and how much weight to give each of these values. Weights are used to adjust how much each element counts when setting the base Risk Score.

      Each rule has an Order setting however, the first one to match the conditions updates the Risk score field in the vulnerable item. For more information on vulnerability calculator rule settings, see Create a Vulnerability Response calculator. Non-scripted calculator rules typically create less of a performance impact than scripted calculator rules.

      The base system Vulnerability Severity calculator contains calculator rules that assign each level of severity (None to Critical) a value (0-100) for Risk Score based on severity. Unknown Severity is automatically assigned a risk score of 100. These values can be adjusted and, like Default Risk Calculator, new calculator rules or new risk rules can be created.

      Tenable Vulnerability Integration and the Tenable Risk Rule

      Starting with v12.1 of Vulnerability Response, the Tenable Risk Rule is available. The Vulnerability Priority Rating (VPR) is an attribute from the Tenable product that is imported and used with a new default risk calculator in Vulnerability Response. The Tenable Risk Rule is installed with the Tenable Vulnerability Integration application as part of the Default Risk Calculator in the Vulnerability Calculators from Vulnerability Response.

      This risk rule is disabled by default. See Configure the Tenable Vulnerability Integration using Setup Assistant.

      Vulnerability Response Rollup Calculators

      Configure how the cumulative risk score is computed for vulnerability groups and imported vulnerabilities with the vulnerability rollup calculators.

      • Vulnerability Response Rollup Calculators

        Use the vulnerability rollup calculators to configure how the cumulative risk score is computed for vulnerability groups and imported vulnerabilities.

      Related concepts
      • Vulnerability Response personas and granular roles
      • Vulnerability Response assignment rules overview
      • Vulnerability Response groups and group rules overview
      • Machine Learning solutions for Vulnerability Response
      • CI Lookup Rules for identifying configuration items from Vulnerability Response third-party vulnerability integrations
      • Creating CIs for Vulnerability Response using the Identification and Reconciliation engine
      • Discovered Items
      • Vulnerability Response group and vulnerable item states
      • Vulnerability Response vulnerable item detections from third-party integrations
      • Vulnerability Response remediation target rules
      • Vulnerability Solution Management
      • Exception Management overview
      • Exception rules overview
      • False Positive overview
      • Change management for Vulnerability Response
      • Software exposure assessment using Software Asset Management (SAM)
      • Domain separation and Vulnerability Response

      Tags:

      Feedback

          Share this page

          Got it! Feel free to add a comment
          To share your product suggestions, visit the Idea Portal.
          Please let us know how to improve this content

          Check any that apply

          To share your product suggestions, visit the Idea Portal.
          Confirm

          We were unable to find "Coaching" in Jakarta. Would you like to search instead?

          No Yes
          • Contact Us
          • Careers
          • Terms of Use
          • Privacy Statement
          • Sitemap
          • © ServiceNow. All rights reserved.

          Subscribe Subscribed Unsubscribe Last updated: Tags: January February March April May June July August September October November December No Results Found Versions Search preferences successfully updated My release version successfully updated My release version successfully deleted An error has occurred. Please try again later. You have been unsubscribed from all topics. You are now subscribed to and will receive notifications if any changes are made to this page. You have been unsubscribed from this content Thank you for your feedback. Form temporarily unavailable. Please try again or contact  docfeedback@servicenow.com  to submit your comments. The topic you requested does not exist in the release. You were redirected to a related topic instead. The available release versions for this topic are listed There is no specific version for this documentation. Explore products Click to go to the page. Release notes and upgrades Click to open the dropdown menu. Delete Remove No selected version Reset This field is required You are already subscribed to this topic Attach screenshot The file you uploaded exceeds the allowed file size of 20MB. Please try again with a smaller file. Please complete the reCAPTCHA step to attach a screenshot
          Log in to personalize your search results and subscribe to topics
          No, thanks Login