Tripwire IP360 for Security Operations
by Tripwire Inc
Integrate Tripwire IP360 vulnerabilities with ServiceNow Vulnerability Response
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2024-10-30 | 7 | - |
About
Tripwire IP360 identifies vulnerabilities, applying an unbounded mathematical scoring equation based on how long the vulnerability has existed, how egregious the exposure is, and what skillset is required to exploit the exposure. Thus, an old vulnerability that grants remote privileged access to an automated exploit will potentially score over 100,000 on this scale, while a new vulnerability with no elevation of privilege and no known exploit will score quite low.
The Vulnerability Response application enables granular manipulation of vulnerability data to leverage automated workflows and reporting for faster vulnerability response. Analysts can use the ServiceNow console to drill down into vulnerability data to better guide remediation processes. Tripwire IP360 data is correlated with the ServiceNow CMDB to prioritize critical vulnerabilities that affect key business services. The data is matched to an asset's CI record in the ServiceNow CMDB and stores the discovered hosts information in the Vulnerability Response application as a Vulnerable Item. The automated workflows enable quick response, even creating automated patch requests for the most critical cases.
Scan results are imported into ServiceNow via a MID Server on a defined interval. Vulnerability Response managers may filter out the lower scoring vulnerabilities to only focus on the most critical, or can import every scan result for every asset to get a complete picture of the risks and exposures in the environment. Once the Tripwire data has been imported, GRC risk analysts can view and report on the vulnerabilities that are associated with a Critical Business Service. This data becomes a part of the asset’s CI record in the ServiceNow CMDB through the Vulnerability Response application. The vulnerability risk score of an asset will be calculated based on the Tripwire IP360 score combined with internal business criticality. Security Operations administrators can then set priority and assignment based on the fields Tripwire provides, and analysts can respond by creating IT Incidents, Changes, or Security Incidents within ServiceNow.
Real-time dashboards let you monitor your organization’s risk exposure and potential impact to business services.
The Tripwire IP360 integration with ServiceNow Security Operations is run at a periodic or defined interval to query Tripwire IP360 for the latest and most severe vulnerabilities to populate vulnerable items against CIs in the ServiceNow CMDB. ServiceNow is now capable of processing the information according to our expert advice or your own tailored security or business logic.
Key Features
* Respond to the most critical vulnerabilities first with prioritization and workflows
* Improve visibility through correlation with business context
* Scale to the largest deployments by combining vulnerability and exposure data from multiple appliances
* Leverage the power of the MID Server for frictionless set-up, maintenance and data collection
* Seamless support for cloud, on-premises, or hybrid vulnerability scanning